CWE-426

High likelihood

Untrusted Search Path

Parent: CWE-642 - External Control of Critical State Data

The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.

626 vulnerabilities with CWE-426
CVE-2021-25699 HIGH
Teradici Pcoip Client < 21.07.0 - Untrusted Search Path
CVSS 7.8
CVE-2021-25698 HIGH
Teradici Pcoip Standard Agent < 21.07.0 - Untrusted Search Path
CVSS 7.8
CVE-2021-26807 HIGH
GOG Galaxy - Untrusted Search Path
CVSS 7.8
CVE-2021-29221 HIGH
Erlang/otp < 23.2.3 - Untrusted Search Path
CVSS 7.0
CVE-2021-3146 HIGH
Dolby Audio X2 < 0.8.8.90 - Untrusted Search Path
CVSS 7.8
CVE-2021-28249 HIGH
CA eHealth Performance Manager <6.3.2.12 - Privilege Escalation
CVSS 8.8
CVE-2021-28246 HIGH
CA eHealth Performance Manager <6.3.2.12 - Privilege Escalation
CVSS 7.8
CVE-2021-21078 MEDIUM
Adobe Creative Cloud Desktop App <5.3 - RCE
CVSS 6.5
CVE-2021-22980 HIGH
Edge Client <7.2.1.1, 7.1.9.x-7.1.9.8, 7.1.x-7.1.8.5 - DLL Hijacking
CVSS 7.8
CVE-2021-21055 MEDIUM
Adobe Dreamweaver <21.0-20.2 - Info Disclosure
CVSS 6.2
CVE-2021-21237 HIGH
Git LFS - RCE
CVSS 7.2
CVE-2020-8094 HIGH
Bitdefender Antivirus Free 2020 - Code Injection
CVSS 7.8
CVE-2020-12892 HIGH
AMD Radeon settings Installer - Privilege Escalation/Code Execution
CVSS 7.8
CVE-2020-35686 HIGH
Soundresearch Dchu Model Software Com... - Untrusted Search Path
CVSS 7.8
CVE-2020-29482 MEDIUM
Xen <4.14.x - Info Disclosure
CVSS 6.0
CVE-2020-4739 HIGH
IBM Db2 < 11.5.5.0 - Untrusted Search Path
CVSS 7.8
CVE-2020-27695 HIGH
Trendmicro Antivirus+ Security 2020 < 16.0 - Untrusted Search Path
CVSS 7.8
CVE-2020-6014 MEDIUM
Check Point Endpoint Security Client <E83.20 - Code Injection
CVSS 6.5
CVE-2020-5144 HIGH
Sonicwall Global VPN Client < 4.10.4.0314 - Untrusted Search Path
CVSS 7.8
CVE-2020-6023 HIGH
Check Point ZoneAlarm <15.8.139.18543 - Privilege Escalation
CVSS 7.8
CVE-2020-5977 HIGH
NVIDIA GeForce Experience <3.20.5.70 - RCE
CVSS 7.8
CVE-2020-8338 HIGH
Lenovo Diagnostics <4.35.4 - Code Injection
CVSS 7.8
CVE-2020-6654 HIGH
Eaton 9000x Programming And Configura... - Uncontrolled Search Path
CVSS 7.8
CVE-2020-10733 HIGH
PostgreSQL <12 - Code Injection
CVSS 7.3
CVE-2020-0570 HIGH
QT < 5.9.10 - Untrusted Search Path
CVSS 7.3
Details
Vulnerabilities 626
Exploit Likelihood High