CWE-426
655 CVEs • Abstraction: Base • Likelihood of Exploit: High
Untrusted Search Path
The product searches for critical resources using an externally-supplied search path that can point to resources that are not under the product's direct control.
CVEs (655)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Trend Micro Endpoint Sensor 1.6 before b1290 has a DLL hijacking vulnerability that allows remote attackers to execute arbitrary code, aka Trend Micro Vulnerability Identifier 2015-0208. |
Rapid7 Metasploit Pro installers prior to version 4.13.0-2017022101 contain a DLL preloading vulnerability, wherein it is possible for the installer to load a malicious DLL located in the current working directory of the...Show more |
Rapid7 Insight Collector installers prior to version 1.0.16 contain a DLL preloading vulnerability, wherein it is possible for the installer to load a malicious DLL located in the current working directory of the install...Show more |
Rapid7 AppSpider Pro installers prior to version 6.14.053 contain a DLL preloading vulnerability, wherein it is possible for the installer to load a malicious DLL located in the current working directory of the installer...Show more |
All editions of Rapid7 Nexpose installers prior to version 6.4.24 contain a DLL preloading vulnerability, wherein it is possible for the installer to load a malicious DLL located in the current working directory of the i...Show more |
Multiple untrusted search path vulnerabilities in Putty beta 0.67 allow local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse (1) UxTheme.dll or (2) ntmarta.dll file in the current wo...Show more |
Untrusted search path vulnerability in Snort 2.9.7.0-WIN32 allows remote attackers to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse tcapi.dll that is located in the same folder on a remote f...Show more |
Untrusted search path vulnerability in the installer for TrueCrypt 7.2 and 7.1a, VeraCrypt before 1.17-BETA, and possibly other products allows local users to execute arbitrary code with administrator privileges and cond...Show more |
Untrusted search path vulnerability in ssh-agent.c in ssh-agent in OpenSSH before 7.4 allows remote attackers to execute arbitrary local PKCS#11 modules by leveraging control over a forwarded agent-socket. |
1Vmware 2Workstation Player Workstation ProMay 6, 2026 Dec 29, 2016 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Untrusted search path vulnerability in the installer in VMware Workstation Pro 12.x before 12.5.0 and VMware Workstation Player 12.x before 12.5.0 on Windows allows local users to gain privileges via a Trojan horse DLL i...Show more |
1Microsoft 1Auto Updater For Mac May 6, 2026 Dec 20, 2016 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Untrusted search path vulnerability in Microsoft Auto Updater for Mac allows local users to gain privileges via a Trojan horse executable file, aka "Microsoft (MAU) Office Elevation of Privilege Vulnerability." |
1Git For Windows Project 1Git For Windows May 6, 2026 Nov 11, 2016 N/A· v4 7.8 HIGH· v3 4.4 MEDIUM· v2 Untrusted search path vulnerability in Git 1.x for Windows allows local users to gain privileges via a Trojan horse git.exe file in the current working directory. NOTE: 2.x is unaffected. |
Untrusted search path vulnerability in the HGFS (aka Shared Folders) feature in VMware Tools 10.0.5 in VMware ESXi 5.0 through 6.0, VMware Workstation Pro 12.1.x before 12.1.1, VMware Workstation Player 12.1.x before 12....Show more |
1Adobe 5Air Desktop Runtime Air SdkAir Sdk & Compiler+2 moreMay 6, 2026 Apr 9, 2016 N/A· v4 7.3 HIGH· v3 6.9 MEDIUM· v2 Untrusted search path vulnerability in Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows local users to gain privileges via a Trojan...Show more |
1Microsoft 5Windows 10 Windows 7Windows 8+2 moreMay 6, 2026 Jan 13, 2016 N/A· v4 7.3 HIGH· v3 6.9 MEDIUM· v2 Microsoft Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 R2, and Windows 10 Gold and 1511 mishandle DLL loading, which allows local users to gain privileges via a crafted application, aka "DLL Loading Remote...Show more |
1Microsoft 9Windows 10 Windows 7Windows 8+6 moreMay 6, 2026 Jan 13, 2016 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 mishandle DLL loading, which...Show more |
1Microsoft 9Windows 10 Windows 7Windows 8+6 moreMay 6, 2026 Jan 13, 2016 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 mishandle DLL loading, which...Show more |
1Cisco 1Anyconnect Secure Mobility Client May 6, 2026 Sep 26, 2015 N/A· v4 N/A· v3 7.2 HIGH· v2 Untrusted search path vulnerability in the CMainThread::launchDownloader function in vpndownloader.exe in Cisco AnyConnect Secure Mobility Client 2.0 through 4.1 on Windows allows local users to gain privileges via a Tro...Show more |
Multiple unquoted Windows search path vulnerabilities in the (1) Client Management and (2) Gateway in McAfee ePO Deep Command 2.1 and 2.2 before HF 1058831 allow local users to gain privileges via unspecified vectors. |
1Microsoft 9Windows 7 Windows 8Windows 8.1+6 moreMay 6, 2026 Mar 11, 2015 N/A· v4 N/A· v3 9.3 HIGH· v2 Untrusted search path vulnerability in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold...Show more |