Vulnerability index

Browse CVEs

1,200 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Search Path (DLL Hijack)CWE-427 × clear
Toolbox HIGH 7.8
CVE-2019-12280

PC-Doctor Toolbox before 7.3 has an Uncontrolled Search Path Element.

Fix: 7.3+
Fix from $1,950 2019-06-25
Private Internet Access HIGH 7.8
CVE-2019-12572

A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client 1.0.2 (build 02363) for Windows could allow an authenticated, loca…

No fix yet
Fix from $1,950 2019-06-21
Manageengine Analytics Plus HIGH 7.8
CVE-2019-12133

Multiple Zoho ManageEngine products suffer from local privilege escalation due to improper permissions for the %SYSTEMDRIVE%\ManageEngine directory a…

Mitigation only
Fix from $1,950 2019-06-18
Hisuite MEDIUM 5.3
CVE-2019-5245

HiSuite 9.1.0.300 versions and earlier contains a DLL hijacking vulnerability. This vulnerability exists due to some DLL file is loaded by HiSuite im…

Fix: after 9.1.0.300
Fix from $1,600 2019-06-13
Viveport HIGH 7.8
CVE-2019-12177

Privilege escalation due to insecure directory permissions affecting ViveportDesktopService in HTC VIVEPORT before 1.0.0.36 allows local attackers to…

Fix: 1.0.0.36+
Fix from $1,950 2019-06-03
Creative Cloud HIGH 7.8
CVE-2019-7093

Creative Cloud Desktop Application (installer) versions 4.7.0.400 and earlier have an insecure library loading (dll hijacking) vulnerability. Success…

Fix: after 4.7.0.400
Fix from $1,950 2019-05-24
Videoxpert Opscenter HIGH 7.8
CVE-2018-7840

A Uncontrolled Search Path Element (CWE-427) vulnerability exists in VideoXpert OpsCenter versions prior to 3.1 which could allow an attacker to caus…

Fix: 3.1+
Fix from $1,950 2019-05-22
Client Security HIGH 7.8
CVE-2019-11644

In the F-Secure installer in F-Secure SAFE for Windows before 17.6, F-Secure Internet Security before 17.6, F-Secure Anti-Virus before 17.6, F-Secure…

Fix: 12.01 / 14.10+
Fix from $1,950 2019-05-17
Workstation HIGH 7.8
CVE-2019-5526EPSS 9%

VMware Workstation (15.x before 15.1.0) contains a DLL hijacking issue because some DLL files are improperly loaded by the application. Successful ex…

Fix: 15.1.0+
Fix from $1,950 2019-05-15
Gpu Display Driver MEDIUM 6.7
CVE-2019-5676

NVIDIA Windows GPU Display driver software for Windows (all versions) contains a vulnerability in which it incorrectly loads Windows system DLLs with…

Fix: 3.19 / 412.36+
Fix from $1,600 2019-05-10
Ge Communicator HIGH 7.8
CVE-2019-6564

GE Communicator, all versions prior to 4.0.517, allows a non-administrative user to place malicious files within the installer file directory, which …

Fix: 4.0.517+
Fix from $1,950 2019-05-09
Ge Communicator HIGH 7.8
CVE-2019-6546

GE Communicator, all versions prior to 4.0.517, allows an attacker to place malicious files within the working directory of the program, which may al…

Fix: 4.0.517+
Fix from $1,950 2019-05-09
Meeting Server MEDIUM 5.1
CVE-2019-1794

A vulnerability in the search path processing of Cisco Directory Connector could allow an authenticated, local attacker to load a binary of their cho…

Mitigation only
Fix from $1,600 2019-04-18
Sentinel Ultrapro Client Library HIGH 7.8
CVE-2019-6534

The uncontrolled search path element vulnerability in Gemalto Sentinel UltraPro Client Library ux32w.dll Versions 1.3.0, 1.3.1, and 1.3.2 enables an …

Patch available
Fix from $1,950 2019-04-11
Opc Factory Server HIGH 7.3
CVE-2015-1014

A successful exploit of these vulnerabilities requires the local user to load a crafted DLL file in the system directory on servers running Schneider…

Mitigation only
Fix from $1,950 2019-03-25
Putty HIGH 7.8
CVE-2019-9896

In PuTTY versions before 0.71 on Windows, local attackers could hijack the application by putting a malicious help file in the same directory as the …

Fix: 0.71+
Fix from $1,950 2019-03-21
Db2 HIGH 7.8
CVE-2019-4094

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 binaries load shared libraries from an untrusted path pot…

Patch available
Fix from $1,950 2019-03-21
Sdk HIGH 7.8
CVE-2018-1890

IBM SDK, Java Technology Edition Version 8 on the AIX platform uses absolute RPATHs which may facilitate code injection and privilege elevation by lo…

Patch available
Fix from $1,950 2019-03-11
Go HIGH 7.8
CVE-2019-9634

Go through 1.12 on Windows misuses certain LoadLibrary functionality, leading to DLL injection.

Fix: 1.11.10 / 1.12.2+
Fix from $1,950 2019-03-08
Orion Platform CRITICAL 9.8
CVE-2019-9546

SolarWinds Orion Platform before 2018.4 Hotfix 2 allows privilege escalation through the RabbitMQ service.

Fix: 2018.4+
Fix from $2,300 2019-03-01
Sublime Text 3 HIGH 7.8
CVE-2019-9116

DLL hijacking is possible in Sublime Text 3 version 3.1.1 build 3176 on 32-bit Windows platforms because a Trojan horse api-ms-win-core-fibers-l1-1-1…

No fix yet
Fix from $1,950 2019-02-25
Debian Linux CRITICAL 9.8
CVE-2019-7653

The Debian python-rdflib-tools 4.2.2-1 package for RDFLib 4.2.2 has CLI tools that can load Python modules from the current working directory, allowi…

No fix yet
Fix from $2,300 2019-02-09
Fall Creators Update HIGH 7.8
CVE-2018-16177

Untrusted search path vulnerability in The installer of Windows 10 Fall Creators Update Modify module for Security Measures tool allows an attacker t…

Mitigation only
Fix from $1,950 2019-01-09
Exiftool HIGH 7.8
CVE-2018-20211

ExifTool 8.32 allows local users to gain privileges by creating a %TEMP%\par-%username%\cache-exiftool-8.32 folder with a victim's username, and then…

No fix yet
Fix from $1,950 2019-01-02
Advanced Malware Protection For Endpoints MEDIUM 6.7
CVE-2018-15452

A vulnerability in the DLL loading component of Cisco Advanced Malware Protection (AMP) for Endpoints on Windows could allow an authenticated, local …

Mitigation only
Fix from $1,600 2018-11-13
Software Update Utility HIGH 7.8
CVE-2018-7799

A DLL hijacking vulnerability exists in Schneider Electric Software Update (SESU), all versions prior to V2.2.0, which could allow an attacker to exe…

Fix: 2.2.0+
Fix from $1,950 2018-11-02
Energy Savings Estimator HIGH 7.8
CVE-2018-14812

An uncontrolled search path element (DLL Hijacking) vulnerability has been identified in Fuji Electric Energy Savings Estimator versions V.1.0.2.0 an…

Mitigation only
Fix from $1,950 2018-10-24
Technical Communications Suite HIGH 7.8
CVE-2018-15976EPSS 5%

Adobe Technical Communications Suite versions 1.0.5.1 and below have an insecure library loading (dll hijacking) vulnerability. Successful exploitati…

Fix: after 1.0.5.1
Fix from $1,950 2018-10-17
Digital Delivery HIGH 7.8
CVE-2018-11072

Dell Digital Delivery versions prior to 3.5.1 contain a DLL Injection Vulnerability. A local authenticated malicious user with advance knowledge of t…

Fix: 3.5.1+
Fix from $1,950 2018-10-02
Data Migration Software MEDIUM 5.3
CVE-2018-12160

DLL injection vulnerability in software installer for Intel Data Center Migration Center Software v3.1 and before may allow an authenticated user to …

Fix: after 3.1
Fix from $1,600 2018-09-12