Vulnerability index

Browse CVEs

1,198 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Uncontrolled Search Path (DLL Hijack)CWE-427 × clear
HIGH 7.8 CVE-2020-7312 DLL Search Order Hijacking Vulnerability in the installer in McAfee Agent (MA) for Windows prior to 5.6.6 allows local users to execute arbitrary cod… Mcafee Agent 5.6.6+ Fix from $1,9502020-09-10 HIGH 7.8 CVE-2019-3881 Bundler prior to 2.1.0 uses a predictable path in /tmp/, created with insecure permissions as a storage location for gems, if locations under the use… Bundler 2.1.0+ Fix from $1,9502020-09-04 HIGH 7.8 CVE-2020-24158 360 Speed Browser 12.0.1247.0 has a DLL hijacking vulnerability, which can be exploited by attackers to execute malicious code. It is a dual-core bro… Speed Browser Mitigation only Fix from $1,9502020-09-03 HIGH 7.8 CVE-2020-24159 NetEase Youdao Dictionary has a DLL hijacking vulnerability, which can be exploited by attackers to gain server permissions. This affects Guangzhou N… Netease Youdao Dictionary Mitigation only Fix from $1,9502020-09-03 HIGH 7.8 CVE-2020-24160 Shenzhen Tencent TIM Windows client 3.0.0.21315 has a DLL hijacking vulnerability, which can be exploited by attackers to execute malicious code. Tim Mitigation only Fix from $1,9502020-09-03 HIGH 7.8 CVE-2020-24161 Guangzhou NetEase Mail Master 4.14.1.1004 on Windows has a DLL hijacking vulnerability. Attackers can use this vulnerability to execute malicious cod… Netease Mail Master Mitigation only Fix from $1,9502020-09-03 HIGH 7.8 CVE-2020-24162 The Shenzhen Tencent app 5.8.2.5300 for PC platforms (from Tencent App Center) has a DLL hijacking vulnerability. Attackers can use this vulnerabilit… Tencent Mitigation only Fix from $1,9502020-09-03 HIGH 7.8 CVE-2020-25045 Installers of Kaspersky Security Center and Kaspersky Security Center Web Console prior to 12 & prior to 12 Patch A were vulnerable to a DLL hijackin… Security Center 12+ Fix from $1,9502020-09-02 HIGH 8.6 CVE-2020-15167 In Miller (command line utility) using the configuration file support introduced in version 5.9.0, it is possible for an attacker to cause Miller to … Miller No fix yet Fix from $1,9502020-09-02 MEDIUM 6.7 CVE-2020-5419 RabbitMQ versions 3.8.x prior to 3.8.7 are prone to a Windows-specific binary planting security vulnerability that allows for arbitrary code executio… Rabbitmq Server 3.7.28 / 3.8.7+ Fix from $1,6002020-08-31 HIGH 7.1 CVE-2020-14349 It was found that PostgreSQL versions before 12.4, before 11.9 and before 10.14 did not properly sanitize the search_path during logical replication.… PostgreSQL 10.14 / 11.9+ Fix from $1,9502020-08-24 HIGH 7.8 CVE-2020-9724 Adobe Lightroom versions 9.2.0.10 and earlier have an insecure library loading vulnerability. Successful exploitation could lead to privilege escalat… Lightroom after 9.2.0.10 Fix from $1,9502020-08-19 HIGH 7.8 CVE-2020-3433 KEVEPSS 10% A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, … Anyconnect Secure Mobility Client 4.9.00086+ Fix from $1,9502020-08-17 HIGH 7.8 CVE-2020-9767 A vulnerability related to Dynamic-link Library (“DLL”) loading in the Zoom Sharing Service would allow an attacker who had local access to a machine… Sharing Service Mitigation only Fix from $1,9502020-08-14 HIGH 7.3 CVE-2020-7360 An Uncontrolled Search Path Element (CWE-427) vulnerability in SmartControl version 4.3.15 and versions released before April 15, 2020 may allow an a… Smartcontrol after 4.3.15 Fix from $1,9502020-08-13 HIGH 7.8 CVE-2020-8687 Uncontrolled search path in the installer for Intel(R) RSTe Software RAID Driver for the Intel(R) Server Board M10JNP2SB before version 4.7.0.1119 ma… Rste Software Raid 4.7.0.1119+ Fix from $1,9502020-08-13 MEDIUM 6.7 CVE-2020-15596 The ALPS ALPINE touchpad driver before 8.2206.1717.634, as used on various Dell, HP, and Lenovo laptops, allows attackers to conduct Path Disclosure … Elite X2 1012 G1 Firmware 8.2206.1717.166 / 8.2206.1717.634+ Fix from $1,6002020-08-12 HIGH 7.8 CVE-2020-13177 The support bundler in Teradici PCoIP Standard Agent for Windows and Graphics Agent for Windows versions prior to 20.04.1 and 20.07.0 does not use ha… Graphics Agent 20.04.1+ Fix from $1,9502020-08-11 HIGH 7.8 CVE-2020-15657 Firefox could be made to load attacker-supplied DLL files from the installation directory. This required an attacker that is already capable of placi… Firefox 78.1 / 79.0+ Fix from $1,9502020-08-10 HIGH 7.8 CVE-2020-16143 The seafile-client client 7.0.8 for Seafile is vulnerable to DLL hijacking because it loads exchndl.dll from the current working directory. Seafile Client No fix yet Fix from $1,9502020-07-29 HIGH 7.8 CVE-2020-10610 In OSIsoft PI System multiple products and versions, a local attacker can modify a search path and plant a binary to exploit the affected PI System s… Pi Api after 4.8.0.18 Fix from $1,9502020-07-24 HIGH 7.8 CVE-2020-15722 In version 12.1.0.1004 and below of 360 Total Security,when TPI calls the browser process, there exists a local privilege escalation vulnerability. A… 360 Total Security after 12.1.0.1004 Fix from $1,9502020-07-21 HIGH 7.8 CVE-2020-15723 In the version 12.1.0.1004 and below of 360 Total Security, when the main process of 360 Total Security calls GameChrome.exe, there exists a local pr… 360 Total Security after 12.1.0.1004 Fix from $1,9502020-07-21 HIGH 7.8 CVE-2020-15724 In the version 12.1.0.1005 and below of 360 Total Security, when the Gamefolde calls GameChrome.exe, there exists a local privilege escalation vulner… 360 Total Security after 12.1.0.1005 Fix from $1,9502020-07-21 HIGH 7.8 CVE-2020-12423 When the Windows DLL "webauthn.dll" was missing from the Operating System, and a malicious one was placed in a folder in the user's %PATH%, Firefox m… Firefox 78.0+ Fix from $1,9502020-07-09 HIGH 7.8 CVE-2020-9100 Earlier than HiSuite 10.1.0.500 have a DLL hijacking vulnerability. This vulnerability exists due to some DLL file is loaded by HiSuite improperly. A… Hisuite 10.1.0.500+ Fix from $1,9502020-07-06 HIGH 7.8 CVE-2020-15523 In Python 3.6 through 3.6.10, 3.7 through 3.7.8, 3.8 through 3.8.4rc1, and 3.9 through 3.9.0b4 on Windows, a Trojan horse python3.dll might be used i… Python 3.5.10 / 3.6.12+ Fix from $1,9502020-07-04 HIGH 7.8 CVE-2019-20419 Affected versions of Atlassian Jira Server and Data Center allow remote attackers to execute arbitrary code via a DLL hijacking vulnerability in Tomc… Jira Data Center 8.5.5 / 8.7.2+ Fix from $1,9502020-07-03 HIGH 8.6 CVE-2020-13279 Client side code execution in gitlab-vscode-extension v2.2.0 allows attacker to execute code on user system Gitlab Vscode Extension after 2.2.0 Fix from $1,9502020-06-22 CRITICAL 9.8 CVE-2019-20856 An issue was discovered in Mattermost Desktop App before 4.3.0 on macOS. It allows dylib injection. Mattermost Desktop 4.3.0+ Fix from $2,3002020-06-19