VYPR

CWE-427

Uncontrolled Search Path Element

BaseDraft

Description

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-38 · CAPEC-471

CVEs mapped to this weakness (1,213)

page 51 of 61
  • CVE-2022-26421MedFeb 16, 2023
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path element in the Intel(R) oneAPI DPC++/C++ Compiler Runtime before version 2022.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-26345MedFeb 16, 2023
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path element in the Intel(R) oneAPI Toolkit OpenMP before version 2022.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-26076MedFeb 16, 2023
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path element in the Intel(R) oneAPI Deep Neural Network (oneDNN) before version 2022.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-26062MedFeb 16, 2023
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path element in the Intel(R) Trace Analyzer and Collector before version 2021.6 for Intel(R) oneAPI HPC Toolkit may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-26052MedFeb 16, 2023
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path element in the Intel(R) MPI Library before version 2021.6 for Intel(R) oneAPI HPC Toolkit may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-26032MedFeb 16, 2023
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path element in the Intel(R) Distribution for Python programming language before version 2022.1 for Intel(R) oneAPI Toolkits may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-25905MedFeb 16, 2023
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path element in the Intel(R) oneAPI Data Analytics Library (oneDAL) before version 2021.5 for Intel(R) oneAPI Base Toolkit may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-31611MedFeb 7, 2023
    risk 0.44cvss 6.8epss 0.00

    NVIDIA GeForce Experience contains an uncontrolled search path vulnerability in all its client installers, where an attacker with user level privileges may cause the installer to load an arbitrary DLL when the installer is launched. A successful exploit of this vulnerability…

  • CVE-2022-38136MedFeb 6, 2023
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path in the Intel(R) oneAPI DPC++/C++ Compiler for Windows and Intel Fortran Compiler for Windows before version 2022.2.1 for some Intel(R) oneAPI Toolkits before version 2022.3.1 may allow an authenticated user to potentially enable escalation of privilege…

  • CVE-2022-47632MedJan 27, 2023
    risk 0.44cvss 6.8epss 0.01

    Razer Synapse before 3.7.0830.081906 allows privilege escalation due to an unsafe installation path, improper privilege management, and improper certificate validation. Attackers can place malicious DLLs into %PROGRAMDATA%\Razer\Synapse3\Service\bin if they do so before the…

  • CVE-2023-0247HigJan 12, 2023
    risk 0.44cvss 7.8epss 0.00

    Uncontrolled Search Path Element in GitHub repository bits-and-blooms/bloom prior to 3.3.1.

  • CVE-2021-36631MedDec 22, 2022
    risk 0.44cvss 6.7epss 0.00

    Untrusted search path vulnerability in Baidunetdisk Version 7.4.3 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

  • CVE-2022-3859MedNov 30, 2022
    risk 0.44cvss 6.7epss 0.00

    An uncontrolled search path vulnerability exists in Trellix Agent (TA) for Windows in versions prior to 5.7.8. This allows an attacker with admin access, which is required to place the DLL in the restricted Windows System folder, to elevate their privileges to System by placing…

  • CVE-2022-36380MedNov 11, 2022
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path in the installer software for some Intel(r) NUC Kit Wireless Adapter drivers for Windows 10 before version 22.40 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-30548MedNov 11, 2022
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path element in the Intel(R) Glorp software may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-27638MedNov 11, 2022
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path element in the Intel(R) Advanced Link Analyzer Pro before version 22.2 and Standard edition software before version 22.1.1 STD may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-27187MedNov 11, 2022
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path element in the Intel(R) Quartus Prime Standard edition software before version 21.1 Patch 0.02std may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-26086MedNov 11, 2022
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path element in the PresentMon software maintained by Intel(R) before version 1.7.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-26028MedNov 11, 2022
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path in the Intel(R) VTune(TM) Profiler software before version 2022.2.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2021-33064MedNov 11, 2022
    risk 0.44cvss 6.7epss 0.00

    Uncontrolled search path in the software installer for Intel(R) System Studio for all versions, may allow an authenticated user to potentially enable escalation of privilege via local access.