CWE-426
High likelihoodUntrusted Search Path
The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.
657 vulnerabilities with CWE-426
CVE-2019-6189
HIGH
Lenovo System Interface Foundation < 1.1.18.3 - Untrusted Search Path DLL Loading
CVSS 7.8
CVE-2019-16861
HIGH
Code42 Server <7.0.2 - Code Injection
CVSS 7.3
CVE-2019-16860
HIGH
Code42 < 7.0.2 - Untrusted Search Path DLL Loading
CVSS 7.3
CVE-2019-3648
MEDIUM
McAfee Total Protection < 16.0.R22 - Privilege Escalation via Untrusted Search Path
CVSS 6.1
CVE-2019-18196
MEDIUM
TeamViewer < 11.0.214397 - DLL Side Loading via Windows Service Restart
CVSS 6.7
CVE-2019-17664
HIGH
Ghidra <= 9.0.4 - Untrusted Search Path via Python Interpreter Launch
CVSS 7.8
CVE-2019-17449
MEDIUM
Avira Software Updater < 2.0.6.21094 - DLL Side-Loading via Untrusted Search Path
CVSS 6.7
CVE-2019-3745
HIGH
Dell Encryption < 10.4.0 and Endpoint Security Suite Enterprise < 2.4.0 - DLL Hijacking via Installer Search Path
CVSS 7.3
CVE-2019-14960
HIGH
JetBrains Rider < 2019.1.2 - Untrusted Search Path
CVSS 7.8
CVE-2019-13357
HIGH
Total Defense Anti-virus 9.0.0.773 - Untrusted Search Path DLL Hijacking via caschelp.exe
CVSS 7.8
CVE-2019-6826
HIGH
SoMachine HVAC < 2.4.1 - Untrusted Search Path DLL Loading
CVSS 7.8
CVE-2019-11660
HIGH
Micro Focus Data Protector <10.50 - Privilege Escalation
CVSS 7.8
CVE-2019-3646
MEDIUM
McAfee Total Protection <16.0.R18 - RCE
CVSS 6.9
CVE-2019-8461
HIGH
Check Point Endpoint Security Initial Client for Windows <E81.30 - ...
CVSS 7.8
CVE-2019-15295
HIGH
Bitdefender Antivirus Free 2020 < 1.0.15.138 - Untrusted Search Path in ServiceInstance.dll
CVSS 7.8
CVE-2019-6165
HIGH
Lenovo Yoga 700-11ISK/14ISK Firmware - Untrusted Search Path in PaperDisplay Hotkey Service
CVSS 7.8
CVE-2019-5631
HIGH
Rapid7 InsightAppSec < 2019.06.24 - DLL Injection in prunsrv.exe
CVSS 7.8
CVE-2019-9492
HIGH
Trend Micro OfficeScan <11.0 SP1-XG - RCE
CVSS 7.8
CVE-2019-1010100
HIGH
Akeo Rufus < 3.0 - DLL Search Order Hijacking in Executable Installers
CVSS 7.8
CVE-2019-13637
HIGH
join.me < 3.16.0.5505 - Untrusted Search Path via Windows URI Handler
CVSS 8.8
CVE-2019-12912
MEDIUM
rdbrck shift < 3.4.3 - Email Information Disclosure
CVSS 5.5
CVE-2019-12576
HIGH
Private Internet Access VPN Client v82 - Authenticated Privilege Escalation via Untrusted Search Path
CVSS 7.8
CVE-2019-12574
HIGH
Private Internet Access VPN Client v1.0 - Authenticated DLL Injection via Updater Library Loading
CVSS 7.8
CVE-2019-10971
HIGH
Network Configurator for DeviceNet Safety < 3.41 - Untrusted Search Path DLL Execution
CVSS 7.8
CVE-2019-12569
HIGH
Viber < 10.7.0 - Untrusted Search Path via Application URI Handler
CVSS 7.8
Details
Vulnerabilities
657
Exploit Likelihood
High