Show filters
57 Total Results
Displaying 11-20 of 57
Sort by:
Attacker Value
Unknown

CVE-2020-5977

Disclosure Date: October 23, 2020 (last updated February 22, 2025)
NVIDIA GeForce Experience, all versions prior to 3.20.5.70, contains a vulnerability in NVIDIA Web Helper NodeJS Web Server in which an uncontrolled search path is used to load a node module, which may lead to code execution, denial of service, escalation of privileges, and information disclosure.
Attacker Value
Unknown

CVE-2020-8338

Disclosure Date: October 14, 2020 (last updated February 22, 2025)
A DLL search path vulnerability was reported in Lenovo Diagnostics prior to version 4.35.4 that could allow a user with local access to execute code on the system.
Attacker Value
Unknown

CVE-2020-10733

Disclosure Date: September 16, 2020 (last updated February 22, 2025)
The Windows installer for PostgreSQL 9.5 - 12 invokes system-provided executables that do not have fully-qualified paths. Executables in the directory where the installer loads or the current working directory take precedence over the intended executables. An attacker having permission to add files into one of those directories can use this to execute arbitrary code with the installer's administrative rights.
Attacker Value
Unknown

CVE-2020-0570

Disclosure Date: September 14, 2020 (last updated February 22, 2025)
Uncontrolled search path in the QT Library before 5.14.0, 5.12.7 and 5.9.10 may allow an authenticated user to potentially enable elevation of privilege via local access.
Attacker Value
Unknown

CVE-2020-7315

Disclosure Date: September 09, 2020 (last updated February 22, 2025)
DLL Injection Vulnerability in McAfee Agent (MA) for Windows prior to 5.6.6 allows local users to execute arbitrary code via careful placement of a malicious DLL.
Attacker Value
Unknown

CVE-2020-6654

Disclosure Date: September 07, 2020 (last updated February 22, 2025)
A DLL Hijacking vulnerability in Eaton's 9000x Programming and Configuration Software v 2.0.38 and prior allows an attacker to execute arbitrary code by replacing the required DLLs with malicious DLLs when the software try to load vci11un6.DLL and cinpl.DLL.
Attacker Value
Unknown

CVE-2020-4545

Disclosure Date: September 03, 2020 (last updated February 22, 2025)
IBM Aspera Connect 3.9.9 could allow a remote attacker to execute arbitrary code on the system, caused by improper loading of Dynamic Link Libraries by the import feature. By persuading a victim to open a specially-crafted .DLL file, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 183190.
Attacker Value
Unknown

CVE-2020-14350

Disclosure Date: August 24, 2020 (last updated February 22, 2025)
It was found that some PostgreSQL extensions did not use search_path safely in their installation script. An attacker with sufficient privileges could use this flaw to trick an administrator into executing a specially crafted script, during the installation or update of such extension. This affects PostgreSQL versions before 12.4, before 11.9, before 10.14, before 9.6.19, and before 9.5.23.
Attacker Value
Unknown

CVE-2020-10610

Disclosure Date: July 24, 2020 (last updated February 21, 2025)
In OSIsoft PI System multiple products and versions, a local attacker can modify a search path and plant a binary to exploit the affected PI System software to take control of the local computer at Windows system privilege level, resulting in unauthorized information disclosure, deletion, or modification.
Attacker Value
Unknown

CVE-2020-8317

Disclosure Date: July 24, 2020 (last updated February 21, 2025)
A DLL search path vulnerability was reported in Lenovo Drivers Management prior to version 2.7.1128.1046 that could allow an authenticated user to execute code with elevated privileges.