Skip to main content

CWE archive

CWE-427 CVEs

Programmatic archive

1,199 CVEs tagged with CWE-42724 Critical, 808 High, 359 Medium, 6 Low, 2 Unrated.

CVE-2019-1010100

Published Jul 19, 2019

Akeo Consulting Rufus 3.0 and earlier is affected by: DLL search order hijacking. The impact is: Arbitrary code execution WITH escalation of privilege. The component is: Executabl…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-7956

Published Jul 18, 2019

Adobe Dreamweaver direct download installer versions 19.0 and below, 18.0 and below have an Insecure Library Loading (DLL hijacking) vulnerability. Successful exploitation could l…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-6825

Published Jul 15, 2019

A CWE-427: Uncontrolled Search Path Element vulnerability exists in ProClima (all versions prior to version 8.0.0) which could allow a malicious DLL file, with the same name of an…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-5629

Published Jul 13, 2019

Rapid7 Insight Agent, version 2.6.3 and prior, suffers from a local privilege escalation due to an uncontrolled DLL search path. Specifically, when Insight Agent 2.6.3 and prior s…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2019-1855

Published Jul 4, 2019

A vulnerability in the loading mechanism of specific dynamic link libraries in Cisco Jabber for Windows could allow an authenticated, local attacker to perform a DLL preloading at…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2019-5443

Published Jul 2, 2019

A non-privileged user or program can put code and a config file in a known non-privileged path (under C:/usr/local/) that will make curl <= 7.65.1 automatically run the code (as a…

CVSS 7.8 · High

CVE-2019-5245

Published Jun 13, 2019

HiSuite 9.1.0.300 versions and earlier contains a DLL hijacking vulnerability. This vulnerability exists due to some DLL file is loaded by HiSuite improperly. And it allows an att…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-12177

Published Jun 3, 2019

Privilege escalation due to insecure directory permissions affecting ViveportDesktopService in HTC VIVEPORT before 1.0.0.36 allows local attackers to escalate privileges via DLL h…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-7093

Published May 24, 2019

Creative Cloud Desktop Application (installer) versions 4.7.0.400 and earlier have an insecure library loading (dll hijacking) vulnerability. Successful exploitation could lead to…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-7840

Published May 22, 2019

A Uncontrolled Search Path Element (CWE-427) vulnerability exists in VideoXpert OpsCenter versions prior to 3.1 which could allow an attacker to cause the system to call an incorr…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-5526

Published May 15, 2019

VMware Workstation (15.x before 15.1.0) contains a DLL hijacking issue because some DLL files are improperly loaded by the application. Successful exploitation of this issue may a…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-6564

Published May 9, 2019

GE Communicator, all versions prior to 4.0.517, allows a non-administrative user to place malicious files within the installer file directory, which may allow an attacker to gain…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2019-6546

Published May 9, 2019

GE Communicator, all versions prior to 4.0.517, allows an attacker to place malicious files within the working directory of the program, which may allow an attacker to manipulate…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2019-1794

Published Apr 18, 2019

A vulnerability in the search path processing of Cisco Directory Connector could allow an authenticated, local attacker to load a binary of their choosing. The vulnerability is du…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-6534

Published Apr 11, 2019

The uncontrolled search path element vulnerability in Gemalto Sentinel UltraPro Client Library ux32w.dll Versions 1.3.0, 1.3.1, and 1.3.2 enables an attacker to load and execute a…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-4094

Published Mar 21, 2019

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 binaries load shared libraries from an untrusted path potentially giving low privilege…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1890

Published Mar 11, 2019

IBM SDK, Java Technology Edition Version 8 on the AIX platform uses absolute RPATHs which may facilitate code injection and privilege elevation by local users. IBM X-Force ID: 152…

CVSS 5.6 · Medium
Vendor/product tagsBeta · best-effort
Showing 1,101-1,125 of 1,199 CVEsPage 45 of 48