Total
1096 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2023-6740 | 2 Checkmk, Tribe29 | 2 Checkmk, Checkmk | 2024-11-21 | N/A | 8.8 HIGH |
|
Privilege escalation in jar_signature agent plugin in Checkmk before 2.2.0p18, 2.1.0p38 and 2.0.0p39 allows local user to escalate privileges
|
|||||
| CVE-2023-6401 | 1 Notepad-plus-plus | 1 Notepad\+\+ | 2024-11-21 | 4.3 MEDIUM | 5.3 MEDIUM |
|
A vulnerability classified as problematic was found in NotePad++ up to 8.1. Affected by this vulnerability is an unknown functionality of the file dbghelp.exe. The manipulation leads to uncontrolled search path. An attack has to be approached locally. The identifier VDB-246421 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
|
|||||
| CVE-2023-6338 | 1 Lenovo | 1 Universal Device Client | 2024-11-21 | N/A | 7.8 HIGH |
|
Uncontrolled search path vulnerabilities were reported in the Lenovo Universal Device Client (UDC) that could allow an attacker with local access to execute code with elevated privileges.
|
|||||
| CVE-2023-6235 | 1 Duetdisplay | 1 Duet Display | 2024-11-21 | N/A | 7.8 HIGH |
|
An uncontrolled search path element vulnerability has been found in the Duet Display product, affecting version 2.5.9.1. An attacker could place an arbitrary libusk.dll file in the C:\Users\user\AppData\Local\Microsoft\WindowsApps\ directory, which could lead to the execution and persistence of arbitrary code.
|
|||||
| CVE-2023-5463 | 1 Xinje | 1 Xdppro | 2024-11-21 | 6.8 MEDIUM | 7.8 HIGH |
|
A vulnerability was found in XINJE XDPPro up to 3.7.17a. It has been rated as critical. Affected by this issue is some unknown functionality in the library cfgmgr32.dll. The manipulation leads to uncontrolled search path. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. VDB-241586 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
|
|||||
| CVE-2023-51710 | 2024-11-21 | N/A | 4.2 MEDIUM | ||
|
EMS SQL Manager 3.6.2 (build 55333) for Oracle allows DLL hijacking: a user can trigger the execution of arbitrary code every time the product is executed.
|
|||||
| CVE-2023-4931 | 1 Plesk | 1 Plesk | 2024-11-21 | N/A | 6.3 MEDIUM |
|
Uncontrolled search path element vulnerability in Plesk Installer affects version 3.27.0.0. A local attacker could execute arbitrary code by injecting DLL files into the same folder where the application is installed, resulting in DLL hijacking in edputil.dll, samlib.dll, urlmon.dll, sspicli.dll, propsys.dll and profapi.dll files.
|
|||||
| CVE-2023-4770 | 2 4d, Microsoft | 3 4d, Server, Windows | 2024-11-21 | N/A | 6.5 MEDIUM |
|
An uncontrolled search path element vulnerability has been found on 4D and 4D server Windows executables applications, affecting version 19 R8 100218. This vulnerability consists in a DLL hijacking by replacing x64 shfolder.dll in the installation path, causing an arbitrary code execution.
|
|||||
| CVE-2023-4632 | 1 Lenovo | 1 System Update | 2024-11-21 | N/A | 7.8 HIGH |
|
An uncontrolled search path vulnerability was reported in Lenovo System Update that could allow an attacker with local access to execute code with elevated privileges.
|
|||||
| CVE-2023-48861 | 2 Baidu, Microsoft | 2 Ttplayer, Windows | 2024-11-21 | N/A | 7.8 HIGH |
|
DLL hijacking vulnerability in TTplayer version 7.0.2, allows local attackers to escalate privileges and execute arbitrary code via urlmon.dll.
|
|||||
| CVE-2023-47454 | 1 Netease | 1 Cloudmusic | 2024-11-21 | N/A | 7.8 HIGH |
|
An Untrusted search path vulnerability in NetEase CloudMusic 2.10.4 for Windows allows local users to gain escalated privileges through the urlmon.dll file in the current working directory.
|
|||||
| CVE-2023-47453 | 1 Sohu | 1 Video Player | 2024-11-21 | N/A | 7.8 HIGH |
|
An Untrusted search path vulnerability in Sohu Video Player 7.0.15.0 allows local users to gain escalated privileges through the version.dll file in the current working directory.
|
|||||
| CVE-2023-47452 | 1 Notepad-plus-plus | 1 Notepad\+\+ | 2024-11-21 | N/A | 7.8 HIGH |
|
An Untrusted search path vulnerability in notepad++ 6.5 allows local users to gain escalated privileges through the msimg32.dll file in the current working directory.
|
|||||
| CVE-2023-47113 | 2 Bleachbit, Microsoft | 2 Bleachbit, Windows | 2024-11-21 | N/A | 7.3 HIGH |
|
BleachBit cleans files to free disk space and to maintain privacy. BleachBit for Windows up to version 4.4.2 is vulnerable to a DLL Hijacking vulnerability. By placing a DLL in the Folder c:\DLLs, an attacker can run arbitrary code on every execution of BleachBit for Windows. This issue has been patched in version 4.5.0.
|
|||||
| CVE-2023-46814 | 2 Microsoft, Videolan | 2 Windows, Vlc Media Player | 2024-11-21 | N/A | 7.8 HIGH |
|
A binary hijacking vulnerability exists within the VideoLAN VLC media player before 3.0.19 on Windows. The uninstaller attempts to execute code with elevated privileges out of a standard user writable location. Standard users may use this to gain arbitrary code execution as SYSTEM.
|
|||||
| CVE-2023-45252 | 2 Huddly, Microsoft | 2 Huddlycameraservice, Windows | 2024-11-21 | N/A | 7.8 HIGH |
|
DLL Hijacking vulnerability in Huddly HuddlyCameraService before version 8.0.7, not including version 7.99, due to the installation of the service in a directory that grants write privileges to standard users, allows attackers to manipulate files, execute arbitrary code, and escalate privileges.
|
|||||
| CVE-2023-45248 | 2 Acronis, Microsoft | 2 Agent, Windows | 2024-11-21 | N/A | 7.3 HIGH |
|
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (Windows) before build 36497, Acronis Cyber Protect 16 (Windows) before build 37391.
|
|||||
| CVE-2023-44220 | 1 Sonicwall | 1 Netextender | 2024-11-21 | N/A | 7.3 HIGH |
|
SonicWall NetExtender Windows (32-bit and 64-bit) client 10.2.336 and earlier versions have a DLL Search Order Hijacking vulnerability in the start-up DLL component. Successful exploitation via a local attacker could result in command execution in the target system.
|
|||||
| CVE-2023-43751 | 2024-11-21 | N/A | 6.7 MEDIUM | ||
|
Uncontrolled search path in Intel(R) Graphics Command Center Service bundled in some Intel(R) Graphics Windows DCH driver software before versions 31.0.101.3790/31.0.101.2114 may allow an authenticated user to potentially enable escalation of privilege via local access.
|
|||||
| CVE-2023-43064 | 1 Ibm | 1 I | 2024-11-21 | N/A | 7.0 HIGH |
|
Facsimile Support for IBM i 7.2, 7.3, 7.4, and 7.5 could allow a local user to gain elevated privileges due to an unqualified library call. A malicious actor could cause arbitrary code to run with the privilege of the user invoking the facsimile support. IBM X-Force ID: 267689.
|
|||||
| CVE-2023-41790 | 1 Artica | 1 Pandora Fms | 2024-11-21 | N/A | 7.6 HIGH |
|
Uncontrolled Search Path Element vulnerability in Pandora FMS on all allows Leveraging/Manipulating Configuration File Search Paths. This vulnerability allows to access the server configuration file and to compromise the database. This issue affects Pandora FMS: from 700 through 773.
|
|||||
| CVE-2023-41787 | 1 Artica | 1 Pandora Fms | 2024-11-21 | N/A | 6.0 MEDIUM |
|
Uncontrolled Search Path Element vulnerability in Pandora FMS on all allows Leveraging/Manipulating Configuration File Search Paths. This vulnerability allows access to files with sensitive information. This issue affects Pandora FMS: from 700 through 772.
|
|||||
| CVE-2023-41613 | 2 Ezviz, Microsoft | 2 Ezviz Studio, Windows | 2024-11-21 | N/A | 7.8 HIGH |
|
EzViz Studio v2.2.0 is vulnerable to DLL hijacking.
|
|||||
| CVE-2023-41091 | 1 Intel | 1 Mpi Library | 2024-11-21 | N/A | 6.7 MEDIUM |
|
Uncontrolled search path for some Intel(R) MPI Library Software before version 2021.11 may allow an authenticated user to potentially enable escalation of privilege via local access.
|
|||||
| CVE-2023-40596 | 2 Microsoft, Splunk | 2 Windows, Splunk | 2024-11-21 | N/A | 7.0 HIGH |
|
In Splunk Enterprise versions earlier than 8.2.12, 9.0.6, and 9.1.1, a dynamic link library (DLL) that ships with Splunk Enterprise references an insecure path for the OPENSSLDIR build definition. An attacker can abuse this reference and subsequently install malicious code to achieve privilege escalation on the Windows machine.
|
|||||
| CVE-2023-40352 | 1 Mcafee | 1 Safe Connect | 2024-11-21 | N/A | 7.2 HIGH |
|
McAfee Safe Connect before 2.16.1.126 may allow an adversary with system privileges to achieve privilege escalation by loading arbitrary DLLs.
|
|||||
| CVE-2023-40156 | 1 Intel | 1 System Support Utility | 2024-11-21 | N/A | 6.7 MEDIUM |
|
Uncontrolled search path element in some Intel(R) SSU software before version 3.0.0.2 may allow an authenticated user to potentially enable escalation of privilege via local access.
|
|||||
| CVE-2023-40155 | 2024-11-21 | N/A | 6.7 MEDIUM | ||
|
Uncontrolled search path for some Intel(R) CST software before version 2.1.10300 may allow an authenticated user to potentially enable escalation of privilege via local access.
|
|||||
| CVE-2023-3662 | 1 Codesys | 1 Development System | 2024-11-21 | N/A | 7.3 HIGH |
|
In CODESYS Development System versions from 3.5.17.0 and prior to 3.5.19.20 a vulnerability allows for execution of binaries from the current working directory in the users context .
|
|||||
| CVE-2023-3252 | 1 Tenable | 1 Nessus | 2024-11-21 | N/A | 6.8 MEDIUM |
|
An arbitrary file write vulnerability exists where an authenticated, remote attacker with administrator privileges could alter logging variables to overwrite arbitrary files on the remote host with log data, which could lead to a denial of service condition.
|
|||||
| CVE-2023-3091 | 1 Captura Project | 1 Captura | 2024-11-21 | 6.0 MEDIUM | 7.0 HIGH |
|
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Captura up to 8.0.0. It has been declared as critical. This vulnerability affects unknown code in the library CRYPTBASE.dll. The manipulation leads to uncontrolled search path. Attacking locally is a requirement. The complexity of an attack is rather high. The exploitation appears to be difficult. The identifier of this vulnerability is VDB-230668. NOTE: This vulnerability only affects products that are no longer supported by the maint ...
Show More |
|||||
| CVE-2023-3078 | 1 Lenovo | 1 Universal Device Client | 2024-11-21 | N/A | 7.8 HIGH |
|
An uncontrolled search path vulnerability was reported in the Lenovo Universal Device Client (UDC) that could allow an attacker with local access to execute code with elevated privileges.
|
|||||
| CVE-2023-39932 | 1 Intel | 1 System Usage Report For Gameplay | 2024-11-21 | N/A | 6.7 MEDIUM |
|
Uncontrolled search path in the Intel(R) SUR for Gameplay Software before version 2.0.1901 may allow a privillaged user to potentially enable escalation of privilege via local access.
|
|||||
| CVE-2023-39929 | 2024-11-21 | N/A | 6.7 MEDIUM | ||
|
Uncontrolled search path in some Libva software maintained by Intel(R) before version 2.20.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
|
|||||
| CVE-2023-39374 | 1 Forescout | 1 Secureconnector | 2024-11-21 | N/A | 7.8 HIGH |
|
ForeScout NAC SecureConnector version 11.2 - CWE-427: Uncontrolled Search Path Element
|
|||||
| CVE-2023-38566 | 1 Intel | 1 Implicit Spmd Program Compiler | 2024-11-21 | N/A | 6.7 MEDIUM |
|
Uncontrolled search path in some Intel(R) ISPC software before version 1.21.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
|
|||||
| CVE-2023-37849 | 1 Watchguard | 1 Panda Security Vpn | 2024-11-21 | N/A | 6.5 MEDIUM |
|
A DLL hijacking vulnerability in Panda Security VPN for Windows prior to version v15.14.8 allows attackers to execute arbitrary code via placing a crafted DLL file in the same directory as PANDAVPN.exe.
|
|||||
| CVE-2023-37490 | 1 Sap | 1 Businessobjects Business Intelligence | 2024-11-21 | N/A | 7.6 HIGH |
|
SAP Business Objects Installer - versions 420, 430, allows an authenticated attacker within the network to overwrite an executable file created in a temporary directory during the installation process. On replacing this executable with a malicious file, an attacker can completely compromise the confidentiality, integrity, and availability of the system
|
|||||
| CVE-2023-36853 | 1 Keysight | 1 Geolocation Server | 2024-11-21 | N/A | 7.8 HIGH |
|
In Keysight Geolocation Server v2.4.2 and prior, a low privileged attacker could create a local ZIP file containing a malicious script in any location. The attacker could abuse this to load a DLL with SYSTEM privileges.
|
|||||
| CVE-2023-36493 | 1 Intel | 1 Software Development Kit For Opencl | 2024-11-21 | N/A | 6.7 MEDIUM |
|
Uncontrolled search path in some Intel(R) SDK for OpenCL(TM) Applications software may allow an authenticated user to potentially enable escalation of privilege via local access.
|
|||||