{"id":"CVE-2016-7838","details":"Untrusted search path vulnerability in WinSparkle versions prior to 0.5.3 allows remote attackers to execute arbitrary code via a specially crafted executable file in an unspecified directory.","modified":"2026-07-08T10:53:56.797671Z","published":"2017-06-09T16:29:01.330Z","references":[{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/95099"},{"type":"ADVISORY","url":"https://jvn.jp/en/jp/JVN90813656/index.html"},{"type":"ADVISORY","url":"https://jvn.jp/en/jp/JVN96681653/index.html"},{"type":"ADVISORY","url":"https://www.wireshark.org/news/20161214.html"},{"type":"FIX","url":"https://github.com/vslavik/winsparkle/commit/bb454857348245a7397f9e4fbb3a902f4ac25913"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/vslavik/winsparkle","events":[{"introduced":"0"},{"last_affected":"89b714992c5059aa1379a7428c942838d21f0aa3"},{"fixed":"bb454857348245a7397f9e4fbb3a902f4ac25913"}],"database_specific":{"cpe":"cpe:2.3:a:winsparkle:winsparkle:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"0.5.2"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["v0.5.2","v0.5.1","v0.5","v0.4","v0.3","v0.2","v0.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-7838.json","vanir_signatures_modified":"2026-07-08T10:53:56Z","vanir_signatures":[{"target":{"file":"src/updatedownloader.cpp"},"deprecated":false,"digest":{"line_hashes":["256509417063967258358568229748065976355","59454089042011457857280912392408001448","235466687894083663880668637713036677341","44065089312639971686781285615697421049","67889234838703458489700306438856562673","149555949355538936170486695210422789571","335082845600165984944224248505277061033","199022011612492004326365850404459664368","173383683836750240036716513681198247082","145405624881629910402282105170309345037","91411699622653063031889991693661834118","272454068616744887573527734074534559476","228980372664329242796278865801960738036","289403668701092855358199752394344996320","148941745934012443053339607565491885353"],"threshold":0.9},"id":"CVE-2016-7838-3955e3f0","signature_type":"Line","signature_version":"v1","source":"https://github.com/vslavik/winsparkle/commit/bb454857348245a7397f9e4fbb3a902f4ac25913"},{"deprecated":false,"digest":{"function_hash":"134035343244820856887635900161991009007","length":402},"id":"CVE-2016-7838-44d8ca31","signature_type":"Function","signature_version":"v1","source":"https://github.com/vslavik/winsparkle/commit/bb454857348245a7397f9e4fbb3a902f4ac25913","target":{"file":"src/updatedownloader.cpp","function":"UpdateDownloader::CleanLeftovers"}},{"target":{"file":"src/updatedownloader.cpp","function":"CreateUniqueTempDirectory"},"deprecated":false,"digest":{"function_hash":"187456941495623255741455871983620343098","length":524},"id":"CVE-2016-7838-dc3e4f5e","signature_type":"Function","signature_version":"v1","source":"https://github.com/vslavik/winsparkle/commit/bb454857348245a7397f9e4fbb3a902f4ac25913"}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}