VYPR

CWE-427

Uncontrolled Search Path Element

BaseDraft

Description

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-38 · CAPEC-471

CVEs mapped to this weakness (1,233)

page 22 of 62
  • CVE-2021-28647HigApr 13, 2021
    risk 0.51cvss 7.8epss 0.00

    Trend Micro Password Manager version 5 (Consumer) is vulnerable to a DLL Hijacking vulnerability which could allow an attacker to inject a malicious DLL file during the installation progress and could execute a malicious program each time a user installs a program.

  • CVE-2021-21545HigApr 12, 2021
    risk 0.51cvss 7.8epss 0.00

    Dell Peripheral Manager 1.3.1 or greater contains remediation for a local privilege escalation vulnerability that could be potentially exploited to gain arbitrary code execution on the system with privileges of the system user.

  • CVE-2020-6790HigMar 25, 2021
    risk 0.51cvss 7.8epss 0.00

    Calling an executable through an Uncontrolled Search Path Element in the Bosch Video Streaming Gateway installer up to and including version 6.45.10 potentially allows an attacker to execute arbitrary code on a victim's system. A prerequisite is that the victim is tricked into…

  • CVE-2020-6789HigMar 25, 2021
    risk 0.51cvss 7.8epss 0.00

    Loading a DLL through an Uncontrolled Search Path Element in the Bosch Monitor Wall installer up to and including version 10.00.0164 potentially allows an attacker to execute arbitrary code on a victim's system. A prerequisite is that the victim is tricked into placing a…

  • CVE-2020-6788HigMar 25, 2021
    risk 0.51cvss 7.8epss 0.00

    Loading a DLL through an Uncontrolled Search Path Element in the Bosch Configuration Manager installer up to and including version 7.21.0078 potentially allows an attacker to execute arbitrary code on a victim's system. A prerequisite is that the victim is tricked into placing a…

  • CVE-2020-6787HigMar 25, 2021
    risk 0.51cvss 7.8epss 0.00

    Loading a DLL through an Uncontrolled Search Path Element in the Bosch Video Client installer up to and including version 1.7.6.079 potentially allows an attacker to execute arbitrary code on a victim's system. A prerequisite is that the victim is tricked into placing a…

  • CVE-2020-6786HigMar 25, 2021
    risk 0.51cvss 7.8epss 0.00

    Loading a DLL through an Uncontrolled Search Path Element in the Bosch Video Recording Manager installer up to and including version 3.82.0055 for 3.82, up to and including version 3.81.0064 for 3.81 and 3.71 and older potentially allows an attacker to execute arbitrary code on…

  • CVE-2020-6785HigMar 25, 2021
    risk 0.51cvss 7.8epss 0.00

    Loading a DLL through an Uncontrolled Search Path Element in Bosch BVMS and BVMS Viewer in versions 10.1.0, 10.0.1, 10.0.0 and 9.0.0 and older potentially allows an attacker to execute arbitrary code on a victim's system. This affects both the installer as well as the installed…

  • CVE-2020-6771HigMar 25, 2021
    risk 0.51cvss 7.8epss 0.00

    Loading a DLL through an Uncontrolled Search Path Element in Bosch IP Helper up to and including version 1.00.0008 potentially allows an attacker to execute arbitrary code on a victim's system. A prerequisite is that the victim is tricked into placing a malicious DLL in the same…

  • CVE-2021-28954HigMar 21, 2021
    risk 0.51cvss 7.8epss 0.01

    In Chris Walz bit before 1.0.5 on Windows, attackers can run arbitrary code via a .exe file in a crafted repository.

  • CVE-2021-28953HigMar 21, 2021
    risk 0.51cvss 7.8epss 0.01

    The unofficial C/C++ Advanced Lint extension before 1.9.0 for Visual Studio Code allows attackers to execute arbitrary binaries if the user opens a crafted repository.

  • CVE-2020-9367HigMar 18, 2021
    risk 0.51cvss 7.8epss 0.01

    The MPS Agent in Zoho ManageEngine Desktop Central MSP build MSP build 10.0.486 is vulnerable to DLL Hijacking: dcinventory.exe and dcconfig.exe try to load CSUNSAPI.dll without supplying the complete path. The issue is aggravated because this DLL is missing from the…

  • CVE-2021-22665HigMar 18, 2021
    risk 0.51cvss 7.8epss 0.00

    Rockwell Automation DriveTools SP v5.13 and below and Drives AOP v4.12 and below both contain a vulnerability that a local attacker with limited privileges may be able to exploit resulting in privilege escalation and complete control of the system.

  • CVE-2020-26155HigMar 18, 2021
    risk 0.51cvss 7.8epss 0.00

    Multiple files and folders in Utimaco SecurityServer 4.20.0.4 and 4.31.1.0. are installed with Read/Write permissions for authenticated users, which allows for binaries to be manipulated by non-administrator users. Additionally, entries are made to the PATH environment variable…

  • CVE-2021-21518HigMar 12, 2021
    risk 0.51cvss 7.8epss 0.00

    Dell SupportAssist Client for Consumer PCs versions 3.7.x, 3.6.x, 3.4.x, 3.3.x, Dell SupportAssist Client for Business PCs versions 2.0.x, 2.1.x, 2.2.x, and Dell SupportAssist Client ProManage 1.x contain a DLL injection vulnerability in the Costura Fody plugin. A local user…

  • CVE-2021-20674HigMar 12, 2021
    risk 0.51cvss 7.8epss 0.01

    Untrusted search path vulnerability in Installer of MagicConnect Client program distributed before 2021 March 1 allows an attacker to gain privileges and via a Trojan horse DLL in an unspecified directory and to execute arbitrary code with the privilege of the user invoking the…

  • CVE-2020-28646HigFeb 26, 2021
    risk 0.51cvss 7.8epss 0.01

    ownCloud owncloud/client before 2.7 allows DLL Injection. The desktop client loaded development plugins from certain directories when they were present.

  • CVE-2021-1366HigFeb 17, 2021
    risk 0.51cvss 7.8epss 0.01

    A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack on an affected device if the VPN Posture (HostScan) Module is installed on the…

  • CVE-2020-24485HigFeb 17, 2021
    risk 0.51cvss 7.8epss 0.00

    Improper conditions check in the Intel(R) FPGA OPAE Driver for Linux before kernel version 4.17 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2020-25238HigFeb 9, 2021
    risk 0.51cvss 7.8epss 0.01

    A vulnerability has been identified in PCS neo (Administration Console) (All versions < V3.1), TIA Portal (V15, V15.1 and V16). Manipulating certain files in specific folders could allow a local attacker to execute code with SYSTEM privileges. The security vulnerability could be…