CWE-428

Unquoted Search Path or Element

Parent: CWE-668 - Exposure of Resource to Wrong Sphere

The product uses a search path that contains an unquoted element, in which the element contains whitespace or other separators. This can cause the product to access resources in a parent path.

451 vulnerabilities with CWE-428
CVE-2021-27608 HIGH
SAPSetup <9.0 - Privilege Escalation
CVSS 7.5
CVE-2021-23879 MEDIUM
McAfee Endpoint Product Removal <21.2 - RCE
CVSS 6.7
CVE-2021-21292 MEDIUM
Traccar <4.12 - Privilege Escalation
CVSS 5.5
CVE-2020-37254 HIGH
Wondershare PDFelement 5.2.9 Privilege Escalation via Unquoted Service Path
CVSS 7.8
CVE-2020-37253 HIGH
Winstep 18.06.0096 Unquoted Service Path Privilege Escalation
CVSS 7.8
CVE-2020-37252 HIGH
Realtek Audio Service 1.0.0.55 Unquoted Service Path Privilege Escalation
CVSS 7.8
CVE-2020-37251 HIGH
RealTimes Desktop Service 18.1.4 Unquoted Service Path Privilege Escalation
CVSS 7.8
CVE-2020-37250 HIGH
TFTP Broadband 4.3.0.1465 Unquoted Service Path Privilege Escalation
CVSS 7.8
CVE-2020-37247 HIGH
Kite 4.2.0.1 U1 Unquoted Service Path Privilege Escalation
CVSS 7.8
CVE-2020-37232 HIGH
Advanced System Care Service 13.0.0.157 Unquoted Service Path Privilege Escalation
CVSS 7.8
CVE-2020-37231 HIGH
Privacy Drive 3.17.0 Unquoted Service Path Privilege Escalation
CVSS 7.8
CVE-2020-37230 HIGH
Syncplify.me Server! 5.0.37 Unquoted Service Path Privilege Escalation
CVSS 7.8
CVE-2020-37229 HIGH
OKI sPSV Port Manager 1.0.41 Unquoted Service Path Privilege Escalation
CVSS 7.8
CVE-2020-37223 HIGH
IObit Uninstaller 9.5.0.15 Unquoted Service Path Privilege Escalation
CVSS 7.8
CVE-2020-37102 HIGH
Adaware Web Companion 4.9.2159 - Code Injection
CVSS 7.8
CVE-2020-37101 HIGH
VPN Unlimited 6.1 - Unquoted Service Path Privilege Escalation via Service Binary Path Injection
CVSS 7.8
CVE-2020-37100 HIGH
Sync Breeze Enterprise 12.4.18 - Code Injection
CVSS 7.8
CVE-2020-37099 HIGH
Disk Savvy Enterprise 12.3.18 - Code Injection
CVSS 7.8
CVE-2020-37098 HIGH
Disk Sorter Enterprise <12.4.16 - Code Injection
CVSS 7.8
CVE-2020-37064 HIGH
EPSON EasyMP Network Projection 2.81 - Code Injection
CVSS 7.8
CVE-2020-37063 HIGH
TFTP Turbo 4.6.1273 - Unquoted Service Path Privilege Escalation
CVSS 7.8
CVE-2020-37062 HIGH
DHCP Turbo 4.61298 - Unquoted Service Path Privilege Escalation
CVSS 7.8
CVE-2020-37061 HIGH
BOOTP Turbo 2.0.1214 - Privilege Escalation
CVSS 7.8
CVE-2020-37055 HIGH
SpyHunter 4 - Unquoted Service Path Privilege Escalation
CVSS 7.8
CVE-2020-37048 HIGH
Iskysoft Application Framework Service 2.4.3.241 - Code Injection
CVSS 7.8
Details
Vulnerabilities 451