CWE-428

Unquoted Search Path or Element

Parent: CWE-668 - Exposure of Resource to Wrong Sphere

The product uses a search path that contains an unquoted element, in which the element contains whitespace or other separators. This can cause the product to access resources in a parent path.

451 vulnerabilities with CWE-428
CVE-2020-27645 HIGH
1E Client <5.0.0.745 - Privilege Escalation
CVSS 8.8
CVE-2020-27644 HIGH
1E Client 5.0.0.745 - Privilege Escalation
CVSS 8.8
CVE-2020-28209 HIGH
EcoStruxure Building Operation <3.1 - Privilege Escalation
CVSS 7.0
CVE-2020-7331 HIGH
McAfee Endpoint Security < 10.6.1 - Unquoted Service Path Denial of Service and Malicious File Execution
CVSS 7.8
CVE-2020-15261 HIGH
Veyon Service <4.4.2 - Privilege Escalation
CVSS 8.0
CVE-2020-7316 MEDIUM
McAfee File and Removable Media Protection < 5.3.0 - Unquoted Service Path Privilege Escalation
CVSS 6.6
CVE-2020-10051 HIGH
SIMATIC RTLS Locating Manager <V2.10.2 - Command Injection
CVSS 7.8
CVE-2020-7382 MEDIUM
Rapid7 Nexpose <6.6.40 - Buffer Overflow
CVSS 6.8
CVE-2020-8326 HIGH
Lenovo Drivers Management <2.7.1128.1046 - Privilege Escalation
CVSS 7.3
CVE-2020-7581 MEDIUM
SIMATIC Notifier Server - Unquoted Search Path or Element
CVSS 6.7
CVE-2020-7580 MEDIUM
SIMATIC Automation Tool < V4 SP2 - Unquoted Search Path or Element
CVSS 6.7
CVE-2020-8337 MEDIUM
Synaptics Smart Audio <1.0.83.0 - Code Injection
CVSS 6.7
CVE-2020-9292 CRITICAL
FortiSIEM Windows Agent - Privilege Escalation
CVSS 9.8
CVE-2020-5569 HIGH
HDD Password tool <1.20.6620 - Path Traversal
CVSS 8.4
CVE-2020-7275 MEDIUM
McAfee ENS <10.7.0 - Code Injection
CVSS 4.8
CVE-2020-8327 HIGH
Lenovo Vantage <10.2003.10.0 - Privilege Escalation
CVSS 7.3
CVE-2020-1988 MEDIUM
Palo Alto Networks GlobalProtect Agent <5.0.5-4.1.13 - Privilege Es...
CVSS 4.2
CVE-2020-0546 HIGH
Intel Optane DC Persistent Memory Mod... - Denial of Service
CVSS 7.8
CVE-2020-0507 MEDIUM
Intel Graphics Driver < 15.33.49.5100 - Authenticated Denial of Service via Unquoted Service Path
CVSS 4.4
CVE-2020-7252 MEDIUM
McAfee Data eXchange Layer < 6.0.0 - Unquoted Service Path Arbitrary Code Execution
CVSS 4.2
CVE-2019-25747 HIGH
Network Inventory Advisor 5.0.26.0 Unquoted Service Path Privilege Escalation
CVSS 7.8
CVE-2019-25345 HIGH
Realtek IIS Codec Service 6.4.10041.133 - Code Injection
CVSS 7.8
CVE-2019-25310 HIGH
ActiveFax Server <6.92 Build 0316 - Code Injection
CVSS 7.8
CVE-2019-25309 HIGH
Zilab Remote Console Server 3.2.9 - Privilege Escalation
CVSS 7.8
CVE-2019-25308 HIGH
Mikogo <5.2.2.150317 - Code Injection
CVSS 7.8
Details
Vulnerabilities 451