CWE-426

High likelihood

Untrusted Search Path

Parent: CWE-642 - External Control of Critical State Data

The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.

657 vulnerabilities with CWE-426
CVE-2019-5589 HIGH
FortiClient < 6.0.6 - Unauthenticated Remote Code Execution via DLL Hijacking
CVSS 7.8
CVE-2019-5958 HIGH
Electronic Reception and Examination of Application for Radio Licenses Offline < 1.0.9.0 - Untrusted Search Path
CVSS 7.8
CVE-2019-5957 HIGH
Electronic Reception and Examination of Application for Radio Licenses Online < 1.0.9.0 - Untrusted Search Path
CVSS 7.8
CVE-2019-5429 HIGH
FileZilla <3.41.0-rc1 - Privilege Escalation
CVSS 7.8
CVE-2019-9798 HIGH
Firefox < 66.0 - Untrusted Search Path via APITRACE_LIB
CVSS 7.4
CVE-2019-11351 HIGH
TeamSpeak < 3.2.5 - Remote Code Execution via Untrusted Search Path
CVSS 8.8
CVE-2019-8453 MEDIUM
Check Point ZoneAlarm < 15.4.062 - Denial of Service via DLL Replacement
CVSS 5.5
CVE-2019-6154 MEDIUM
Lenovo Bootable Generator < Mar-2019 - Untrusted Search Path
CVSS 5.3
CVE-2019-0809 HIGH
Visual Studio C++ Redistributable Installer - RCE
CVSS 7.8
CVE-2019-6724 HIGH
Barracuda VPN Client < 5.0.2.7 - Untrusted Search Path via barracudavpn Component
CVSS 7.8
CVE-2019-5922 HIGH
Microsoft Teams - Untrusted Search Path via Trojan Horse DLL
CVSS 7.8
CVE-2019-5921 HIGH
Windows 7 - Untrusted Search Path Vulnerability via Trojan Horse DLL
CVSS 7.8
CVE-2019-5913 HIGH
LHMelting < 1.65.3.6 - Untrusted Search Path
CVSS 7.8
CVE-2019-5912 HIGH
unarj32.dll < 1.10.1.25 - Untrusted Search Path
CVSS 7.8
CVE-2019-5911 HIGH
UNLHA32.DLL < 2.67.1.2 - Untrusted Search Path
CVSS 7.8
CVE-2019-3587 HIGH
McAfee Total Protection < 16.0.18 - DLL Search Order Hijacking
CVSS 7.2
CVE-2018-21241 HIGH
Foxit PhantomPDF < 8.3.6 - Remote Code Execution via Untrusted Search Path
CVSS 7.8
CVE-2018-16156 HIGH
PaperStream IP (TWAIN) 1.42.0.5685 - Unauthenticated Local Privilege Escalation via Untrusted Search Path
CVSS 7.8
CVE-2018-18367 HIGH
Symantec Endpoint Protection Manager <= 12.1 RU6 MP9 and < 14.2 RU1 - DLL Preloading
CVSS 7.8
CVE-2018-18369 HIGH
Norton Security < 22.16.3 and Symantec Endpoint Protection Cloud < 22.16.3 - DLL Preloading
CVSS 7.8
CVE-2018-10959 HIGH
Avecto Defendpoint 4.0-4.4.267.0 - Untrusted Search Path via Environment Variable Manipulation
CVSS 7.5
CVE-2018-18913 HIGH
Opera < 57.0.3098.106 - DLL Search Order Hijacking via Malicious ZIP Archive
CVSS 7.8
CVE-2018-16190 HIGH
LHMelting < 1.65.3.6 and UNARJ32.DLL < 1.10.1.25 - Untrusted Search Path
CVSS 7.8
CVE-2018-16189 HIGH
unlha32.dll < 3.00 - Untrusted Search Path
CVSS 7.8
CVE-2018-18364 HIGH
Symantec Ghost Solution Suite < 3.3 RU1 - DLL Hijacking via Untrusted Search Path
CVSS 7.3
Details
Vulnerabilities 657
Exploit Likelihood High