The product uses a search path that contains an unquoted element, in which the element contains whitespace or other separators. This can cause the product to access resources in a parent path.
451 vulnerabilities with CWE-428
CVE-2024-1618
HIGH
Faronics Deep Freeze Server <8.30.020.4627 - Local Privilege Escala...
CVSS 7.8
CVE-2024-25552
HIGH
Product <Version - Privilege Escalation
CVSS 7.8
CVE-2024-24722
CRITICAL
12d Synergy <5.1.5.221 - Privilege Escalation
CVSS 9.1
CVE-2024-1201
HIGH
HDD Health < 4.2.0.112 - Unquoted Search Path Privilege Escalation
CVSS 7.8
CVE-2023-54353
HIGH
Chromacam 4.0.3.0 Unquoted Service Path Privilege Escalation
CVSS 7.8
CVE-2023-54338
HIGH
Tftpd32 SE 4.60 - Unquoted Service Path Privilege Escalation
CVSS 8.4
CVE-2023-54336
HIGH
Mediconta 3.7.27 - Privilege Escalation
CVSS 8.4
CVE-2023-54331
HIGH
Outline 1.6.0 - Privilege Escalation
CVSS 7.8
CVE-2023-53984
HIGH
Clevo HotKey Clipboard 2.1.0.6 - Code Injection
CVSS 8.4
CVE-2023-53965
HIGH
SOUND4 Server Service 4.1.102 - Privilege Escalation
CVSS 8.4
CVE-2023-53954
MEDIUM
ActFax 10.10 - Privilege Escalation
CVSS 6.2
CVE-2023-53947
HIGH
OCS Inventory NG <2.3.0.0 - Privilege Escalation
CVSS 8.4
CVE-2023-53946
HIGH
Arcsoft PhotoStudio 6.0.0.172 - Privilege Escalation
CVSS 8.4
CVE-2023-53912
MEDIUM
USB Flash Drives Control 4.1.0.0 - Code Injection
CVSS 6.2
CVE-2023-39464
HIGH
Triangle MicroWorks SCADA Data Gateway - Remote Code Execution via Unquoted GTWWebMonitorService Path
CVSS 7.2
CVE-2023-24542
MEDIUM
Intel(R) Thunderbolt(TM) DCH <88 - Privilege Escalation
CVSS 6.7
CVE-2023-7043
LOW
ESET Endpoint Antivirus 10.1.2046.0-11.0.2032.0 - Unquoted Service Path
CVSS 3.3
CVE-2023-6631
HIGH
PowerSYSTEM Center <2020 Update 16 - Privilege Escalation
CVSS 7.8
CVE-2023-32658
MEDIUM
Intel(R) NUC Kits <1.79.1.1 - Privilege Escalation
CVSS 6.7
CVE-2023-29165
MEDIUM
Intel(R) Arc(TM) Control <1.73.5335.2 - Privilege Escalation
CVSS 6.7
CVE-2023-25075
MEDIUM
Intel Server Configuration Utility <16.0.9 - Privilege Escalation
CVSS 6.7
CVE-2023-0392
MEDIUM
Okta LDAP Agent < 5.18 - Remote Code Execution via Unquoted Service Path
CVSS 6.7
CVE-2023-37537
HIGH
HCL AppScan Presence - Privilege Escalation
CVSS 7.8
CVE-2023-42486
MEDIUM
Fortect < 5.0.0.7 - Privilege Escalation via Unquoted Search Path
CVSS 6.3
CVE-2023-5012
MEDIUM
Topaz OFD <2.11.0.201 - Unquoted Search Path
CVSS 5.3
Details
Vulnerabilities
451