CWE-426

High likelihood

Untrusted Search Path

Parent: CWE-642 - External Control of Critical State Data

The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.

657 vulnerabilities with CWE-426
CVE-2021-26556 HIGH
Octopus Deploy 0.9-2020.4.229 and Octopus Server 2020.5.0-2020.5.256 - Untrusted Search Path via DLL Side-Loading
CVSS 7.8
CVE-2021-36297 HIGH
SupportAssist Client <3.8-3.9 - Code Injection
CVSS 7.8
CVE-2021-31841 HIGH
McAfee Agent < 5.7.4 - DLL Sideloading via Unsigned DLL
CVSS 8.2
CVE-2021-41387 HIGH
seatd 0.6.0-0.6.1 - Privilege Escalation via execlp Untrusted Search Path
CVSS 8.8
CVE-2021-37617 HIGH
Nextcloud Desktop 3.0.3-3.2.4 - Uncontrolled Search Path Element via Uninstall.exe
CVSS 7.3
CVE-2021-21562 MEDIUM
Dell EMC PowerScale OneFS - Untrusted Search Path
CVSS 4.4
CVE-2021-25699 HIGH
Teradici PCoIP Client < 21.07.0 - DLL Hijacking via OpenSSL Config Directory
CVSS 7.8
CVE-2021-25698 HIGH
Teradici PCoIP Standard Agent < 21.07.0 - Privilege Escalation via OpenSSL DLL Hijacking
CVSS 7.8
CVE-2021-26807 HIGH
GOG Galaxy 2.0.28.9 - Untrusted Search Path DLL Loading
CVSS 7.8
CVE-2021-29221 HIGH
Erlang/OTP < 23.2.3 - Local Privilege Escalation via Unsafe Filesystem Permissions
CVSS 7.0
CVE-2021-3146 HIGH
Dolby Audio X2 < 0.8.8.90 - Untrusted Search Path Privilege Escalation
CVSS 7.8
CVE-2021-28249 HIGH
CA eHealth Performance Manager <6.3.2.12 - Privilege Escalation
CVSS 8.8
CVE-2021-28246 HIGH
CA eHealth Performance Manager <6.3.2.12 - Privilege Escalation
CVSS 7.8
CVE-2021-21078 MEDIUM
Adobe Creative Cloud Desktop App <5.3 - RCE
CVSS 6.5
CVE-2021-22980 HIGH
Edge Client <7.2.1.1, 7.1.9.x-7.1.9.8, 7.1.x-7.1.8.5 - DLL Hijacking
CVSS 7.8
CVE-2021-21055 MEDIUM
Adobe Dreamweaver <21.0-20.2 - Info Disclosure
CVSS 6.2
CVE-2021-21237 HIGH
Git LFS <2.13.2 - Windows Code Execution via Current-Directory Git Binary
CVSS 7.2
CVE-2020-8094 HIGH
Bitdefender Antivirus Free 2020 - Code Injection
CVSS 7.8
CVE-2020-12892 HIGH
AMD Radeon settings Installer - Privilege Escalation/Code Execution
CVSS 7.8
CVE-2020-35686 HIGH
Sound Research DCHU Model Software Component Modules < 2.0.9.17 - Privilege Escalation via DLL Hijacking
CVSS 7.8
CVE-2020-29482 MEDIUM
Xen < 4.14.0 - Denial of Service via Xenstore Path Length Limit Bypass
CVSS 6.0
CVE-2020-4739 HIGH
IBM DB2 9.7-11.5 - Authenticated DLL Search Order Hijacking
CVSS 7.8
CVE-2020-27695 HIGH
Trend Micro Security 2020 < 16.0 - DLL Hijacking via Installer Package
CVSS 7.8
CVE-2020-6014 MEDIUM
Check Point Endpoint Security Client <E83.20 - Code Injection
CVSS 6.5
CVE-2020-5144 HIGH
SonicWall Global VPN Client < 4.10.4.0314 - Privilege Escalation via Process Hijacking
CVSS 7.8
Details
Vulnerabilities 657
Exploit Likelihood High