CWE-428

Unquoted Search Path or Element

Parent: CWE-668 - Exposure of Resource to Wrong Sphere

The product uses a search path that contains an unquoted element, in which the element contains whitespace or other separators. This can cause the product to access resources in a parent path.

451 vulnerabilities with CWE-428
CVE-2019-17658 CRITICAL
FortiClient Windows <6.2.2 - Privilege Escalation
CVSS 9.8
CVE-2019-18915 HIGH
HP System Event Utility <1.4.33 - RCE
CVSS 7.8
CVE-2019-20357 HIGH
Trend Micro Security <2019-2020 - RCE
CVSS 7.8
CVE-2019-20362 HIGH
Teradici PCoIP Agent <19.08.1 - Path Traversal
CVSS 7.8
CVE-2019-6008 HIGH
Multiple Yokogawa products - Privilege Escalation
CVSS 7.8
CVE-2019-7487 HIGH
SonicOS SSLVPN NACagent <3.5 - Code Injection
CVSS 7.8
CVE-2019-18245 HIGH
Reliable Controls LicenseManager <3.4 - Code Injection
CVSS 7.8
CVE-2019-7201 HIGH
QNAP NetBak Replicator <4.5.12.1108 - Privilege Escalation
CVSS 7.8
CVE-2019-16647 HIGH
Maxthon <5.2.7 - Privilege Escalation
CVSS 7.2
CVE-2019-6145 MEDIUM
Forcepoint VPN Client < 6.6.1 - Local Privilege Escalation via Unquoted Search Path
CVSS 6.7
CVE-2019-14685 HIGH
Trend Micro Security <15.0 - Privilege Escalation
CVSS 7.8
CVE-2019-7590 MEDIUM
ExacqVision Server <9.8 - Privilege Escalation
CVSS 6.7
CVE-2019-8459 CRITICAL
Check Point Endpoint Security Client <E80.83 - Path Traversal
CVSS 9.8
CVE-2019-11093 MEDIUM
Intel(R) SCS Discovery Utility <12.0.0.129 - Privilege Escalation
CVSS 6.7
CVE-2019-6149 MEDIUM
Lenovo Dynamic Power Reduction Utility <2.2.2.0 - Code Injection
CVSS 6.7
CVE-2018-20341 HIGH
WINMAGIC SecureDoc Disk Encryption <8.3 - RCE
CVSS 7.8
CVE-2018-16098 HIGH
Lenovo Synaptics ThinkPad UltraNav Driver - Unquoted Search Path
CVSS 7.8
CVE-2018-16183 HIGH
Panasonic PC - Privilege Escalation
CVSS 7.8
CVE-2018-14789 MEDIUM
Philips IntelliSpace Cardiovascular <3.1 - Privilege Escalation
CVSS 6.7
CVE-2018-11063 HIGH
Dell WMS <1.1 - Privilege Escalation
CVSS 7.8
CVE-2018-3688 HIGH
Intel Quartus Prime Programmer <18.0 - RCE
CVSS 7.8
CVE-2018-3687 HIGH
Intel Quartus II Programmer and Tools 11.0-15.0 - Unquoted Service Path
CVSS 7.8
CVE-2018-3684 HIGH
Intel Quartus II 11.0-15.0 - Unquoted Service Path
CVSS 7.8
CVE-2018-3683 HIGH
Intel Quartus Prime 15.1-18.0 - Unquoted Service Path Arbitrary Code Execution
CVSS 7.8
CVE-2018-3668 HIGH
Intel Processor Diagnostic Tool <4.1.0.27 - RCE
CVSS 7.8
Details
Vulnerabilities 451