CWE-428
450 CVEs • Abstraction: Base
Unquoted Search Path or Element
The product uses a search path that contains an unquoted element, in which the element contains whitespace or other separators. This can cause the product to access resources in a parent path.
CVEs (450)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Sierrawireless 3Sierra Wireless Em7345 Software Sierra Wireless Em7455 SoftwareSierra Wireless Location Sensor DriverMay 13, 2026 Aug 2, 2017 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Multiple unquoted service path vulnerabilities in Sierra Wireless Windows Mobile Broadband Driver Package (MBDP) with build ID < 4657 allows local users to launch processes with elevated privileges. |
1Eduiq 1Net Monitor For Employees May 13, 2026 Jun 8, 2017 N/A· v4 7.3 HIGH· v3 6.9 MEDIUM· v2 Net Monitor for Employees Pro through 5.3.4 has an unquoted service path, which allows a Security Feature Bypass of its documented "Block applications" design goal. The local attacker must have privileges to write to pro...Show more |
Adobe Photoshop versions CC 2017 (18.0.1) and earlier, CC 2015.5.1 (17.0.1) and earlier have an unquoted search path vulnerability. |
Unquoted Windows search path vulnerability in the guest service in Unisys s-Par before 4.4.20 allows local users to gain privileges via a Trojan horse executable file in the %SYSTEMDRIVE% directory, as demonstrated by pr...Show more |
1Lenovo 2Edge Keyboard Driver Slim Usb Keyboard DriverMay 13, 2026 Jan 26, 2017 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Unquoted service path vulnerability in Lenovo Edge and Lenovo Slim USB Keyboard Driver versions earlier than 1.21 allows local users to execute code with elevated privileges. |
Unquoted Windows search path vulnerability in Adobe Creative Cloud Desktop Application before 3.8.0.310 on Windows allows local users to gain privileges via a Trojan horse executable file in the %SYSTEMDRIVE% directory. |
Unquoted Windows search path vulnerability in Moxa Active OPC Server before 2.4.19 allows local users to gain privileges via a Trojan horse executable file in the %SYSTEMDRIVE% directory. |
Unquoted Windows search path vulnerability in the autorun value in Dell SonicWall NetExtender before 7.5.227 and 8.0.x before 8.0.238, as used in the SRA firmware before 7.5.1.2-40sv and 8.x before 8.0.0.3-23sv, allows l...Show more |
2Openvpn Privatetunnel2Openvpn PrivatetunnelMay 28, 2026 Aug 25, 2014 N/A· v4 5.3 MEDIUM· v3 6.9 MEDIUM· v2 Unquoted Windows search path vulnerability in the ptservice service prior to PrivateTunnel version 3.0 (Windows) and OpenVPN Connect version 3.1 (Windows) allows local users to gain privileges via a crafted program.exe f...Show more |
1Schneider Electric 1Floating License Manager May 28, 2026 Feb 28, 2014 N/A· v4 5.9 MEDIUM· v3 6.9 MEDIUM· v2 Unquoted Windows search path vulnerability in Schneider Electric Floating License Manager 1.0.0 through 1.4.0 allows local users to gain privileges via a Trojan horse application with a name composed of an initial substr...Show more |