VYPR

CWE-426

Untrusted Search Path

BaseStableLikelihood: High

Description

The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.

Hierarchy (View 1000)

Children

none

Related attack patterns (CAPEC)

CAPEC-38

CVEs mapped to this weakness (672)

page 21 of 34
  • CVE-2016-7838HigJun 9, 2017
    risk 0.51cvss 7.8epss 0.03

    Untrusted search path vulnerability in WinSparkle versions prior to 0.5.3 allows remote attackers to execute arbitrary code via a specially crafted executable file in an unspecified directory.

  • CVE-2016-4902HigJun 9, 2017
    risk 0.51cvss 7.8epss 0.02

    Untrusted search path vulnerability in The Public Certification Service for Individuals "The JPKI user's software (for Windows 7 and later)" Ver3.0.1 and earlier, The Public Certification Service for Individuals "The JPKI user's software (for Windows Vista)" Ver3.0.1 and earlier…

  • CVE-2017-2175HigMay 22, 2017
    risk 0.51cvss 7.8epss 0.01

    Untrusted search path vulnerability in Empirical Project Monitor - eXtended all versions allows remote attackers to gain privileges via a Trojan horse DLL in an unspecified directory.

  • CVE-2016-7804HigMay 22, 2017
    risk 0.51cvss 7.8epss 0.02

    Untrusted search path vulnerability in 7 Zip for Windows 16.02 and earlier allows remote attackers to gain privileges via a Trojan horse DLL in an unspecified directory.

  • CVE-2016-4901HigMay 22, 2017
    risk 0.51cvss 7.8epss 0.02

    Untrusted search path vulnerability in The installer of e-Tax Software all versions allows remote attackers to gain privileges via a Trojan horse DLL in an unspecified directory.

  • CVE-2016-4900HigMay 22, 2017
    risk 0.51cvss 7.8epss 0.02

    Untrusted search path vulnerability in Evernote for Windows versions prior to 6.3 allows remote attackers to gain privileges via a Trojan horse DLL in an unspecified directory.

  • CVE-2017-2167HigMay 12, 2017
    risk 0.51cvss 7.8epss 0.02

    Untrusted search path vulnerability in Installer for PrimeDrive Desktop Application version 1.4.4 and earlier allows remote attackers to execute arbitrary code via a specially crafted executable file in an unspecified directory.

  • CVE-2017-5236HigMay 3, 2017
    risk 0.51cvss 7.8epss 0.01

    Editions of Rapid7 AppSpider Pro installers prior to version 6.14.060 contain a DLL preloading vulnerability, wherein it is possible for the installer to load a malicious DLL located in the current working directory of the installer.

  • CVE-2017-2156HigApr 28, 2017
    risk 0.51cvss 7.8epss 0.03

    Untrusted search path vulnerability in Vivaldi installer for Windows prior to version 1.7.735.48 allows an attacker to execute arbitrary code via a specially crafted executable file in an unspecified directory.

  • CVE-2017-2130HigApr 28, 2017
    risk 0.51cvss 7.8epss 0.02

    Untrusted search path vulnerability in the installer of PhishWall Client Internet Explorer version Ver. 3.7.13 and earlier allows remote attackers to gain privileges via a Trojan horse DLL in an unspecified directory.

  • CVE-2017-2108HigApr 28, 2017
    risk 0.51cvss 7.8epss 0.01

    Untrusted search path vulnerability in PrimeDrive Desktop Application 1.4.3 and earlier allows remote attackers to gain privileges via a Trojan horse DLL in an unspecified directory.

  • CVE-2017-2107HigApr 28, 2017
    risk 0.51cvss 7.8epss 0.01

    Untrusted search path vulnerability in Self-extracting archive files created by 7-ZIP32.DLL 9.22.00.01 and earlier allows remote attackers to gain privileges via a Trojan horse DLL in an unspecified directory.

  • CVE-2016-4846HigApr 21, 2017
    risk 0.51cvss 7.8epss 0.01

    Untrusted search path vulnerability in the installer of PhishWall Client Internet Explorer before 3.7.8.2.

  • CVE-2017-3007HigApr 12, 2017
    risk 0.51cvss 7.8epss 0.01

    Adobe Thor versions 3.9.5.353 and earlier have a vulnerability in the directory search path used to find resources, related to Creative Cloud desktop applications.

  • CVE-2017-2983HigMar 14, 2017
    risk 0.51cvss 7.8epss 0.03

    Adobe Shockwave versions 12.2.7.197 and earlier have an insecure library loading (DLL hijacking) vulnerability. Successful exploitation could lead to escalation of privilege.

  • CVE-2017-6798HigMar 10, 2017
    risk 0.51cvss 7.8epss 0.04

    Trend Micro Endpoint Sensor 1.6 before b1290 has a DLL hijacking vulnerability that allows remote attackers to execute arbitrary code, aka Trend Micro Vulnerability Identifier 2015-0208.

  • CVE-2017-5235HigMar 2, 2017
    risk 0.51cvss 7.8epss 0.01

    Rapid7 Metasploit Pro installers prior to version 4.13.0-2017022101 contain a DLL preloading vulnerability, wherein it is possible for the installer to load a malicious DLL located in the current working directory of the installer.

  • CVE-2017-5234HigMar 2, 2017
    risk 0.51cvss 7.8epss 0.01

    Rapid7 Insight Collector installers prior to version 1.0.16 contain a DLL preloading vulnerability, wherein it is possible for the installer to load a malicious DLL located in the current working directory of the installer.

  • CVE-2017-5233HigMar 2, 2017
    risk 0.51cvss 7.8epss 0.01

    Rapid7 AppSpider Pro installers prior to version 6.14.053 contain a DLL preloading vulnerability, wherein it is possible for the installer to load a malicious DLL located in the current working directory of the installer.

  • CVE-2017-5232HigMar 2, 2017
    risk 0.51cvss 7.8epss 0.01

    All editions of Rapid7 Nexpose installers prior to version 6.4.24 contain a DLL preloading vulnerability, wherein it is possible for the installer to load a malicious DLL located in the current working directory of the installer.