CWE-426

High likelihood

Untrusted Search Path

Parent: CWE-642 - External Control of Critical State Data

The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.

657 vulnerabilities with CWE-426
CVE-2017-10885 HIGH
HYPER SBI <= 2.2 - Untrusted Search Path
CVSS 7.8
CVE-2017-10825 HIGH
Flets Easy Setup Tool <= 1.2.0 - Untrusted Search Path
CVSS 7.8
CVE-2017-15566 HIGH
SchedMD Slurm Privilege Escalation via SPANK Environment Variable Handling
CVSS 7.8
CVE-2017-5996 HIGH
BeyondTrust Remote Support 15.2.x-15.2.2 16.1.x-16.1.4 16.2.x-16.2.3 - DLL Hijacking via Weak ProgramData Permissions
CVSS 7.8
CVE-2017-10865 HIGH
HIBUN Confidential File Decryption < 10.50.0.5 - Untrusted Search Path
CVSS 7.8
CVE-2017-10864 HIGH
Hitachi Solutions HIBUN Confidential File Viewer Installer < 11.20.0001 - Untrusted Search Path
CVSS 7.8
CVE-2017-10863 HIGH
HIBUN Confidential File Decryption < 10.50.0.5 - Untrusted Search Path
CVSS 7.8
CVE-2017-12252 HIGH
Cisco FindIT Network Discovery Utility - DLL Preloading
CVSS 7.8
CVE-2017-10860 HIGH
Digital Arts i-filter 6.0 installer - Untrusted Search Path
CVSS 7.8
CVE-2017-10859 HIGH
Digital Arts i-filter 6.0 installer - Untrusted Search Path
CVSS 7.8
CVE-2017-10858 HIGH
Digital Arts i-filter 6.0 install program < file version 1.0.8.1 - Untrusted Search Path
CVSS 7.8
CVE-2017-10855 HIGH
FENCE-Explorer for Windows <= V8.4.1 - Untrusted Search Path
CVSS 7.8
CVE-2017-10851 HIGH
Fuji Xerox ContentsBridge Utility < 7.4.0 - Untrusted Search Path
CVSS 7.8
CVE-2017-10850 HIGH
Fujifilm ApeosPort-VI and DocuCentre-VI Installers - Untrusted Search Path
CVSS 7.8
CVE-2017-10849 HIGH
Fuji Xerox DocuWorks - Untrusted Search Path via Trojan Horse DLL
CVSS 7.8
CVE-2017-10848 HIGH
Fuji Xerox DocuWorks and DocuWorks Viewer Light < 8.0.7 - Untrusted Search Path
CVSS 7.8
CVE-2017-10829 HIGH
Remote Support Tool (Enkaku Support Tool) - Untrusted Search Path
CVSS 7.8
CVE-2017-11158 HIGH
Synology Cloud Station Drive < 4.2.5-4396 - Untrusted Search Path via DLL Hijacking
CVSS 7.8
CVE-2017-11157 HIGH
Synology Cloud Station Backup < 4.2.4-4393 - Untrusted Search Path via DLL Hijacking
CVSS 7.8
CVE-2017-2242 HIGH
Flets Setsuzoku Tool - Privilege Escalation
CVSS 7.8
CVE-2017-10836 HIGH
Optimal Guard <= 1.1.21 - Untrusted Search Path
CVSS 7.8
CVE-2017-10831 HIGH
The CRCA user's Software <= 1.8 - Untrusted Search Path
CVSS 7.8
CVE-2017-10830 HIGH
NTT Security Setup Tool - Untrusted Search Path
CVSS 7.8
CVE-2017-10828 HIGH
Flets Install Tool - Untrusted Search Path via Trojan Horse DLL
CVSS 7.8
CVE-2017-10827 HIGH
Flets Azukeru for Windows Auto Backup Tool <= 1.0.3.0 - Untrusted Search Path
CVSS 7.8
Details
Vulnerabilities 657
Exploit Likelihood High