← Back
CWE-426

655 CVEs • Abstraction: Base • Likelihood of Exploit: High

Untrusted Search Path

The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.

JSON object

Loading...

CVEs (655)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Londontrustmedia
1Private Internet Access Vpn Client
Jun 17, 2026
Jul 11, 2019
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v1.0 for Windows could allow an authenticated, local attacker to run arbitrary code with elevated privileges. The PIA client is vulnerabl...Show more
A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v1.0 for Windows could allow an authenticated, local attacker to run arbitrary code with elevated privileges. The PIA client is vulnerable to a DLL injection vulnerability during the software update process. The updater loads several libraries from a folder that authenticated users have write access to. A low privileged user can leverage this vulnerability to execute arbitrary code as SYSTEM.Show less
1Omron
1Network Configurator For Devicenet Safety
Jun 17, 2026
Jun 12, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
The application (Network Configurator for DeviceNet Safety 3.41 and prior) searches for resources by means of an untrusted search path that could execute a malicious .dll file not under the application's direct control a...Show more
The application (Network Configurator for DeviceNet Safety 3.41 and prior) searches for resources by means of an untrusted search path that could execute a malicious .dll file not under the application's direct control and outside the intended directories.Show less
1Rakuten
1Viber
Jun 17, 2026
Jun 3, 2019
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
A vulnerability in Viber before 10.7.0 for Desktop (Windows) could allow an attacker to execute arbitrary commands on a targeted system. This vulnerability is due to unsafe search paths used by the application URI. An at...Show more
A vulnerability in Viber before 10.7.0 for Desktop (Windows) could allow an attacker to execute arbitrary commands on a targeted system. This vulnerability is due to unsafe search paths used by the application URI. An attacker could exploit this vulnerability by convincing a targeted user to follow a malicious link. Successful exploitation could cause the application to load libraries from the directory targeted by the URI link. The attacker could use this behavior to execute arbitrary commands on the system with the privileges of the targeted user, if the attacker can place a crafted library in a directory that is accessible to the vulnerable system.Show less
1Fortinet
1Forticlient
Jun 17, 2026
May 28, 2019
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
An Unsafe Search Path vulnerability in FortiClient Online Installer (Windows version before 6.0.6) may allow an unauthenticated, remote attacker with control over the directory in which FortiClientOnlineInstaller.exe res...Show more
An Unsafe Search Path vulnerability in FortiClient Online Installer (Windows version before 6.0.6) may allow an unauthenticated, remote attacker with control over the directory in which FortiClientOnlineInstaller.exe resides to execute arbitrary code on the system via uploading malicious .dll files in that directory.Show less
1Fujitsu
1Paperstream Ip (twain)
Nov 21, 2024
May 17, 2019
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
In PaperStream IP (TWAIN) 1.42.0.5685 (Service Update 7), the FJTWSVIC service running with SYSTEM privilege processes unauthenticated messages received over the FjtwMkic_Fjicube_32 named pipe. One of these message proce...Show more
In PaperStream IP (TWAIN) 1.42.0.5685 (Service Update 7), the FJTWSVIC service running with SYSTEM privilege processes unauthenticated messages received over the FjtwMkic_Fjicube_32 named pipe. One of these message processing functions attempts to dynamically load the UninOldIS.dll library and executes an exported function named ChangeUninstallString. The default install does not contain this library and therefore if any DLL with that name exists in any directory listed in the PATH variable, it can be used to escalate to SYSTEM level privilege.Show less
1Soumu
1Electronic Reception And Examination Of Application For Radio Licenses
Jun 17, 2026
May 17, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Untrusted search path vulnerability in Electronic reception and examination of application for radio licenses Offline 1.0.9.0 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified dir...Show more
Untrusted search path vulnerability in Electronic reception and examination of application for radio licenses Offline 1.0.9.0 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.Show less
1Soumu
1Electronic Reception And Examination Of Application For Radio Licenses
Jun 17, 2026
May 17, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Untrusted search path vulnerability in Installer of Electronic reception and examination of application for radio licenses Online 1.0.9.0 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an uns...Show more
Untrusted search path vulnerability in Installer of Electronic reception and examination of application for radio licenses Online 1.0.9.0 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.Show less
3Debian
FedoraprojectFilezilla Project
3Debian Linux
FedoraFilezilla Client
Jun 17, 2026
Apr 29, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Untrusted search path in FileZilla before 3.41.0-rc1 allows an attacker to gain privileges via a malicious 'fzsftp' binary in the user's home directory.
1Mozilla
1Firefox
Jun 17, 2026
Apr 26, 2019
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
On Android systems, Firefox can load a library from APITRACE_LIB, which is writable by all users and applications. This could allow malicious third party applications to execute a man-in-the-middle attack if a malicious...Show more
On Android systems, Firefox can load a library from APITRACE_LIB, which is writable by all users and applications. This could allow malicious third party applications to execute a man-in-the-middle attack if a malicious code was written to that location and loaded. *Note: This issue only affects Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 66.Show less
1Symantec
1Endpoint Protection Manager
Nov 21, 2024
Apr 25, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Symantec Endpoint Protection Manager (SEPM) prior to and including 12.1 RU6 MP9 and prior to 14.2 RU1 may be susceptible to a DLL Preloading vulnerability, which is a type of issue that can occur when an application look...Show more
Symantec Endpoint Protection Manager (SEPM) prior to and including 12.1 RU6 MP9 and prior to 14.2 RU1 may be susceptible to a DLL Preloading vulnerability, which is a type of issue that can occur when an application looks to call a DLL for execution and an attacker provides a malicious DLL to use instead.Show less
1Symantec
4Endpoint Protection
Endpoint Protection CloudEndpoint Protection Cloud Agent+1 more
Nov 21, 2024
Apr 25, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Norton Security (Windows client) prior to 22.16.3 and SEP SBE (Windows client) prior to Cloud Agent 3.00.31.2817, NIS-22.15.2.22 & SEP-12.1.7484.7002, may be susceptible to a DLL Preloading vulnerability, which is a type...Show more
Norton Security (Windows client) prior to 22.16.3 and SEP SBE (Windows client) prior to Cloud Agent 3.00.31.2817, NIS-22.15.2.22 & SEP-12.1.7484.7002, may be susceptible to a DLL Preloading vulnerability, which is a type of issue that can occur when an application looks to call a DLL for execution and an attacker provides a malicious DLL to use instead.Show less
1Teamspeak
1Teamspeak
Jun 17, 2026
Apr 19, 2019
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
TeamSpeak 3 Client before 3.2.5 allows remote code execution in the Qt framework.
1Checkpoint
1Zonealarm
Jun 17, 2026
Apr 17, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Some of the DLLs loaded by Check Point ZoneAlarm up to 15.4.062 are taken from directories where all users have write permissions. This can allow a local attacker to replace a DLL file with a malicious one and cause Deni...Show more
Some of the DLLs loaded by Check Point ZoneAlarm up to 15.4.062 are taken from directories where all users have write permissions. This can allow a local attacker to replace a DLL file with a malicious one and cause Denial of Service to the client.Show less
1Beyondtrust
1Avecto Defendpoint
Nov 21, 2024
Apr 17, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Avecto Defendpoint 4 prior to 4.4 SR6 and 5 prior to 5.1 SR1 has an Untrusted Search Path vulnerability, exploitable by modifying environment variables to trigger automatic elevation of an attacker's process launch.
1Lenovo
1Bootable Usb
Jun 17, 2026
Apr 10, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A DLL search path vulnerability was reported in Lenovo Bootable Generator, prior to version Mar-2019, that could allow a malicious user with local access to execute code on the system.
1Microsoft
1Visual Studio 2017
Jun 17, 2026
Apr 9, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A remote code execution vulnerability exists when the Visual Studio C++ Redistributable Installer improperly validates input before loading dynamic link library (DLL) files, aka 'Visual Studio Remote Code Execution Vulne...Show more
A remote code execution vulnerability exists when the Visual Studio C++ Redistributable Installer improperly validates input before loading dynamic link library (DLL) files, aka 'Visual Studio Remote Code Execution Vulnerability'.Show less
1Opera
1Opera Browser
Nov 21, 2024
Mar 21, 2019
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
Opera before 57.0.3098.106 is vulnerable to a DLL Search Order hijacking attack where an attacker can send a ZIP archive composed of an HTML page along with a malicious DLL to the target. Once the document is opened, it...Show more
Opera before 57.0.3098.106 is vulnerable to a DLL Search Order hijacking attack where an attacker can send a ZIP archive composed of an HTML page along with a malicious DLL to the target. Once the document is opened, it may allow the attacker to take full control of the system from any location within the system. The issue lies in the loading of the shcore.dll and dcomp.dll files: these files are being searched for by the program in the same system-wide directory where the HTML file is executed.Show less
1Barracuda
1Vpn Client
Jun 17, 2026
Mar 21, 2019
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
The barracudavpn component of the Barracuda VPN Client prior to version 5.0.2.7 for Linux, macOS, and OpenBSD runs as a privileged process and can allow an unprivileged local attacker to load a malicious library, resulti...Show more
The barracudavpn component of the Barracuda VPN Client prior to version 5.0.2.7 for Linux, macOS, and OpenBSD runs as a privileged process and can allow an unprivileged local attacker to load a malicious library, resulting in arbitrary code executing as root.Show less
1Microsoft
1Teams
Jun 17, 2026
Mar 12, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Untrusted search path vulnerability in The installer of Microsoft Teams allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
1Microsoft
1Windows 7
Jun 17, 2026
Mar 12, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Untrusted search path vulnerability in Windows 7 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.