← Back
CWE-426

655 CVEs • Abstraction: Base • Likelihood of Exploit: High

Untrusted Search Path

The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.

JSON object

Loading...

CVEs (655)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Adobe
1Framemaker
Nov 21, 2024
Oct 17, 2018
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Adobe Framemaker versions 1.0.5.1 and below have an insecure library loading (dll hijacking) vulnerability. Successful exploitation could lead to privilege escalation.
1Nomachine
1Nomachine
Nov 21, 2024
Oct 15, 2018
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
NoMachine before 5.3.27 and 6.x before 6.3.6 allows attackers to gain privileges via a Trojan horse wintab32.dll file located in the same directory as a .nxs file, as demonstrated by a scenario where the .nxs file and th...Show more
NoMachine before 5.3.27 and 6.x before 6.3.6 allows attackers to gain privileges via a Trojan horse wintab32.dll file located in the same directory as a .nxs file, as demonstrated by a scenario where the .nxs file and the DLL are in the current working directory, and the Trojan horse code is executed. (The directory could, in general, be on a local filesystem or a network share.).Show less
1Navercorp
1Whale
Nov 21, 2024
Oct 11, 2018
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
The Whale browser installer 0.4.3.0 and earlier versions allows DLL hijacking.
1Mcafee
1True Key
Jun 17, 2026
Sep 24, 2018
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
DLL Search Order Hijacking vulnerability in Microsoft Windows Client in McAfee True Key (TK) before 5.1.165 allows local users to execute arbitrary code via specially crafted malware.
1Eset
6Compusec
Deslock+ ProInternet Security+3 more
Nov 21, 2024
Sep 7, 2018
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
Untrusted search path vulnerability in the installers of multiple Canon IT Solutions Inc. software programs (ESET Smart Security Premium, ESET Internet Security, ESET Smart Security, ESET NOD32 Antivirus, DESlock+ Pro, a...Show more
Untrusted search path vulnerability in the installers of multiple Canon IT Solutions Inc. software programs (ESET Smart Security Premium, ESET Internet Security, ESET Smart Security, ESET NOD32 Antivirus, DESlock+ Pro, and CompuSec (all programs except packaged ones)) allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.Show less
1Chatwork
1Chatwork
Nov 21, 2024
Sep 7, 2018
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Untrusted search path vulnerability in installer of ChatWork Desktop App for Windows 2.3.0 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
1Yayoi Kk
6Aoiro Shinkoku
HanbaiKaikei+3 more
Nov 21, 2024
Sep 7, 2018
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Untrusted search path vulnerability in Multiple Yayoi 17 Series products (Yayoi Kaikei 17 Series Ver.23.1.1 and earlier, Yayoi Aoiro Shinkoku 17 Ver.23.1.1 and earlier, Yayoi Kyuuyo 17 Ver.20.1.4 and earlier, Yayoi Kyuuy...Show more
Untrusted search path vulnerability in Multiple Yayoi 17 Series products (Yayoi Kaikei 17 Series Ver.23.1.1 and earlier, Yayoi Aoiro Shinkoku 17 Ver.23.1.1 and earlier, Yayoi Kyuuyo 17 Ver.20.1.4 and earlier, Yayoi Kyuuyo Keisan 17 Ver.20.1.4 and earlier, Yayoi Hanbai 17 Series Ver.20.0.2 and earlier, and Yayoi Kokyaku Kanri 17 Ver.11.0.2 and earlier) allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. This flaw exists within the handling of ykkapi.dll loaded by the vulnerable products.Show less
1Yayoi Kk
6Aoiro Shinkoku
HanbaiKaikei+3 more
Nov 21, 2024
Sep 7, 2018
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Untrusted search path vulnerability in Multiple Yayoi 17 Series products (Yayoi Kaikei 17 Series Ver.23.1.1 and earlier, Yayoi Aoiro Shinkoku 17 Ver.23.1.1 and earlier, Yayoi Kyuuyo 17 Ver.20.1.4 and earlier, Yayoi Kyuuy...Show more
Untrusted search path vulnerability in Multiple Yayoi 17 Series products (Yayoi Kaikei 17 Series Ver.23.1.1 and earlier, Yayoi Aoiro Shinkoku 17 Ver.23.1.1 and earlier, Yayoi Kyuuyo 17 Ver.20.1.4 and earlier, Yayoi Kyuuyo Keisan 17 Ver.20.1.4 and earlier, Yayoi Hanbai 17 Series Ver. 20.0.2 and earlier, and Yayoi Kokyaku Kanri 17 Ver.11.0.2 and earlier) allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. This flaw exists within the handling of msjet49.dll loaded by the vulnerable products.Show less
4Debian
GlusterOpensuse+1 more
5Debian Linux
Enterprise Linux ServerGlusterfs+2 more
Nov 21, 2024
Sep 4, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
It was found that glusterfs server does not properly sanitize file paths in the "trusted.io-stats-dump" extended attribute which is used by the "debug/io-stats" translator. Attacker can use this flaw to create files and...Show more
It was found that glusterfs server does not properly sanitize file paths in the "trusted.io-stats-dump" extended attribute which is used by the "debug/io-stats" translator. Attacker can use this flaw to create files and execute arbitrary code. To exploit this attacker would require sufficient access to modify the extended attributes of files on a gluster volume.Show less
1Sony
1Digital Paper App
Nov 21, 2024
Sep 4, 2018
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Untrusted search path vulnerability in The installer of Digital Paper App version 1.4.0.16050 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
1Adobe
1Creative Cloud
Nov 21, 2024
Aug 29, 2018
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Adobe Creative Cloud Desktop Application before 4.5.5.342 (installer) has an insecure library loading (dll hijacking) vulnerability. Successful exploitation could lead to privilege escalation.
1Logitech
1Connection Utility Software
Nov 21, 2024
Jul 26, 2018
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Untrusted search path vulnerability in LOGICOOL CONNECTION UTILITY SOFTWARE versions before 2.30.9 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
1Logitech
1Game Software
Nov 21, 2024
Jul 26, 2018
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Untrusted search path vulnerability in LOGICOOL Game Software versions before 8.87.116 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
1Glarysoft
1Glary Utilities
Nov 21, 2024
Jul 26, 2018
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Untrusted search path vulnerability in the installer of Glarysoft Glary Utilities (Glary Utilities 5.99 and earlier and Glary Utilities Pro 5.99 and earlier) allows an attacker to gain privileges via a Trojan horse DLL i...Show more
Untrusted search path vulnerability in the installer of Glarysoft Glary Utilities (Glary Utilities 5.99 and earlier and Glary Utilities Pro 5.99 and earlier) allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.Show less
4Canonical
DebianRedhat+1 more
10Ansible Engine
Ceph StorageDebian Linux+7 more
Nov 21, 2024
Jul 13, 2018
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
A flaw was found in ansible. ansible.cfg is read from the current working directory which can be altered to make it point to a plugin or a module path under the control of an attacker, thus allowing the attacker to execu...Show more
A flaw was found in ansible. ansible.cfg is read from the current working directory which can be altered to make it point to a plugin or a module path under the control of an attacker, thus allowing the attacker to execute arbitrary code.Show less
1Ibm
1Db2
Nov 21, 2024
Jul 10, 2018
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5 and 11.1 binaries load shared libraries from an untrusted path potentially giving low privilege users full access to the DB2 instance acco...Show more
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5 and 11.1 binaries load shared libraries from an untrusted path potentially giving low privilege users full access to the DB2 instance account by loading a malicious shared library. IBM X-Force ID: 140972.Show less
1Ibm
1Db2
Nov 21, 2024
Jul 10, 2018
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10,1, 10.5 and 11.1 could allow a local user to execute arbitrary code and conduct DLL hijacking attacks. IBM X-Force ID: 140209.
1Goldenfrog
1Vyprvpn
Nov 21, 2024
Jul 4, 2018
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Golden Frog VyprVPN before 2018-06-21 has a vulnerability associated with the installation process on Windows.
1Anydesk
1Anydesk
Nov 21, 2024
Jul 3, 2018
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
AnyDesk before "12.06.2018 - 4.1.3" on Windows 7 SP1 has a DLL preloading vulnerability.
1Redhat
4Ansible Engine
OpenstackVirtualization+1 more
Nov 21, 2024
Jul 2, 2018
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
In ansible it was found that inventory variables are loaded from current working directory when running ad-hoc command which are under attacker's control, allowing to run arbitrary code as a result.