VYPR

CWE-426

Untrusted Search Path

BaseStableLikelihood: High

Description

The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-38

CVEs mapped to this weakness (672)

page 2 of 34
  • CVE-2026-24070HigFeb 2, 2026
    risk 0.57cvss 8.8epss 0.00

    During the installation of the Native Access application, a privileged helper `com.native-instruments.NativeAccess.Helper2`, which is used by Native Access to trigger functions via XPC communication like copy-file, remove or set-permissions, is deployed as well. The…

  • CVE-2024-53866CriDec 10, 2024
    risk 0.57cvss 9.8epss 0.01

    The package manager pnpm prior to version 9.15.0 seems to mishandle overrides and global cache: Overrides from one workspace leak into npm metadata saved in global cache; npm metadata from global cache affects other workspaces; and installs by default don't revalidate the data…

  • CVE-2024-44103HigSep 10, 2024
    risk 0.57cvss 8.8epss 0.00

    DLL hijacking in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to escalate their privileges.

  • CVE-2024-6975HigJul 31, 2024
    risk 0.57cvss 8.8epss 0.00

    Cato Networks Windows SDP Client Local Privilege Escalation via openssl configuration file. This issue affects SDP Client before 5.10.34.

  • CVE-2024-6974HigJul 31, 2024
    risk 0.57cvss 8.8epss 0.00

    Cato Networks Windows SDP Client Local Privilege Escalation via self-upgradeThis issue affects SDP Client: before 5.10.34.

  • CVE-2024-21435HigMar 12, 2024
    risk 0.57cvss 8.8epss 0.02

    Windows OLE Remote Code Execution Vulnerability

  • CVE-2022-0074HigOct 27, 2022
    risk 0.57cvss 8.8epss 0.01

    Untrusted Search Path vulnerability in LiteSpeed Technologies OpenLiteSpeed Web Server and LiteSpeed Web Server Container allows Privilege Escalation. This affects versions from 1.6.15 before 1.7.16.1.

  • CVE-2017-20123HigJun 30, 2022
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was found in Viscosity 1.6.7. It has been classified as critical. This affects an unknown part of the component DLL Handler. The manipulation leads to untrusted search path. It is possible to initiate the attack remotely. The exploit has been disclosed to the…

  • CVE-2022-26184CriMar 21, 2022
    risk 0.57cvss 9.8epss 0.02

    Poetry v1.1.9 and below was discovered to contain an untrusted search path which causes the application to behave in unexpected ways when users execute Poetry commands in a directory containing malicious content. This vulnerability occurs when the application is ran on Windows…

  • CVE-2021-41387HigSep 17, 2021
    risk 0.57cvss 8.8epss 0.01

    seatd-launch in seatd 0.6.x before 0.6.2 allows privilege escalation because it uses execlp and may be installed setuid root.

  • CVE-2021-28249HigMar 26, 2021
    risk 0.57cvss 8.8epss 0.00

    CA eHealth Performance Manager through 6.3.2.12 is affected by Privilege Escalation via a Dynamically Linked Shared Object Library. To exploit the vulnerability, the ehealth user must create a malicious library in the writable RPATH, to be dynamically linked when the…

  • CVE-2019-13637HigJul 17, 2019
    risk 0.57cvss 8.8epss 0.03

    In LogMeIn join.me before 3.16.0.5505, an attacker could execute arbitrary commands on a targeted system. This vulnerability is due to unsafe search paths used by the application URI that is defined in Windows. An attacker could exploit this vulnerability by convincing a…

  • CVE-2018-10904HigSep 4, 2018
    risk 0.57cvss 8.8epss 0.03

    It was found that glusterfs server does not properly sanitize file paths in the "trusted.io-stats-dump" extended attribute which is used by the "debug/io-stats" translator. Attacker can use this flaw to create files and execute arbitrary code. To exploit this attacker would…

  • CVE-2018-6513HigJun 11, 2018
    risk 0.57cvss 8.8epss 0.01

    Puppet Enterprise 2016.4.x prior to 2016.4.12, Puppet Enterprise 2017.3.x prior to 2017.3.7, Puppet Enterprise 2018.1.x prior to 2018.1.1, Puppet Agent 1.10.x prior to 1.10.13, Puppet Agent 5.3.x prior to 5.3.7, and Puppet Agent 5.5.x prior to 5.5.2, were vulnerable to an attack…

  • CVE-2017-2207HigJun 9, 2017
    risk 0.57cvss 8.8epss 0.02

    Untrusted search path vulnerability in the installer of SaAT Personal ver.1.0.10.272 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

  • CVE-2017-2206HigJun 9, 2017
    risk 0.57cvss 8.8epss 0.02

    Untrusted search path vulnerability in the installer of SaAT Netizen ver.1.2.10.510 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

  • CVE-2017-2178HigJun 9, 2017
    risk 0.57cvss 8.8epss 0.02

    Untrusted search path vulnerability in Installer of electronic tendering and bid opening system available prior to May 25, 2017 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

  • CVE-2017-2177HigJun 9, 2017
    risk 0.57cvss 8.8epss 0.01

    Untrusted search path vulnerability in Installer of Shogyo Touki Denshi Ninsho Software Ver 1.7 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

  • CVE-2017-2149HigApr 28, 2017
    risk 0.57cvss 8.8epss 0.03

    Untrusted search path vulnerability in installers of the software for SDHC/SDXC Memory Card with embedded NFC functionality Software Update Tool V1.00.03 and earlier, SDHC Memory Card with embedded wireless LAN functionality FlashAir Configuration Software V3.0.2 and earlier,…

  • CVE-2026-27290HigApr 14, 2026
    risk 0.56cvss 8.6epss 0.00

    Adobe Framemaker versions 2022.8 and earlier are affected by an Untrusted Search Path vulnerability that might allow attackers to execute arbitrary code in the context of the current user. If the application uses a search path to locate critical resources such as programs, then…