The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.
1,175 vulnerabilities with CWE-427
CVE-2017-3097
CRITICAL
Adobe Digital Editions <= 4.5.4 - Uncontrolled Search Path Element in Installer Plugin
CVSS 9.8
CVE-2017-3092
CRITICAL
Adobe Digital Editions <= 4.5.4 - Uncontrolled Search Path Element in Installer Plugin
CVSS 9.8
CVE-2017-3090
CRITICAL
Adobe Digital Editions <= 4.5.4 - Uncontrolled Search Path Element in Installer Plugin
CVSS 9.8
CVE-2017-4987
HIGH
EMC VNX2 and VNX1 - Authenticated Uncontrolled Search Path Element
CVSS 7.3
CVE-2017-7884
HIGH
apcupsd < 3.14.14 - Authenticated Privilege Escalation via Executable Replacement
CVSS 8.4
CVE-2017-2210
HIGH
PatchJGD 1.0.1 - Privilege Escalation
CVSS 7.8
CVE-2017-7966
HIGH
Schneider Electric SoMachine HVAC Programming Software 2.1.0 - DLL Hijacking
CVSS 8.8
CVE-2017-5176
HIGH
Rockwell Automation CCW <9.01.00 - DLL Hijack
CVSS 7.0
CVE-2017-6051
HIGH
BLF-Tech VisualView HMI <= 9.9.14.0 - Uncontrolled Search Path Element
CVSS 7.0
CVE-2017-3013
HIGH
Adobe Acrobat Reader <= 11.0.19, <= 15.006.30280, <= 15.023.20070 - DLL Hijacking via Insecure Library Loading
CVSS 7.8
CVE-2017-3012
HIGH
Adobe Acrobat and Reader < 11.0.19, < 15.006.30280, < 15.023.20070 - DLL Hijacking in OCR Plugin
CVSS 7.8
CVE-2017-6033
HIGH
Schneider Electric Interactive Graphical SCADA System < 12.0 - DLL Hijacking via Uncontrolled Search Path
CVSS 7.8
CVE-2017-6517
CRITICAL
Microsoft Skype 7.16.0.102 - Unauthenticated Remote Code Execution via DLL Hijacking
CVSS 9.8
CVE-2017-6417
MEDIUM
Avira Free Security Suite < 15.0 - Code Injection via DoubleAgent Attack
CVSS 6.7
CVE-2017-5567
MEDIUM
Avast Free Antivirus < 12.3 - Local Code Injection via DoubleAgent Attack
CVSS 6.7
CVE-2017-5566
MEDIUM
AVG AntiVirus FREE 17.1 and earlier - Code Injection via DoubleAgent Attack
CVSS 6.7
CVE-2017-5565
MEDIUM
Trend Micro Antivirus+ < 11.1.1005 - Code Injection via DoubleAgent
CVSS 6.7
CVE-2017-5161
HIGH
Sielco Sistemi Winlog Lite SCADA Software <3.02.01 - DLL Hijacking
CVSS 7.2
CVE-2016-6592
HIGH
Symantec Norton Download Manager <5.6 - RCE
CVSS 7.8
CVE-2016-5311
HIGH
Symantec Norton and Endpoint Protection < 22.8.0.50 - Privilege Escalation via DLL Preloading
CVSS 7.8
CVE-2016-4526
HIGH
Trane Tracer SC < 4.2.1134 - Uncontrolled Search Path
CVSS 7.5
CVE-2015-1014
HIGH
Schneider Electric OFS <7.40 - Code Injection
CVSS 7.3
CVE-2014-8393
HIGH
CorelDRAW X7, Corel Photo-Paint X7, Corel PaintShop Pro X7, Corel Painter 2015, and Corel PDF Fusion - DLL Hijacking
CVSS 7.8
CVE-2013-0725
HIGH
ERDAS ER Viewer 13.0 - Uncontrolled Search Path Element
CVSS 7.8
CVE-2005-0457
Opera < 7.54 - Uncontrolled Search Path Element via PORTAGE_TMPDIR
Details
Vulnerabilities
1,175