Vulnerabilities > Unquoted Search Path or Element

DATE CVE VULNERABILITY TITLE RISK
2019-10-29 CVE-2019-16647 Unquoted Search Path or Element vulnerability in Maxthon Browser
Unquoted Search Path in Maxthon 5.1.0 to 5.2.7 Browser for Windows.
network
low complexity
maxthon CWE-428
7.2
2019-09-20 CVE-2019-6145 Unquoted Search Path or Element vulnerability in Forcepoint VPN Client 6.6.0
Forcepoint VPN Client for Windows versions lower than 6.6.1 have an unquoted search path vulnerability.
local
low complexity
forcepoint CWE-428
6.7
2019-08-21 CVE-2019-14685 Unquoted Search Path or Element vulnerability in Trendmicro products
A local privilege escalation vulnerability exists in Trend Micro Security 2019 (v15.0) in which, if exploited, would allow an attacker to manipulate a specific product feature to load a malicious service.
local
low complexity
trendmicro CWE-428
7.8
2019-07-19 CVE-2019-7590 Unquoted Search Path or Element vulnerability in Johnsoncontrols Exacqvision Server 9.6/9.8
ExacqVision Server’s services 'exacqVisionServer', 'dvrdhcpserver' and 'mdnsresponder' have an unquoted service path.
local
low complexity
johnsoncontrols CWE-428
7.8
2019-06-20 CVE-2019-8459 Unquoted Search Path or Element vulnerability in Checkpoint products
Check Point Endpoint Security Client for Windows, with the VPN blade, before version E80.83, starts a process without using quotes in the path.
network
low complexity
checkpoint CWE-428
critical
9.8
2019-05-17 CVE-2019-11093 Unquoted Search Path or Element vulnerability in Intel SCS Discovery Utility 12.0.0.129
Unquoted service path in the installer for the Intel(R) SCS Discovery Utility version 12.0.0.129 and earlier may allow an authenticated user to potentially enable escalation of privilege via local access.
local
low complexity
intel CWE-428
6.7
2019-04-08 CVE-2018-20341 Unquoted Search Path or Element vulnerability in Winmagic Securedoc Disk Encryption 4.60.0
WINMAGIC SecureDoc Disk Encryption software before 8.3 has an Unquoted Service Path vulnerability, which could allow an attacker to execute arbitrary code on a target system.
local
low complexity
winmagic CWE-428
7.8
2019-03-18 CVE-2019-6149 Unquoted Search Path or Element vulnerability in Lenovo Dynamic Power Reduction
An unquoted search path vulnerability was identified in Lenovo Dynamic Power Reduction Utility prior to version 2.2.2.0 that could allow a malicious user with local access to execute code with administrative privileges.
local
low complexity
lenovo CWE-428
6.7
2019-01-24 CVE-2018-16098 Unquoted Search Path or Element vulnerability in Lenovo products
In some Lenovo ThinkPads, an unquoted search path vulnerability was found in various versions of the Synaptics Pointing Device driver which could allow unauthorized code execution as a low privilege user.
local
low complexity
lenovo CWE-428
7.8
2019-01-16 CVE-2017-3141 Unquoted Search Path or Element vulnerability in ISC Bind
The BIND installer on Windows uses an unquoted service path which can enable a local user to achieve privilege escalation if the host file system permissions allow this.
local
low complexity
isc CWE-428
7.8