Vulnerability index

Browse CVEs

1,200 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Search Path (DLL Hijack)CWE-427 × clear
Patrol HIGH 7.8
CVE-2017-13130

mcmnm in BMC Patrol allows local users to gain privileges via a crafted libmcmclnx.so file in the current working directory, because it is setuid roo…

No fix yet
Fix from $1,950 2017-08-23
Vip Access For Desktop HIGH 7.8
CVE-2017-6329

Symantec VIP Access for Desktop prior to 2.2.4 can be susceptible to a DLL Pre-Loading vulnerability. These types of issues occur when an application…

Fix: after 2.2.3
Fix from $1,950 2017-08-21
Heating Control Downloader HIGH 7.8
CVE-2017-9646

An Uncontrolled Search Path Element issue was discovered in Solar Controls Heating Control Downloader (HCDownloader) Version 1.0.1.15 and prior. An u…

Fix: after 1.0.1.15
Fix from $1,950 2017-08-14
Wattconfig M HIGH 7.8
CVE-2017-9648

An Uncontrolled Search Path Element issue was discovered in Solar Controls WATTConfig M Software Version 2.5.10.1 and prior. An uncontrolled search p…

Fix: after 2.5.10.1
Fix from $1,950 2017-08-14
Scada HIGH 7.0
CVE-2017-9661

An Uncontrolled Search Path Element issue was discovered in SIMPlight SCADA Software version 4.3.0.27 and prior. The uncontrolled search path element…

Fix: after 4.3.0.27
Fix from $1,950 2017-08-14
360 Total Security HIGH 7.8
CVE-2017-12653

360 Total Security 9.0.0.1202 before 2017-07-07 allows Privilege Escalation via a Trojan horse Shcore.dll file in any directory in the PATH, as demon…

Fix: after 9.0.0.1202
Fix from $1,950 2017-08-07
Nfc Port Firmware HIGH 7.8
CVE-2017-2286

Untrusted search path vulnerability in NFC Port Software Version 5.5.0.6 and earlier (for RC-S310, RC-S320, RC-S330, RC-S370, RC-S380, RC-S380/S), NF…

Fix: after 5.5.0.6
Fix from $1,950 2017-08-02
Nfc Port Software Remover HIGH 7.8
CVE-2017-2287

Untrusted search path vulnerability in NFC Port Software remover Ver.1.3.0.1 and earlier allows an attacker to gain privileges via a Trojan horse DLL…

Fix: after 1.3.0.1
Fix from $1,950 2017-08-02
Lhaforge HIGH 7.8
CVE-2017-2288

Untrusted search path vulnerability in LhaForge Ver.1.6.5 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified …

Fix: after 1.6.5
Fix from $1,950 2017-08-02
Audacity HIGH 7.8
CVE-2017-1000010

Audacity 2.1.2 through 2.3.2 is vulnerable to Dll HIjacking in the avformat-55.dll resulting arbitrary code execution.

Fix: after 2.3.2
Fix from $1,950 2017-07-17
Digital Editions CRITICAL 9.8
CVE-2017-3090EPSS 8%

Adobe Digital Editions versions 4.5.4 and earlier contain an insecure library loading vulnerability. The vulnerability is due to unsafe library loadi…

Fix: after 4.5.4
Fix from $2,300 2017-06-20
Digital Editions CRITICAL 9.8
CVE-2017-3092EPSS 8%

Adobe Digital Editions versions 4.5.4 and earlier contain an insecure library loading vulnerability. The vulnerability is due to unsafe library loadi…

Fix: after 4.5.4
Fix from $2,300 2017-06-20
Digital Editions CRITICAL 9.8
CVE-2017-3097EPSS 7%

Adobe Digital Editions versions 4.5.4 and earlier contain an insecure library loading vulnerability. The vulnerability is due to unsafe library loadi…

Fix: after 4.5.4
Fix from $2,300 2017-06-20
Vnx2 Firmware HIGH 7.3
CVE-2017-4987

In EMC VNX2 versions prior to OE for File 8.1.9.211 and VNX1 versions prior to OE for File 7.1.80.8, a local authenticated user can load a maliciousl…

Mitigation only
Fix from $1,950 2017-06-19
Apc Ups Daemon HIGH 8.4
CVE-2017-7884

In Adam Kropelin adk0212 APC UPS Daemon through 3.14.14, the default installation of APCUPSD allows a local authenticated, but unprivileged, user to …

Fix: after 3.14.14
Fix from $1,950 2017-06-16
Patchjgd HIGH 7.8
CVE-2017-2210

Untrusted search path vulnerability in PatchJGD (PatchJGD101.EXE) ver. 1.0.1 allows an attacker to gain privileges via a Trojan horse DLL in an unspe…

Mitigation only
Fix from $1,950 2017-06-09
Somachine HIGH 8.8
CVE-2017-7966

A DLL Hijacking vulnerability in the programming software in Schneider Electric's SoMachine HVAC v2.1.0 allows a remote attacker to execute arbitrary…

Mitigation only
Fix from $1,950 2017-06-07
Connected Components Workbench HIGH 7.0
CVE-2017-5176

A DLL Hijack issue was discovered in Rockwell Automation Connected Components Workbench (CCW). The following versions are affected: Connected Compone…

Fix: after 9.01.00
Fix from $1,950 2017-05-19
Visualview Hmi HIGH 7.0
CVE-2017-6051

An Uncontrolled Search Path Element issue was discovered in BLF-Tech LLC VisualView HMI Version 9.9.14.0 and prior. The uncontrolled search path elem…

Fix: after 9.9.14.0
Fix from $1,950 2017-05-08
Acrobat HIGH 7.8
CVE-2017-3012

Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have an insecure library loading (DLL hijacking…

Fix: after 15.023.20070
Fix from $1,950 2017-04-12
Acrobat HIGH 7.8
CVE-2017-3013

Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have an insecure library loading (DLL hijacking…

Fix: after 15.023.20070
Fix from $1,950 2017-04-12
Interactive Graphical Scada System HIGH 7.8
CVE-2017-6033

A DLL Hijacking issue was discovered in Schneider Electric Interactive Graphical SCADA System (IGSS) Software, Version 12 and previous versions. The …

Fix: after 12.0
Fix from $1,950 2017-04-07
Skype CRITICAL 9.8
CVE-2017-6517EPSS 46%

Microsoft Skype 7.16.0.102 contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on the targeted sy…

No fix yet
Fix from $2,300 2017-03-23
Antivirus\+ MEDIUM 6.7
CVE-2017-5565

Code injection vulnerability in Trend Micro Maximum Security 11.0 (and earlier), Internet Security 11.0 (and earlier), and Antivirus+ Security 11.0 (…

Fix: after 11.1.1005
Fix from $1,600 2017-03-21
Anti Virus MEDIUM 6.7
CVE-2017-5566

Code injection vulnerability in AVG Ultimate 17.1 (and earlier), AVG Internet Security 17.1 (and earlier), and AVG AntiVirus FREE 17.1 (and earlier) …

Mitigation only
Fix from $1,600 2017-03-21
Free Antivirus MEDIUM 6.7
CVE-2017-5567

Code injection vulnerability in Avast Premier 12.3 (and earlier), Internet Security 12.3 (and earlier), Pro Antivirus 12.3 (and earlier), and Free An…

Fix: after 12.3
Fix from $1,600 2017-03-21
Free Security Suite MEDIUM 6.7
CVE-2017-6417

Code injection vulnerability in Avira Total Security Suite 15.0 (and earlier), Optimization Suite 15.0 (and earlier), Internet Security Suite 15.0 (a…

Fix: after 15.0
Fix from $1,600 2017-03-21
Winlog Lite HIGH 7.2
CVE-2017-5161

An issue was discovered in Sielco Sistemi Winlog Lite SCADA Software, versions prior to Version 3.02.01, and Winlog Pro SCADA Software, versions prio…

Fix: after 3.01.10
Fix from $1,950 2017-02-13
Tracer Sc HIGH 7.5
CVE-2016-4526

ABB DataManagerPro 1.x before 1.7.1 allows local users to gain privileges by replacing a DLL file in the package directory.

Fix: after 4.2.1134
Fix from $1,950 2016-09-19
Opera Browser HIGH 7.2
CVE-2005-0457

Opera 7.54 and earlier on Gentoo Linux uses an insecure path for plugins, which could allow local users to gain privileges by inserting malicious lib…

Fix: after 7.54
Fix from $1,950 2005-05-02