The product uses a search path that contains an unquoted element, in which the element contains whitespace or other separators. This can cause the product to access resources in a parent path.
451 vulnerabilities with CWE-428
CVE-2019-25307
HIGH
WorkgroupMail 7.5.1 - Code Injection
CVSS 7.8
CVE-2019-25306
HIGH
BlackMoon FTP Server 3.1.2.1731 - Privilege Escalation
CVSS 7.8
CVE-2019-25305
HIGH
JumpStart 0.6.0.0 - Unquoted Service Path Privilege Escalation via jswpbapi Service
CVSS 7.8
CVE-2019-25304
HIGH
SecurOS Enterprise 10.2 - Privilege Escalation
CVSS 7.8
CVE-2019-25302
HIGH
Acer Launch Manager 6.1.7600.16385 - Privilege Escalation
CVSS 7.8
CVE-2019-25293
HIGH
BlueStacks App Player 2.4.44.62.57 - Local Privilege Escalation
CVSS 7.8
CVE-2019-25292
HIGH
Alps HID Monitor Service 8.1.0.10 - Code Injection
CVSS 7.8
CVE-2019-25266
HIGH
Wondershare Application Framework Service 2.4.3.231 - Code Injection
CVSS 7.8
CVE-2019-25288
HIGH
Wacom WTabletService 6.6.7-3 - Code Injection
CVSS 7.8
CVE-2019-25287
HIGH
Adaware Web Companion 4.8.2078.3950 - Code Injection
CVSS 7.8
CVE-2019-25286
HIGH
GCaf 3.0 - Unquoted Service Path in gbClientService
CVSS 7.8
CVE-2019-25285
HIGH
Alps Pointing-device Controller 8.1202.1711.04 - Code Injection
CVSS 7.8
CVE-2019-25283
HIGH
Shrew Soft VPN Client 2.2.2 - Privilege Escalation
CVSS 7.8
CVE-2019-25281
HIGH
NCP Secure Entry Client 9.2 - Code Injection
CVSS 7.8
CVE-2019-25276
HIGH
Studio 5000 Logix Designer 30.01.00 - Privilege Escalation
CVSS 7.8
CVE-2019-25275
HIGH
BartVPN 1.2.2 - Unquoted Service Path Privilege Escalation via BartVPNService
CVSS 7.8
CVE-2019-25274
HIGH
ProShow Producer 9.0.3797 - Code Injection
CVSS 7.8
CVE-2019-25273
HIGH
Easy-Hide-IP 5.0.0.3 - Code Injection
CVSS 7.8
CVE-2019-25272
HIGH
TexasSoft CyberPlanet 6.4.131 - Code Injection
CVSS 7.8
CVE-2019-25271
HIGH
NETGATE Data Backup 3.0.620 - Code Injection
CVSS 7.8
CVE-2019-25269
HIGH
Amiti Antivirus <25.0.640 - Code Injection
CVSS 7.8
CVE-2019-25267
HIGH
Wing FTP Server 6.0.7 - Privilege Escalation
CVSS 7.8
CVE-2019-25261
HIGH
AnyDesk 5.4.0 - Unquoted Service Path Privilege Escalation
CVSS 7.8
CVE-2019-25231
HIGH
devolo dLAN Cockpit 4.3.1 - Code Injection
CVSS 8.4
CVE-2019-19705
HIGH
Realtek Audio Drivers - DLL Preloading
CVSS 7.8
Details
Vulnerabilities
451