CWE-428

Unquoted Search Path or Element

Parent: CWE-668 - Exposure of Resource to Wrong Sphere

The product uses a search path that contains an unquoted element, in which the element contains whitespace or other separators. This can cause the product to access resources in a parent path.

451 vulnerabilities with CWE-428
CVE-2018-10619 HIGH
RSLinx Classic <3.90.01 - Privilege Escalation
CVSS 7.8
CVE-2018-4873 HIGH
Adobe Creative Cloud < 4.4.1.298 - Unquoted Search Path Privilege Escalation
CVSS 7.8
CVE-2018-2406 MEDIUM
SAP Crystal Reports Server 4.0-4.30 - Unquoted Search Path Vulnerability
CVSS 5.3
CVE-2018-5470 HIGH
Philips IntelliSpace Portal - Privilege Escalation
CVSS 7.8
CVE-2018-6321 HIGH
Panda Global Protection 17.0.1 - Privilege Escalation
CVSS 7.8
CVE-2018-6016 HIGH
10-Strike Network Monitor <5.4 - Privilege Escalation
CVSS 7.8
CVE-2018-6384 HIGH
NSClient++ <0.4.1.73 - Privilege Escalation
CVSS 7.8
CVE-2017-20218 HIGH
Serviio PRO 1.8 Local Privilege Escalation via Unquoted Path
CVSS 7.8
CVE-2017-3141 HIGH
BIND 9.2.6-P2-9.11.1 - Privilege Escalation via Unquoted Service Path
CVSS 7.2
CVE-2017-11672 HIGH
OPC Foundation LDS <1.03.367 - Privilege Escalation
CVSS 7.8
CVE-2017-6015 HIGH
Rockwell Automation FactoryTalk Activation < 4.00.02 - Unquoted Search Path or Element
CVSS 7.8
CVE-2017-1000475 HIGH
FreeSSHd <1.3.1 - Privilege Escalation
CVSS 7.8
CVE-2017-14030 HIGH
Moxa MXview <2.8 - Privilege Escalation
CVSS 7.8
CVE-2017-14019 MEDIUM
Progea Movicon <11.5.1181 - Privilege Escalation
CVSS 6.7
CVE-2017-15383 HIGH
Nero 7.10.1.0 - Unquoted Search Path Privilege Escalation via Trojan Horse Nero.exe
CVSS 7.8
CVE-2017-12730 HIGH
mySCADA myPRO <7.0.26 - Code Injection
CVSS 7.8
CVE-2017-13993 HIGH
i-SENS SmartLog Diabetes Management Software <2.4.0 - Code Injection
CVSS 7.8
CVE-2017-3757 HIGH
ElanTech Touchpad Driver - Unquoted Service Path Privilege Escalation
CVSS 7.8
CVE-2017-9644 HIGH
ALC WebCTRL <6.5 - Code Injection
CVSS 7.0
CVE-2017-3751 HIGH
ThinkPad Compact USB Keyboard with TrackPoint <1.5.5.0 - Code Injec...
CVSS 7.8
CVE-2017-9247 HIGH
Sierra Wireless Windows Mobile Broadband Driver Package - Privilege...
CVSS 7.8
CVE-2017-7180 HIGH
Net Monitor for Employees Pro <5.3.4 - Auth Bypass
CVSS 7.3
CVE-2017-3005 HIGH
Adobe Photoshop <CC 2017 - Buffer Overflow
CVSS 7.8
CVE-2017-5873 MEDIUM
Unisys s-Par <4.4.20 - Privilege Escalation
CVSS 6.7
CVE-2016-20095 HIGH
Matrix42 Remote Control Host 3.20.0031 Unquoted Path Privilege Escalation
CVSS 7.8
Details
Vulnerabilities 451