CWE-427

Uncontrolled Search Path Element

Parent: CWE-668 - Exposure of Resource to Wrong Sphere

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

1,175 vulnerabilities with CWE-427
CVE-2018-7799 HIGH
Schneider Electric SESU <V2.2.0 - Code Injection
CVSS 7.8
CVE-2018-14812 HIGH
Fuji Electric Energy Savings Estimator <V.1.0.2.0 - DLL Hijacking
CVSS 7.8
CVE-2018-15976 HIGH
Adobe Technical Communications Suite < 1.0.5.1 - Uncontrolled Search Path Element
CVSS 7.8
CVE-2018-11072 HIGH
Dell Digital Delivery < 3.5.1 - Authenticated DLL Injection
CVSS 7.8
CVE-2018-12163 MEDIUM
Intel IoT Developers Kit 4.0 - Privilege Escalation
CVSS 4.8
CVE-2018-12160 MEDIUM
Intel Data Center Migration Center Software <3.1 - Code Injection
CVSS 5.3
CVE-2018-13806 HIGH
SIEMENS TD Keypad Designer - DLL Hijacking via Project File Directory
CVSS 7.8
CVE-2018-14797 HIGH
Emerson DeltaV DCS <14 - Code Injection
CVSS 7.8
CVE-2018-5238 HIGH
Norton Power Eraser <5.3.0.24 & SymDiag <2.1.242 - DLL Preloading
CVSS 7.8
CVE-2018-5235 MEDIUM
Norton Utilities <16.0.3.44 - Code Injection
CVSS 6.0
CVE-2018-8090 HIGH
Quick Heal Various - Buffer Overflow
CVSS 7.8
CVE-2018-12805 CRITICAL
Adobe Connect <9.7.5 - Privilege Escalation
CVSS 9.8
CVE-2018-11049 HIGH
RSA Identity Governance and Lifecycle - Uncontrolled Search Path Element via Environment Variable Manipulation
CVSS 7.3
CVE-2018-1000622 HIGH
Rust Programming Language rustdoc <1.27.0 - RCE
CVSS 7.8
CVE-2018-4938 HIGH
Adobe ColdFusion - Local Privilege Escalation via Insecure Library Loading
CVSS 7.8
CVE-2018-3649 HIGH
Intel Wireless Drivers < 20.20.2.2 - DLL Injection via Autorun.exe and Setup.exe
CVSS 7.8
CVE-2018-6766 HIGH
Swisscom TVMediaHelper 1.1.0.50 - Unauthenticated Remote Code Execution via DLL Hijacking
CVSS 7.8
CVE-2018-6765 HIGH
Swisscom MySwisscomAssistant 2.17.1.1065 - Unauthenticated Remote Code Execution via DLL Hijacking
CVSS 7.8
CVE-2018-5457 HIGH
Vyaire Medical CareFusion Upgrade Utility <2.0.2.2 - Code Injection
CVSS 7.0
CVE-2017-20123 HIGH
Viscosity <1.6.8 - Untrusted Search Path
CVSS 8.8
CVE-2017-20052 MEDIUM
Python 2.7.13 - Uncontrolled Search Path
CVSS 5.0
CVE-2017-20051 MEDIUM
InnoSetup Installer - Path Traversal
CVSS 6.3
CVE-2017-20018 MEDIUM
XAMPP 7.1.1-0-VC14 - Privilege Escalation
CVSS 6.3
CVE-2017-7836 HIGH
Firefox < 57 - Privilege Escalation via Pingsender Dynamic Library Loading
CVSS 7.8
CVE-2017-5175 HIGH
Advantech WebAccess <8.1 - Code Injection
CVSS 7.8
Details
Vulnerabilities 1,175