Skip to main content

CWE archive

CWE-427 CVEs

Programmatic archive

1,188 CVEs tagged with CWE-42724 Critical, 799 High, 357 Medium, 6 Low, 2 Unrated.

CVE-2018-12163

Published Sep 12, 2018

A DLL injection vulnerability in the Intel IoT Developers Kit 4.0 installer may allow an authenticated user to potentially escalate privileges using file modification via local ac…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-12160

Published Sep 12, 2018

DLL injection vulnerability in software installer for Intel Data Center Migration Center Software v3.1 and before may allow an authenticated user to potentially execute code using…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-13806

Published Sep 12, 2018

A vulnerability has been identified in SIEMENS TD Keypad Designer (All versions). A DLL hijacking vulnerability exists in all versions of SIEMENS TD Keypad Designer which could al…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-14797

Published Aug 23, 2018

Emerson DeltaV DCS versions 11.3.1, 12.3.1, 13.3.0, 13.3.1, R5 allow a specially crafted DLL file to be placed in the search path and loaded as an internal and valid DLL, which ma…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2018-5235

Published Aug 22, 2018

Norton Utilities (prior to 16.0.3.44) may be susceptible to a DLL Preloading vulnerability, which is a type of issue that can occur when an application looks to call a DLL for exe…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-12805

Published Jul 20, 2018

Adobe Connect versions 9.7.5 and earlier have an Insecure Library Loading vulnerability. Successful exploitation could lead to privilege escalation.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-1000622

Published Jul 9, 2018

The Rust Programming Language rustdoc version Between 0.8 and 1.27.0 contains a CWE-427: Uncontrolled Search Path Element vulnerability in rustdoc plugins that can result in local…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-4938

Published May 19, 2018

Adobe ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions have an exploitable Insecure Library Loading vulnerability. Successful exploitation co…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-5175

Published May 9, 2018

Advantech WebAccess 8.1 and earlier contains a DLL hijacking vulnerability which may allow an attacker to run a malicious DLL file within the search path resulting in execution of…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-6766

Published Mar 27, 2018

Swisscom TVMediaHelper 1.1.0.50 contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on the targeted system. This vulnerability…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-6765

Published Mar 27, 2018

Swisscom MySwisscomAssistant 2.17.1.1065 contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on the targeted system. This vulne…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-5170

Published Jan 18, 2018

An Uncontrolled Search Path Element issue was discovered in Moxa SoftNVR-IA Live Viewer, Version 3.30.3122 and prior versions. An uncontrolled search path element (DLL Hijacking)…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2017-16777

Published Nov 16, 2017

If HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) 5.0.3 is installed but VMware Fusion is not, a local attacker can create a fake application directory and exp…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-12314

Published Nov 16, 2017

A vulnerability in the Cisco FindIT Network Discovery Utility could allow an authenticated, local attacker to perform a DLL preloading attack, potentially causing a partial impact…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-12313

Published Nov 16, 2017

An untrusted search path (aka DLL Preload) vulnerability in the Cisco Network Academy Packet Tracer software could allow an authenticated, local attacker to execute arbitrary code…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-14029

Published Nov 6, 2017

An Uncontrolled Search Path Element issue was discovered in Trihedral VTScada 11.3.03 and prior. The program will execute specially crafted malicious dll files placed on the targe…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-14017

Published Oct 19, 2017

An Uncontrolled Search Path Element issue was discovered in Progea Movicon Version 11.5.1181 and prior. An uncontrolled search path element vulnerability has been identified, whic…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 1,126-1,150 of 1,188 CVEsPage 46 of 48