Vulnerability index

Browse CVEs

1,198 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Search Path (DLL Hijack)CWE-427 × clear
HIGH 7.8 CVE-2020-28950 The installer of Kaspersky Anti-Ransomware Tool (KART) prior to KART 4.0 Patch C was vulnerable to a DLL hijacking attack that allowed an attacker to… Anti Ransomware Tool 4.0+ Fix from $1,9502020-12-04 MEDIUM 6.8 CVE-2020-27348 In some conditions, a snap package built by snapcraft includes the current directory in LD_LIBRARY_PATH, allowing a malicious snap to gain code execu… Snapcraft 4.4.4+ Fix from $1,6002020-12-04 HIGH 7.8 CVE-2020-6021 Check Point Endpoint Security Client for Windows before version E84.20 allows write access to the directory from which the installation repair takes … Endpoint Security Mitigation only Fix from $1,9502020-12-03 MEDIUM 5.5 CVE-2020-25738 CyberArk Endpoint Privilege Manager (EPM) 11.1.0.173 allows attackers to bypass a Credential Theft protection mechanism by injecting a DLL into a pro… Endpoint Privilege Manager No fix yet Fix from $1,6002020-11-27 HIGH 7.8 CVE-2020-5674 Untrusted search path vulnerability in the installers of multiple SEIKO EPSON products allows an attacker to gain privileges via a Trojan horse DLL i… Album Print Mitigation only Fix from $1,9502020-11-24 HIGH 7.8 CVE-2020-12329 Uncontrolled search path in the Intel(R) VTune(TM) Profiler before version 2020 Update 1 may allow an authenticated user to potentially enable escala… Vtune Profiler after 2020 Fix from $1,9502020-11-12 HIGH 7.8 CVE-2020-12320 Uncontrolled search path in Intel(R) SCS Add-on for Microsoft* SCCM before version 2.1.10 may allow an authenticated user to potentially enable escal… Scs Add On For Microsoft Sccm Mitigation only Fix from $1,9502020-11-12 HIGH 7.8 CVE-2020-13771 Various components in Ivanti Endpoint Manager through 2020.1.1 rely on Windows search order when loading a (nonexistent) library file, allowing (unde… Endpoint Manager after 2020.1.1 Fix from $1,9502020-11-12 HIGH 7.8 CVE-2020-5992 NVIDIA GeForce NOW application software on Windows, all versions prior to 2.0.25.119, contains a vulnerability in its open-source software dependency… Geforce Now 2.0.25.119+ Fix from $1,9502020-11-11 HIGH 7.8 CVE-2020-25174 A DLL hijacking vulnerability in the B. Braun OnlineSuite Version AP 3.0 and earlier allows local attackers to execute code on the system as a high p… Onlinesuite Application Package after 3.0 Fix from $1,9502020-11-06 CRITICAL 9.8 CVE-2020-27955EPSS 83% Git LFS 2.12.0 allows Remote Code Execution. Git Large File Storage No fix yet Fix from $2,3002020-11-05 HIGH 7.8 CVE-2020-27708 A vulnerability exists in the Origin Client that could allow a non-Administrative user to elevate their access to either Administrator or System. Onc… Origin after 10.5.86 Fix from $1,9502020-11-02 HIGH 8.6 CVE-2020-5145 SonicWall Global VPN client version 4.10.4.0314 and earlier have an insecure library loading (DLL hijacking) vulnerability. Successful exploitation c… Global Vpn Client after 4.10.4.0314 Fix from $1,9502020-10-28 HIGH 7.8 CVE-2020-24425 Dreamweaver version 20.2 (and earlier) is affected by an uncontrolled search path element vulnerability that could lead to privilege escalation. Succ… Dreamweaver after 20.2 Fix from $1,9502020-10-21 HIGH 7.8 CVE-2020-24419 Adobe After Effects version 17.1.1 (and earlier) for Windows is affected by an uncontrolled search path vulnerability that could result in arbitrary … After Effects after 17.1.1 Fix from $1,9502020-10-21 HIGH 7.8 CVE-2020-24420 Adobe Photoshop for Windows version 21.2.1 (and earlier) is affected by an uncontrolled search path element vulnerability that could result in arbitr… Photoshop after 21.2.1 Fix from $1,9502020-10-21 HIGH 7.8 CVE-2020-24423 Adobe Media Encoder version 14.4 (and earlier) for Windows is affected by an uncontrolled search path vulnerability that could result in arbitrary co… Media Encoder after 14.4 Fix from $1,9502020-10-21 HIGH 7.8 CVE-2020-24424 Adobe Premiere Pro version 14.4 (and earlier) is affected by an uncontrolled search path element that could result in arbitrary code execution in the… Premiere Pro after 14.4 Fix from $1,9502020-10-21 HIGH 7.8 CVE-2020-24422 Adobe Creative Cloud Desktop Application version 5.2 (and earlier) and 2.1 (and earlier) for Windows is affected by an uncontrolled search path vulne… Creative Cloud after 5.2 Fix from $1,9502020-10-21 HIGH 7.8 CVE-2020-8345 A DLL search path vulnerability was reported in the Lenovo HardwareScan Plugin for the Lenovo Vantage hardware scan feature prior to version 1.0.46.1… Hardware Scan 1.0.46.11+ Fix from $1,9502020-10-14 HIGH 7.8 CVE-2020-26947 monero-wallet-gui in Monero GUI before 0.17.1.0 includes the . directory in an embedded RPATH (with a preference ahead of /usr/lib), which allows loc… Monero 0.17.1.0+ Fix from $1,9502020-10-10 HIGH 7.8 CVE-2019-19115 An escalation of privilege vulnerability in Nahimic APO Software Component Driver 1.4.2, 1.5.0, 1.5.1, 1.6.1 and 1.6.2 allows an attacker to execute … Apo Software Component No fix yet Fix from $1,9502020-10-08 HIGH 7.8 CVE-2020-26894 LiveCode v9.6.1 on Windows allows local, low-privileged users to gain privileges by creating a malicious "cmd.exe" in the folder of the vulnerable Li… Wildlife Issues In The New Millennium Patch available Fix from $1,9502020-10-08 HIGH 8.4 CVE-2020-3535 A vulnerability in the loading mechanism of specific DLLs in the Cisco Webex Teams client for Windows could allow an authenticated, local attacker to… Webex Teams after 3.0.16040.0 Fix from $1,9502020-10-08 HIGH 7.8 CVE-2020-24356 `cloudflared` versions prior to 2020.8.1 contain a local privilege escalation vulnerability on Windows systems. When run on a Windows system, `cloudf… Cloudflared 2020.8.1+ Fix from $1,9502020-10-02 HIGH 7.8 CVE-2020-26538 An issue was discovered in Foxit Reader and PhantomPDF before 10.1. It allows attackers to execute arbitrary code via a Trojan horse taskkill.exe in … Foxit Reader 10.1+ Fix from $1,9502020-10-02 HIGH 8.8 CVE-2020-15663 If Firefox is installed to a user-writable directory, the Mozilla Maintenance Service would execute updater.exe from the install location with system… Firefox 68.12 / 78.2+ Fix from $1,9502020-10-01 HIGH 7.8 CVE-2020-6654 A DLL Hijacking vulnerability in Eaton's 9000x Programming and Configuration Software v 2.0.38 and prior allows an attacker to execute arbitrary code… 9000x Programming And Configuration Software after 2.0.38 Fix from $1,9502020-09-30 HIGH 7.8 CVE-2020-3979 InstallBuilder for Qt Windows (versions prior to 20.7.0) installers look for plugins at a predictable location at initialization time, writable by no… Installbuilder 20.7.0+ Fix from $1,9502020-09-18 MEDIUM 6.5 CVE-2020-7358 In AppSpider installer versions prior to 7.2.126, the AppSpider installer calls an executable which can be placed in the appropriate directory by an … Appspider 7.2.126+ Fix from $1,6002020-09-18