CWE-428
452 CVEs • Abstraction: Base
Unquoted Search Path or Element
The product uses a search path that contains an unquoted element, in which the element contains whitespace or other separators. This can cause the product to access resources in a parent path.
CVEs (452)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Automatedlogic Carrier3Automatedlogic Webctrl I VuSitescan WebMay 13, 2026 Aug 25, 2017 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 An Unquoted Search Path or Element issue was discovered in Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan Web 6.5 and prior; ALC WebCTRL, SiteScan Web 6.1 and prior; ALC WebCTRL, i-Vu 6.0 and prior; ALC We...Show more |
1Lenovo 1Thinkpad Compact Usb Keyboard Driver May 13, 2026 Aug 10, 2017 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 An unquoted service path vulnerability was identified in the driver for the ThinkPad Compact USB Keyboard with TrackPoint versions earlier than 1.5.5.0. This could allow an attacker with local privileges to execute code...Show more |
1Sierrawireless 3Sierra Wireless Em7345 Software Sierra Wireless Em7455 SoftwareSierra Wireless Location Sensor DriverMay 13, 2026 Aug 2, 2017 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Multiple unquoted service path vulnerabilities in Sierra Wireless Windows Mobile Broadband Driver Package (MBDP) with build ID < 4657 allows local users to launch processes with elevated privileges. |
1Eduiq 1Net Monitor For Employees May 13, 2026 Jun 8, 2017 N/A· v4 7.3 HIGH· v3 6.9 MEDIUM· v2 Net Monitor for Employees Pro through 5.3.4 has an unquoted service path, which allows a Security Feature Bypass of its documented "Block applications" design goal. The local attacker must have privileges to write to pro...Show more |
Adobe Photoshop versions CC 2017 (18.0.1) and earlier, CC 2015.5.1 (17.0.1) and earlier have an unquoted search path vulnerability. |
Unquoted Windows search path vulnerability in the guest service in Unisys s-Par before 4.4.20 allows local users to gain privileges via a Trojan horse executable file in the %SYSTEMDRIVE% directory, as demonstrated by pr...Show more |
1Lenovo 2Edge Keyboard Driver Slim Usb Keyboard DriverMay 13, 2026 Jan 26, 2017 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Unquoted service path vulnerability in Lenovo Edge and Lenovo Slim USB Keyboard Driver versions earlier than 1.21 allows local users to execute code with elevated privileges. |
Unquoted Windows search path vulnerability in Adobe Creative Cloud Desktop Application before 3.8.0.310 on Windows allows local users to gain privileges via a Trojan horse executable file in the %SYSTEMDRIVE% directory. |
Unquoted Windows search path vulnerability in Moxa Active OPC Server before 2.4.19 allows local users to gain privileges via a Trojan horse executable file in the %SYSTEMDRIVE% directory. |
Unquoted Windows search path vulnerability in the autorun value in Dell SonicWall NetExtender before 7.5.227 and 8.0.x before 8.0.238, as used in the SRA firmware before 7.5.1.2-40sv and 8.x before 8.0.0.3-23sv, allows l...Show more |
2Openvpn Privatetunnel2Openvpn PrivatetunnelMay 28, 2026 Aug 25, 2014 N/A· v4 5.3 MEDIUM· v3 6.9 MEDIUM· v2 Unquoted Windows search path vulnerability in the ptservice service prior to PrivateTunnel version 3.0 (Windows) and OpenVPN Connect version 3.1 (Windows) allows local users to gain privileges via a crafted program.exe f...Show more |
1Schneider Electric 1Floating License Manager May 28, 2026 Feb 28, 2014 N/A· v4 5.9 MEDIUM· v3 6.9 MEDIUM· v2 Unquoted Windows search path vulnerability in Schneider Electric Floating License Manager 1.0.0 through 1.4.0 allows local users to gain privileges via a Trojan horse application with a name composed of an initial substr...Show more |