CWE-426
High likelihoodUntrusted Search Path
The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.
657 vulnerabilities with CWE-426
CVE-2018-0507
HIGH
FLET'S VIRUS CLEAR Easy Setup & Application Tool <= ver.11 - Untrusted Search Path
CVSS 7.8
CVE-2017-20123
HIGH
Viscosity <1.6.8 - Untrusted Search Path
CVSS 8.8
CVE-2017-12580
HIGH
UltraEdit < 24.10.0.32 - Untrusted Search Path DLL Preloading
CVSS 7.8
CVE-2017-7755
HIGH
Firefox < 54 and Firefox ESR < 52.2 - Untrusted Search Path DLL Loading
CVSS 7.8
CVE-2017-2802
HIGH
Dell Precision Optimizer 3.5.5.0 - DLL Hijacking via PATH Environment Variable
CVSS 7.8
CVE-2017-1711
HIGH
IBM Notes 8.5 and 9.0 - Untrusted Search Path via DLL Masquerading in Temp Directory
CVSS 7.8
CVE-2017-7327
HIGH
Yandex Browser <17.4.1 - DLL Hijacking
CVSS 7.8
CVE-2017-5696
HIGH
Intel Graphics Driver 15.40.x.x 15.45.x.x and 21.20.x.x - Privilege Escalation via Untrusted Search Path
CVSS 7.8
CVE-2017-15913
HIGH
Whale - DLL Hijacking via Untrusted Search Path
CVSS 7.8
CVE-2017-17010
HIGH
Content Manager Assistant <3.55.7671.0901 - Privilege Escalation
CVSS 7.8
CVE-2017-10909
HIGH
Music Center for PC <= 1.0.01 - Untrusted Search Path
CVSS 7.8
CVE-2017-17809
HIGH
Golden Frog VyprVPN < 2.15.0.5828 - Untrusted Search Path via XPC Service
CVSS 7.8
CVE-2017-16997
HIGH
GNU C Library 2.19-2.26 - Privilege Escalation
CVSS 7.8
CVE-2017-11397
HIGH
Trend Micro Encryption for Email < 5.6.0.1073 - Unauthenticated Remote Code Execution via Service DLL Preloading
CVSS 7.8
CVE-2017-16690
HIGH
SAP Plant Connectivity 2.3,15.0 - DLL Preload
CVSS 7.8
CVE-2017-13070
HIGH
QNAP Qsync for Windows < 4.2.2.0724 - DLL Hijacking
CVSS 7.8
CVE-2017-10893
HIGH
The Public Certification Service for Individuals < 3.1 - Untrusted Search Path
CVSS 7.8
CVE-2017-17069
HIGH
Amazon Audible <Nov 2017 - Code Injection
CVSS 7.8
CVE-2017-10892
HIGH
Music Center for PC 1.0.00 - Untrusted Search Path
CVSS 7.8
CVE-2017-10891
HIGH
Media Go < 3.2.0.191 - Untrusted Search Path
CVSS 7.8
CVE-2017-8137
HIGH
HedEx Lite < V200R006C00 - DLL Hijacking via Relative Path
CVSS 7.8
CVE-2017-4939
HIGH
VMware Workstation 12.x < 12.5.8 - DLL Hijacking via Improper DLL Loading
CVSS 7.8
CVE-2017-10887
HIGH
BOOK WALKER for Windows <= 1.2.9 - Untrusted Search Path
CVSS 7.8
CVE-2017-12313
MEDIUM
Cisco Network Academy Packet Tracer - Code Injection
CVSS 6.7
CVE-2017-12312
MEDIUM
Cisco Advanced Malware Protection for Endpoints - Authenticated DLL Hijacking via Untrusted Search Path
CVSS 6.7
Details
Vulnerabilities
657
Exploit Likelihood
High