Vulnerability index

Browse CVEs

1,198 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Search Path (DLL Hijack)CWE-427 × clear
MEDIUM 6.5 CVE-2020-4623 IBM i2 iBase 8.9.13 could allow a local authenticated attacker to execute arbitrary code on the system, caused by a DLL search order hijacking flaw. … I2 Ibase Patch available Fix from $1,6002021-07-26 HIGH 7.8 CVE-2020-5316 Dell SupportAssist for Business PCs versions 2.0, 2.0.1, 2.0.2, 2.1, 2.1.1, 2.1.2, 2.1.3 and Dell SupportAssist for Home PCs version 2.0, 2.0.1, 2.0.… Supportassist For Business Pcs Patch available Fix from $1,9502021-07-22 HIGH 7.8 CVE-2021-1089 NVIDIA GPU Display Driver for Windows contains a vulnerability in nvidia-smi where an uncontrolled DLL loading path may lead to arbitrary code execut… Gpu Display Driver 427.48 / 453.10+ Fix from $1,9502021-07-22 HIGH 7.8 CVE-2021-3550 A DLL search path vulnerability was reported in Lenovo PCManager, prior to version 3.0.500.5102, that could allow privilege escalation. Pcmanager 3.0.500.5102+ Fix from $1,9502021-07-16 HIGH 7.8 CVE-2021-36753 sharkdp BAT before 0.18.2 executes less.exe from the current working directory. Bat 0.18.2+ Fix from $1,9502021-07-15 HIGH 7.8 CVE-2020-11634 The Zscaler Client Connector for Windows prior to 2.1.2.105 had a DLL hijacking vulnerability caused due to the configuration of OpenSSL. A local adv… Client Connector 2.1.2.105+ Fix from $1,9502021-07-15 HIGH 7.8 CVE-2021-3042 A local privilege escalation (PE) vulnerability exists in the Palo Alto Networks Cortex XDR agent on Windows platforms that enables an authenticated … Cortex Xdr Agent Mitigation only Fix from $1,9502021-07-15 HIGH 7.8 CVE-2020-29157 An issue in RAONWIZ K Editor v2018.0.0.10 allows attackers to perform a DLL hijacking attack when the service or system is restarted. Raon K Editor No fix yet Fix from $1,9502021-07-14 HIGH 7.8 CVE-2021-22000 VMware Thinapp version 5.x prior to 5.2.10 contain a DLL hijacking vulnerability due to insecure loading of DLLs. A malicious actor with non-administ… Thinapp 5.2.10+ Fix from $1,9502021-07-13 MEDIUM 6.7 CVE-2021-35957 Stormshield Endpoint Security Evolution 2.0.0 through 2.0.2 does not accomplish the intended defense against local administrators who can replace the… Endpoint Security after 2.0.2 Fix from $1,6002021-07-13 HIGH 7.8 CVE-2021-36376 dandavison delta before 0.8.3 on Windows resolves an executable's pathname as a relative path from the current directory. Delta 0.8.3+ Fix from $1,9502021-07-13 HIGH 7.8 CVE-2021-3613 OpenVPN Connect 3.2.0 through 3.3.0 allows local users to load arbitrary dynamic loadable libraries via an OpenSSL configuration file if present, whi… Connect after 3.3.0 Fix from $1,9502021-07-02 HIGH 7.8 CVE-2021-3606 OpenVPN before version 2.5.3 on Windows allows local users to load arbitrary dynamic loadable libraries via an OpenSSL configuration file if present,… Openvpn 2.5.3+ Fix from $1,9502021-07-02 HIGH 8.6 CVE-2021-28570 Adobe After Effects version 18.1 (and earlier) is affected by an Uncontrolled Search Path element vulnerability. An unauthenticated attacker could ex… After Effects after 18.1 Fix from $1,9502021-06-28 HIGH 7.8 CVE-2021-29949 When loading the shared library that provides the OTR protocol implementation, Thunderbird will initially attempt to open it using a filename that is… Thunderbird 78.9.1+ Fix from $1,9502021-06-24 HIGH 7.8 CVE-2021-21999 VMware Tools for Windows (11.x.y prior to 11.2.6), VMware Remote Console for Windows (12.x prior to 12.0.1) , VMware App Volumes (2.x prior to 2.18.1… App Volumes 2.18.10 / 11.2.6+ Fix from $1,9502021-06-23 MEDIUM 6.7 CVE-2021-1567 A vulnerability in the DLL loading mechanism of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to p… Anyconnect Secure Mobility Client 4.10.01075+ Fix from $1,6002021-06-16 HIGH 7.8 CVE-2021-34803 TeamViewer before 14.7.48644 on Windows loads untrusted DLLs in certain situations. Teamviewer 9.0.259145 / 10.0.259144+ Fix from $1,9502021-06-16 HIGH 7.3 CVE-2021-31840 A vulnerability in the preloading mechanism of specific dynamic link libraries in McAfee Agent for Windows prior to 5.7.3 could allow an authenticate… Mcafee Agent 5.7.3+ Fix from $1,9502021-06-10 HIGH 7.8 CVE-2021-23023 On version 7.2.1.x before 7.2.1.3 and 7.1.x before 7.1.9.9 Update 1, a DLL hijacking issue exists in cachecleaner.dll included in the BIG-IP Edge Cli… Big Ip Access Policy Manager 7.2.1.3+ Fix from $1,9502021-06-10 HIGH 7.8 CVE-2021-3041 A local privilege escalation vulnerability exists in the Palo Alto Networks Cortex XDR agent on Windows platforms that enables an authenticated local… Cortex Xdr Agent 5.0.11 / 6.1.8+ Fix from $1,9502021-06-10 HIGH 7.8 CVE-2021-0057 Uncontrolled search path in the Intel(R) NUC M15 Laptop Kit Driver Pack software before updated version 1.1 may allow an authenticated user to potent… Lapbc510 Firmware 1.1+ Fix from $1,9502021-06-09 HIGH 7.3 CVE-2021-0090 Uncontrolled search path element in Intel(R) DSA before version 20.11.50.9 may allow an authenticated user to potentially enable an escalation of pri… Driver \& Support Assistant 20.11.50.9+ Fix from $1,9502021-06-09 HIGH 7.8 CVE-2021-0104 Uncontrolled search path element in the installer for the Intel(R) Rapid Storage Technology software, before versions 17.9.0.34, 18.0.0.640 and 18.1.… Rapid Storage Technology 17.9.1.1009.5 / 18.0.3.1148.4+ Fix from $1,9502021-06-09 HIGH 7.3 CVE-2021-0108 Uncontrolled search path in the Intel Unite(R) Client for Windows before version 4.2.25031 may allow an authenticated user to potentially enable an e… Unite 4.2.25031+ Fix from $1,9502021-06-09 HIGH 7.3 CVE-2020-8702 Uncontrolled search path element in the Intel(R) Processor Diagnostic Tool before version 4.1.5.37 may allow an authenticated user to potentially ena… Processor Diagnostic Tool 4.1.5.37+ Fix from $1,9502021-06-09 HIGH 7.8 CVE-2021-1536 A vulnerability in Cisco Webex Meetings Desktop App for Windows, Cisco Webex Meetings Server, Cisco Webex Network Recording Player for Windows, and C… Webex Meetings Desktop Mitigation only Fix from $1,9502021-06-04 HIGH 7.8 CVE-2019-4588 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local user to execute arbitrary code … Db2 Mitigation only Fix from $1,9502021-05-26 HIGH 7.8 CVE-2021-20726 Untrusted search path vulnerability in The Installer of Overwolf 2.168.0.n and earlier allows an attacker to gain privileges and execute arbitrary co… Overwolf after 2.168.0.n Fix from $1,9502021-05-24 HIGH 7.8 CVE-2021-20722 Untrusted search path vulnerability in the installers of ScanSnap Manager prior to versions V7.0L20 and the Software Download Installer prior to WinS… Scansnap Manager 7.0l20+ Fix from $1,9502021-05-24