CWE-428
426 CVEs • Abstraction: Base
Unquoted Search Path or Element
The product uses a search path that contains an unquoted element, in which the element contains whitespace or other separators. This can cause the product to access resources in a parent path.
CVEs (426)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Siemens 11Opcenter Execution Discrete Opcenter Execution FoundationOpcenter Execution Process+8 moreNov 21, 2024 Jul 14, 2020 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 A vulnerability has been identified in Opcenter Execution Discrete (All versions < V3.2), Opcenter Execution Foundation (All versions < V3.2), Opcenter Execution Process (All versions < V3.2), Opcenter Intelligence (All...Show more |
1Siemens 17Simatic Automatic Tool Simatic Net PcSimatic Pcs 7+14 moreNov 21, 2024 Jun 10, 2020 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 A vulnerability has been identified in SIMATIC Automation Tool (All versions < V4 SP2), SIMATIC NET PC Software V14 (All versions < V14 SP1 Update 14), SIMATIC NET PC Software V15 (All versions), SIMATIC NET PC Software...Show more |
An unquoted search path vulnerability was reported in versions prior to 1.0.83.0 of the Synaptics Smart Audio UWP app associated with the DCHU audio drivers on Lenovo platforms that could allow an administrative user to...Show more |
1Fortinet 1Fortisiem Windows Agent Nov 21, 2024 Jun 4, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An unquoted service path vulnerability in the FortiSIEM Windows Agent component may allow an attacker to gain elevated privileges via the AoWinAgt executable service path. |
1Toshiba 1Password Tool For Windows Nov 21, 2024 Apr 20, 2020 N/A· v4 8.4 HIGH· v3 4.6 MEDIUM· v2 An unquoted search path vulnerability exists in HDD Password tool (for Windows) version 1.20.6620 and earlier which is stored in CANVIO PREMIUM 3TB(HD-MB30TY, HD-MA30TY, HD-MB30TS, HD-MA30TS), CANVIO PREMIUM 2TB(HD-MB20T...Show more |
Accessing, modifying or executing executable files vulnerability in the uninstaller in McAfee Endpoint Security (ENS) for Windows Prior to 10.7.0 April 2020 Update allows local users to execute arbitrary code via a caref...Show more |
A privilege escalation vulnerability was reported in LenovoBatteryGaugePackage for Lenovo System Interface Foundation bundled in Lenovo Vantage prior to version 10.2003.10.0 that could allow an authenticated user to exec...Show more |
1Paloaltonetworks 1Globalprotect Nov 21, 2024 Apr 8, 2020 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 An unquoted search path vulnerability in the Windows release of Global Protect Agent allows an authenticated local user with file creation privileges on the root of the OS disk (C:\) or to Program Files directory to gain...Show more |
An unquoted service path vulnerability in the FortiClient FortiTray component of FortiClientWindows v6.2.2 and prior allow an attacker to gain elevated privileges via the FortiClientConsole executable service path. |
1Intel 1Optane Dc Persistent Memory Module Management Nov 21, 2024 Mar 12, 2020 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Unquoted service path in Intel(R) Optane(TM) DC Persistent Memory Module Management Software before version 1.0.0.3461 may allow an authenticated user to potentially enable escalation of privilege and denial of service v...Show more |
Unquoted service path in Intel(R) Graphics Drivers before versions 15.33.49.5100, 15.36.38.5117, 15.40.44.5107, 15.45.30.5103, and 26.20.100.7212 may allow an authenticated user to potentially enable denial of service vi...Show more |
Unquoted service executable path in DXL Broker in McAfee Data eXchange Layer (DXL) Framework 6.0.0 and earlier allows local users to cause a denial of service and malicious file execution via carefully crafted and named...Show more |
A potential security vulnerability has been identified with certain versions of HP System Event Utility prior to version 1.4.33. This vulnerability may allow a local attacker to execute arbitrary code via an HP System Ev...Show more |
1Trendmicro 8Antivirus + Security 2019 Antivirus + Security 2020Internet Security 2019+5 moreNov 21, 2024 Jan 18, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A Persistent Arbitrary Code Execution vulnerability exists in the Trend Micro Security 2020 (v160 and 2019 (v15) consumer familiy of products which could potentially allow an attacker the ability to create a malicious pr...Show more |
1Whoopsie Daisy Project 1Whoopsie Daisy Nov 21, 2024 Jan 15, 2020 N/A· v4 4.9 MEDIUM· v3 5.5 MEDIUM· v2 whoopsie-daisy before 0.1.26: Root user can remove arbitrary files |
1Teradici 3Pcoip Client Pcoip Graphics AgentPcoip Standard AgentNov 21, 2024 Jan 8, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 In Teradici PCoIP Agent before 19.08.1 and PCoIP Client before 19.08.3, an unquoted service path can cause execution of %PROGRAMFILES(X86)%\Teradici\PCoIP.exe instead of the intended pcoip_vchan_printing_svc.exe file. |
1Yokogawa 8Exaopc ExaplogExaquantum+5 moreNov 21, 2024 Dec 26, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 An unquoted search path vulnerability in Multiple Yokogawa products for Windows (Exaopc (R1.01.00 ? R3.77.00), Exaplog (R1.10.00 ? R3.40.00), Exaquantum (R1.10.00 ? R3.02.00 and R3.15.00), Exaquantum/Batch (R1.01.00 ? R2...Show more |
1Sonicwall 2Sonicos Sonicos Sslvpn NacagentNov 21, 2024 Dec 19, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Installation of the SonicOS SSLVPN NACagent 3.5 on the Windows operating system, an autorun value is created does not put the path in quotes, so if a malicious binary by an attacker within the parent path could allow cod...Show more |
1Reliablecontrols 1Rc Licensemanager Nov 21, 2024 Dec 11, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Reliable Controls LicenseManager versions 3.4 and prior may allow an authenticated user to insert malicious code into the system root path, which may allow execution of code with elevated privileges of the application. |
An unquoted service path vulnerability is reported to affect the service QVssService in QNAP NetBak Replicator. This vulnerability could allow an authorized but non-privileged local user to execute arbitrary code with el...Show more |