Vulnerabilities > Untrusted Search Path

DATE CVE VULNERABILITY TITLE RISK
2019-07-17 CVE-2019-13637 Untrusted Search Path vulnerability in Logmeininc Join.Me
In LogMeIn join.me before 3.16.0.5505, an attacker could execute arbitrary commands on a targeted system.
network
low complexity
logmeininc CWE-426
8.8
2019-07-17 CVE-2019-12912 Untrusted Search Path vulnerability in Rdbrck Shift
Redbrick Shift through 3.4.3 allows an attacker to extract emails of services (such as Gmail, Outlook, etc.) used in the application.
local
low complexity
rdbrck CWE-426
5.5
2019-07-11 CVE-2019-12576 Untrusted Search Path vulnerability in Londontrustmedia Private Internet Access VPN Client 82
A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v82 for macOS could allow an authenticated, local attacker to run arbitrary code with elevated privileges.
local
low complexity
londontrustmedia CWE-426
7.8
2019-07-11 CVE-2019-12574 Untrusted Search Path vulnerability in Londontrustmedia Private Internet Access VPN Client 1.0
A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v1.0 for Windows could allow an authenticated, local attacker to run arbitrary code with elevated privileges.
local
low complexity
londontrustmedia CWE-426
7.8
2019-06-12 CVE-2019-10971 Untrusted Search Path vulnerability in Omron Network Configurator for Devicenet Safety 3.41
The application (Network Configurator for DeviceNet Safety 3.41 and prior) searches for resources by means of an untrusted search path that could execute a malicious .dll file not under the application's direct control and outside the intended directories.
local
low complexity
omron CWE-426
7.8
2019-06-03 CVE-2019-12569 Untrusted Search Path vulnerability in Rakuten Viber
A vulnerability in Viber before 10.7.0 for Desktop (Windows) could allow an attacker to execute arbitrary commands on a targeted system.
local
low complexity
rakuten CWE-426
7.8
2019-05-28 CVE-2019-5589 Untrusted Search Path vulnerability in Fortinet Forticlient
An Unsafe Search Path vulnerability in FortiClient Online Installer (Windows version before 6.0.6) may allow an unauthenticated, remote attacker with control over the directory in which FortiClientOnlineInstaller.exe resides to execute arbitrary code on the system via uploading malicious .dll files in that directory.
local
low complexity
fortinet CWE-426
7.8
2019-05-17 CVE-2018-16156 Untrusted Search Path vulnerability in Fujitsu Paperstream IP (Twain) 1.42.0.5685
In PaperStream IP (TWAIN) 1.42.0.5685 (Service Update 7), the FJTWSVIC service running with SYSTEM privilege processes unauthenticated messages received over the FjtwMkic_Fjicube_32 named pipe.
local
low complexity
fujitsu CWE-426
7.8
2019-05-17 CVE-2019-5958 Untrusted Search Path vulnerability in Soumu Electronic Reception and Examination of Application for Radio Licenses 1.0.9.0
Untrusted search path vulnerability in Electronic reception and examination of application for radio licenses Offline 1.0.9.0 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
local
low complexity
soumu CWE-426
7.8
2019-05-17 CVE-2019-5957 Untrusted Search Path vulnerability in Soumu Electronic Reception and Examination of Application for Radio Licenses 1.0.9.0
Untrusted search path vulnerability in Installer of Electronic reception and examination of application for radio licenses Online 1.0.9.0 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
local
low complexity
soumu CWE-426
7.8