Show filters
357 Total Results
Displaying 111-120 of 357
Sort by:
Attacker Value
Unknown
CVE-2022-25969
Disclosure Date: March 17, 2022 (last updated February 23, 2025)
The installer of WPS Office Version 10.8.0.6186 insecurely load VERSION.DLL (or some other DLLs), allowing an attacker to execute arbitrary code with the privilege of the user invoking the installer.
0
Attacker Value
Unknown
CVE-2022-20001
Disclosure Date: March 14, 2022 (last updated February 23, 2025)
fish is a command line shell. fish version 3.1.0 through version 3.3.1 is vulnerable to arbitrary code execution. git repositories can contain per-repository configuration that change the behavior of git, including running arbitrary commands. When using the default configuration of fish, changing to a directory automatically runs `git` commands in order to display information about the current repository in the prompt. If an attacker can convince a user to change their current directory into one controlled by the attacker, such as on a shared file system or extracted archive, fish will run arbitrary commands under the attacker's control. This problem has been fixed in fish 3.4.0. Note that running git in these directories, including using the git tab completion, remains a potential trigger for this issue. As a workaround, remove the `fish_git_prompt` function from the prompt.
0
Attacker Value
Unknown
CVE-2022-23401
Disclosure Date: March 11, 2022 (last updated February 23, 2025)
The following Yokogawa Electric products contain insecure DLL loading issues. CENTUM CS 3000 versions from R3.08.10 to R3.09.00, CENTUM VP versions from R4.01.00 to R4.03.00, from R5.01.00 to R5.04.20, and from R6.01.00 to R6.08.00, Exaopc versions from R3.72.00 to R3.79.00.
0
Attacker Value
Unknown
CVE-2022-26337
Disclosure Date: March 08, 2022 (last updated February 23, 2025)
Trend Micro Password Manager (Consumer) installer version 5.0.0.1262 and below is vulnerable to an Uncontrolled Search Path Element vulnerability that could allow an attacker to use a specially crafted file to exploit the vulnerability and escalate local privileges on the affected machine.
0
Attacker Value
Unknown
CVE-2022-26319
Disclosure Date: March 08, 2022 (last updated February 23, 2025)
An installer search patch element vulnerability in Trend Micro Portable Security 3.0 Pro, 3.0 and 2.0 could allow a local attacker to place an arbitrarily generated DLL file in an installer folder to elevate local privileges. Please note: an attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability.
0
Attacker Value
Unknown
CVE-2022-22943
Disclosure Date: March 03, 2022 (last updated February 23, 2025)
VMware Tools for Windows (11.x.y and 10.x.y prior to 12.0.0) contains an uncontrolled search path vulnerability. A malicious actor with local administrative privileges in the Windows guest OS, where VMware Tools is installed, may be able to execute code with system privileges in the Windows guest OS due to an uncontrolled search path element.
0
Attacker Value
Unknown
CVE-2022-23410
Disclosure Date: February 14, 2022 (last updated February 23, 2025)
AXIS IP Utility before 4.18.0 allows for remote code execution and local privilege escalation by the means of DLL hijacking. IPUtility.exe would attempt to load DLLs from its current working directory which could allow for remote code execution if a compromised DLL would be placed in the same folder.
0
Attacker Value
Unknown
CVE-2022-23853
Disclosure Date: February 11, 2022 (last updated February 23, 2025)
The LSP (Language Server Protocol) plugin in KDE Kate before 21.12.2 and KTextEditor before 5.91.0 tries to execute the associated LSP server binary when opening a file of a given type. If this binary is absent from the PATH, it will try running the LSP server binary in the directory of the file that was just opened (due to a misunderstanding of the QProcess API, that was never intended). This can be an untrusted directory.
0
Attacker Value
Unknown
CVE-2022-24955
Disclosure Date: February 11, 2022 (last updated February 23, 2025)
Foxit PDF Reader before 11.2.1 and Foxit PDF Editor before 11.2.1 have an Uncontrolled Search Path Element for DLL files.
0
Attacker Value
Unknown
CVE-2022-0483
Disclosure Date: February 11, 2022 (last updated February 23, 2025)
Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis VSS Doctor (Windows) before build 53
0