Show filters
74 Total Results
Displaying 31-40 of 74
Sort by:
Attacker Value
Unknown

CVE-2020-0570

Disclosure Date: September 14, 2020 (last updated February 22, 2025)
Uncontrolled search path in the QT Library before 5.14.0, 5.12.7 and 5.9.10 may allow an authenticated user to potentially enable elevation of privilege via local access.
Attacker Value
Unknown

CVE-2020-7315

Disclosure Date: September 09, 2020 (last updated February 22, 2025)
DLL Injection Vulnerability in McAfee Agent (MA) for Windows prior to 5.6.6 allows local users to execute arbitrary code via careful placement of a malicious DLL.
Attacker Value
Unknown

CVE-2020-6654

Disclosure Date: September 07, 2020 (last updated February 22, 2025)
A DLL Hijacking vulnerability in Eaton's 9000x Programming and Configuration Software v 2.0.38 and prior allows an attacker to execute arbitrary code by replacing the required DLLs with malicious DLLs when the software try to load vci11un6.DLL and cinpl.DLL.
Attacker Value
Unknown

CVE-2020-4545

Disclosure Date: September 03, 2020 (last updated February 22, 2025)
IBM Aspera Connect 3.9.9 could allow a remote attacker to execute arbitrary code on the system, caused by improper loading of Dynamic Link Libraries by the import feature. By persuading a victim to open a specially-crafted .DLL file, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 183190.
Attacker Value
Unknown

CVE-2020-14350

Disclosure Date: August 24, 2020 (last updated February 22, 2025)
It was found that some PostgreSQL extensions did not use search_path safely in their installation script. An attacker with sufficient privileges could use this flaw to trick an administrator into executing a specially crafted script, during the installation or update of such extension. This affects PostgreSQL versions before 12.4, before 11.9, before 10.14, before 9.6.19, and before 9.5.23.
Attacker Value
Unknown

CVE-2020-10610

Disclosure Date: July 24, 2020 (last updated February 21, 2025)
In OSIsoft PI System multiple products and versions, a local attacker can modify a search path and plant a binary to exploit the affected PI System software to take control of the local computer at Windows system privilege level, resulting in unauthorized information disclosure, deletion, or modification.
Attacker Value
Unknown

CVE-2020-8317

Disclosure Date: July 24, 2020 (last updated February 21, 2025)
A DLL search path vulnerability was reported in Lenovo Drivers Management prior to version 2.7.1128.1046 that could allow an authenticated user to execute code with elevated privileges.
Attacker Value
Unknown

CVE-2020-15009

Disclosure Date: July 20, 2020 (last updated February 21, 2025)
AsusScreenXpertServicec.exe and ScreenXpertUpgradeServiceManager.exe in ScreenPad2_Upgrade_Tool.msi V1.0.3 for ASUS PCs with ScreenPad 1.0 (UX450FDX, UX550GDX and UX550GEX) could lead to unsigned code execution with no additional restrictions when a user puts an application at a particular path with a particular file name.
Attacker Value
Unknown

CVE-2020-15801

Disclosure Date: July 17, 2020 (last updated February 21, 2025)
In Python 3.8.4, sys.path restrictions specified in a python38._pth file are ignored, allowing code to be loaded from arbitrary locations. The <executable-name>._pth file (e.g., the python._pth file) is not affected.
Attacker Value
Unknown

CVE-2020-9673

Disclosure Date: July 17, 2020 (last updated February 21, 2025)
Adobe ColdFusion 2016 update 15 and earlier versions, and ColdFusion 2018 update 9 and earlier versions have a dll search-order hijacking vulnerability. Successful exploitation could lead to privilege escalation.