Filtered by vendor
Subscriptions
Total
812 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2023-41117 | 1 Enterprisedb | 1 Postgres Advanced Server | 2024-11-21 | 8.8 High |
An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0. It contain packages, standalone packages, and functions that run SECURITY DEFINER but are inadequately secured against search_path attacks. | ||||
CVE-2023-41091 | 1 Intel | 1 Mpi Library | 2024-11-21 | 6.7 Medium |
Uncontrolled search path for some Intel(R) MPI Library Software before version 2021.11 may allow an authenticated user to potentially enable escalation of privilege via local access. | ||||
CVE-2023-40352 | 1 Mcafee | 1 Safe Connect | 2024-11-21 | 7.2 High |
McAfee Safe Connect before 2.16.1.126 may allow an adversary with system privileges to achieve privilege escalation by loading arbitrary DLLs. | ||||
CVE-2023-40156 | 1 Intel | 1 System Support Utility | 2024-11-21 | 6.7 Medium |
Uncontrolled search path element in some Intel(R) SSU software before version 3.0.0.2 may allow an authenticated user to potentially enable escalation of privilege via local access. | ||||
CVE-2023-40155 | 2024-11-21 | 6.7 Medium | ||
Uncontrolled search path for some Intel(R) CST software before version 2.1.10300 may allow an authenticated user to potentially enable escalation of privilege via local access. | ||||
CVE-2023-3662 | 1 Codesys | 1 Development System | 2024-11-21 | 7.3 High |
In CODESYS Development System versions from 3.5.17.0 and prior to 3.5.19.20 a vulnerability allows for execution of binaries from the current working directory in the users context . | ||||
CVE-2023-3252 | 1 Tenable | 1 Nessus | 2024-11-21 | 6.8 Medium |
An arbitrary file write vulnerability exists where an authenticated, remote attacker with administrator privileges could alter logging variables to overwrite arbitrary files on the remote host with log data, which could lead to a denial of service condition. | ||||
CVE-2023-3091 | 1 Captura Project | 1 Captura | 2024-11-21 | 7 High |
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Captura up to 8.0.0. It has been declared as critical. This vulnerability affects unknown code in the library CRYPTBASE.dll. The manipulation leads to uncontrolled search path. Attacking locally is a requirement. The complexity of an attack is rather high. The exploitation appears to be difficult. The identifier of this vulnerability is VDB-230668. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. | ||||
CVE-2023-3078 | 1 Lenovo | 1 Universal Device Client | 2024-11-21 | 7.8 High |
An uncontrolled search path vulnerability was reported in the Lenovo Universal Device Client (UDC) that could allow an attacker with local access to execute code with elevated privileges. | ||||
CVE-2023-39932 | 1 Intel | 1 System Usage Report For Gameplay | 2024-11-21 | 6.7 Medium |
Uncontrolled search path in the Intel(R) SUR for Gameplay Software before version 2.0.1901 may allow a privillaged user to potentially enable escalation of privilege via local access. | ||||
CVE-2023-39929 | 2024-11-21 | 6.7 Medium | ||
Uncontrolled search path in some Libva software maintained by Intel(R) before version 2.20.0 may allow an authenticated user to potentially enable escalation of privilege via local access. | ||||
CVE-2023-39374 | 1 Forescout | 1 Secureconnector | 2024-11-21 | 7.8 High |
ForeScout NAC SecureConnector version 11.2 - CWE-427: Uncontrolled Search Path Element | ||||
CVE-2023-39254 | 2024-11-21 | 6.7 Medium | ||
Dell Update Package (DUP), Versions prior to 4.9.10 contain an Uncontrolled Search Path vulnerability. A malicious user with local access to the system could potentially exploit this vulnerability to run arbitrary code as admin. | ||||
CVE-2023-38566 | 1 Intel | 1 Implicit Spmd Program Compiler | 2024-11-21 | 6.7 Medium |
Uncontrolled search path in some Intel(R) ISPC software before version 1.21.0 may allow an authenticated user to potentially enable escalation of privilege via local access. | ||||
CVE-2023-37849 | 1 Watchguard | 1 Panda Security Vpn | 2024-11-21 | 6.5 Medium |
A DLL hijacking vulnerability in Panda Security VPN for Windows prior to version v15.14.8 allows attackers to execute arbitrary code via placing a crafted DLL file in the same directory as PANDAVPN.exe. | ||||
CVE-2023-37490 | 1 Sap | 1 Businessobjects Business Intelligence | 2024-11-21 | 7.6 High |
SAP Business Objects Installer - versions 420, 430, allows an authenticated attacker within the network to overwrite an executable file created in a temporary directory during the installation process. On replacing this executable with a malicious file, an attacker can completely compromise the confidentiality, integrity, and availability of the system | ||||
CVE-2023-36853 | 1 Keysight | 1 Geolocation Server | 2024-11-21 | 7.8 High |
In Keysight Geolocation Server v2.4.2 and prior, a low privileged attacker could create a local ZIP file containing a malicious script in any location. The attacker could abuse this to load a DLL with SYSTEM privileges. | ||||
CVE-2023-36493 | 1 Intel | 1 Software Development Kit For Opencl | 2024-11-21 | 6.7 Medium |
Uncontrolled search path in some Intel(R) SDK for OpenCL(TM) Applications software may allow an authenticated user to potentially enable escalation of privilege via local access. | ||||
CVE-2023-36344 | 1 Dieboldnixdorf | 1 Vynamic View | 2024-11-21 | 7.8 High |
An issue in Diebold Nixdorf Vynamic View Console v.5.3.1 and before allows a local attacker to execute arbitrary code via not restricting the search path for required DLLs and not verifying the signature. | ||||
CVE-2023-35897 | 1 Ibm | 2 Storage Protect, Storage Protect Client | 2024-11-21 | 8.4 High |
IBM Spectrum Protect Client and IBM Storage Protect for Virtual Environments 8.1.0.0 through 8.1.19.0 could allow a local user to execute arbitrary code on the system using a specially crafted file, caused by a DLL hijacking flaw. IBM X-Force ID: 259246. |