CWE-427

Uncontrolled Search Path Element

Parent: CWE-668 - Exposure of Resource to Wrong Sphere

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

1,175 vulnerabilities with CWE-427
CVE-2017-3097 CRITICAL
Adobe Digital Editions <= 4.5.4 - Uncontrolled Search Path Element in Installer Plugin
CVSS 9.8
CVE-2017-3092 CRITICAL
Adobe Digital Editions <= 4.5.4 - Uncontrolled Search Path Element in Installer Plugin
CVSS 9.8
CVE-2017-3090 CRITICAL
Adobe Digital Editions <= 4.5.4 - Uncontrolled Search Path Element in Installer Plugin
CVSS 9.8
CVE-2017-4987 HIGH
EMC VNX2 and VNX1 - Authenticated Uncontrolled Search Path Element
CVSS 7.3
CVE-2017-7884 HIGH
apcupsd < 3.14.14 - Authenticated Privilege Escalation via Executable Replacement
CVSS 8.4
CVE-2017-2210 HIGH
PatchJGD 1.0.1 - Privilege Escalation
CVSS 7.8
CVE-2017-7966 HIGH
Schneider Electric SoMachine HVAC Programming Software 2.1.0 - DLL Hijacking
CVSS 8.8
CVE-2017-5176 HIGH
Rockwell Automation CCW <9.01.00 - DLL Hijack
CVSS 7.0
CVE-2017-6051 HIGH
BLF-Tech VisualView HMI <= 9.9.14.0 - Uncontrolled Search Path Element
CVSS 7.0
CVE-2017-3013 HIGH
Adobe Acrobat Reader <= 11.0.19, <= 15.006.30280, <= 15.023.20070 - DLL Hijacking via Insecure Library Loading
CVSS 7.8
CVE-2017-3012 HIGH
Adobe Acrobat and Reader < 11.0.19, < 15.006.30280, < 15.023.20070 - DLL Hijacking in OCR Plugin
CVSS 7.8
CVE-2017-6033 HIGH
Schneider Electric Interactive Graphical SCADA System < 12.0 - DLL Hijacking via Uncontrolled Search Path
CVSS 7.8
CVE-2017-6517 CRITICAL
Microsoft Skype 7.16.0.102 - Unauthenticated Remote Code Execution via DLL Hijacking
CVSS 9.8
CVE-2017-6417 MEDIUM
Avira Free Security Suite < 15.0 - Code Injection via DoubleAgent Attack
CVSS 6.7
CVE-2017-5567 MEDIUM
Avast Free Antivirus < 12.3 - Local Code Injection via DoubleAgent Attack
CVSS 6.7
CVE-2017-5566 MEDIUM
AVG AntiVirus FREE 17.1 and earlier - Code Injection via DoubleAgent Attack
CVSS 6.7
CVE-2017-5565 MEDIUM
Trend Micro Antivirus+ < 11.1.1005 - Code Injection via DoubleAgent
CVSS 6.7
CVE-2017-5161 HIGH
Sielco Sistemi Winlog Lite SCADA Software <3.02.01 - DLL Hijacking
CVSS 7.2
CVE-2016-6592 HIGH
Symantec Norton Download Manager <5.6 - RCE
CVSS 7.8
CVE-2016-5311 HIGH
Symantec Norton and Endpoint Protection < 22.8.0.50 - Privilege Escalation via DLL Preloading
CVSS 7.8
CVE-2016-4526 HIGH
Trane Tracer SC < 4.2.1134 - Uncontrolled Search Path
CVSS 7.5
CVE-2015-1014 HIGH
Schneider Electric OFS <7.40 - Code Injection
CVSS 7.3
CVE-2014-8393 HIGH
CorelDRAW X7, Corel Photo-Paint X7, Corel PaintShop Pro X7, Corel Painter 2015, and Corel PDF Fusion - DLL Hijacking
CVSS 7.8
CVE-2013-0725 HIGH
ERDAS ER Viewer 13.0 - Uncontrolled Search Path Element
CVSS 7.8
CVE-2005-0457
Opera < 7.54 - Uncontrolled Search Path Element via PORTAGE_TMPDIR
Details
Vulnerabilities 1,175