CWE-427
1,189 CVEs • Abstraction: Base
Uncontrolled Search Path Element
The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.
CVEs (1,189)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, and 8.1 software. Certain security settings, related to whether packages are verified and accepted only from known sources, are mishandled....Show more |
An issue was discovered in LG PC Suite for LG G3 and earlier (aka LG PC Suite v5.3.27 and earlier). DLL Hijacking can occur via a Trojan horse DLL in the current working directory. The LG ID is LVE-MOT-190001 (November 2...Show more |
1Starface 1Unified Communication & Collaboration Client Jun 17, 2026 Apr 2, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 STARFACE UCC Client before 6.7.1.204 on WIndows allows binary planting to execute code with System rights, aka usd-2020-0006. |
In UniFi Video v3.10.1 (for Windows 7/8/10 x64) there is a Local Privileges Escalation to SYSTEM from arbitrary file deletion and DLL hijack vulnerabilities. The issue was fixed by adjusting the .tsExport folder when the...Show more |
1Adobe 2Acrobat Dc Acrobat Reader DcJun 17, 2026 Mar 25, 2020 N/A· v4 7.8 HIGH· v3 4.4 MEDIUM· v2 Adobe Acrobat and Reader versions 2020.006.20034 and earlier, 2017.011.30158 and earlier, 2017.011.30158 and earlier, 2015.006.30510 and earlier, and 2015.006.30510 and earlier have an insecure library loading (dll hijac...Show more |
DevActSvc.exe in ASUS Device Activation before 1.0.7.0 for Windows 10 notebooks and PCs could lead to unsigned code execution with no additional restrictions when a user puts an application at a particular path with a pa...Show more |
1Schneider Electric 1Pmepxm0100 Prosoft Configurator Jun 17, 2026 Mar 23, 2020 N/A· v4 7.8 HIGH· v3 4.4 MEDIUM· v2 A CWE-427: Uncontrolled Search Path Element vulnerability exists in ProSoft Configurator (v1.002 and prior), for the PMEPXM0100 (H) module, which could cause the execution of untrusted code when using double click to ope...Show more |
1Fortinet 2Forticlient Forticlient Virtual Private NetworkJun 17, 2026 Mar 15, 2020 N/A· v4 7.8 HIGH· v3 6.9 MEDIUM· v2 An Unsafe Search Path vulnerability in FortiClient for Windows online installer 6.2.3 and below may allow a local attacker with control over the directory in which FortiClientOnlineInstaller.exe and FortiClientVPNOnlineI...Show more |
1Fortinet 1Forticlient Emergency Management Server Jun 17, 2026 Mar 15, 2020 N/A· v4 7.8 HIGH· v3 6.9 MEDIUM· v2 An Unsafe Search Path vulnerability in FortiClient EMS online installer 6.2.1 and below may allow a local attacker with control over the directory in which FortiClientEMSOnlineInstaller.exe resides to execute arbitrary c...Show more |
Trend Micro Password Manager for Windows version 5.0 is affected by a DLL hijacking vulnerability would could potentially allow an attacker privleged escalation. |
Uncontrolled search path in Intel(R) Graphics Drivers before version 26.20.100.7158 may allow an authenticated user to potentially enable escalation of privilege via local access. |
Uncontrolled search path element in the installer for Intel(R) Graphics Drivers before versions 26.20.100.7584, 15.45.30.5103, 15.40.44.5107, 15.36.38.5117, and 15.33.49.5100 may allow an authenticated user to potentiall...Show more |
1Dell 113G3 15 3590 Firmware G3 3579 FirmwareG3 3779 Firmware+110 moreJun 17, 2026 Feb 21, 2020 N/A· v4 4.4 MEDIUM· v3 2.6 LOW· v2 Dell Client Consumer and Commercial Platforms contain an Arbitrary File Overwrite Vulnerability. The vulnerability is limited to the Dell Firmware Update Utility during the time window while being executed by an administ...Show more |
1Trendmicro 1Vulnerability Protection Jun 17, 2026 Feb 20, 2020 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Trend Micro Vulnerability Protection 2.0 is affected by a vulnerability that could allow an attack to use the product installer to load other DLL files located in the same directory. |
1Trendmicro 8Control Manager Endpoint SensorIm Security+5 moreJun 17, 2026 Feb 20, 2020 N/A· v4 7.0 HIGH· v3 5.1 MEDIUM· v2 Trend Micro has repackaged installers for several Trend Micro products that were found to utilize a version of an install package that had a DLL hijack vulnerability that could be exploited during a new product installat...Show more |
1Cisco 1Anyconnect Secure Mobility Client Jun 17, 2026 Feb 19, 2020 N/A· v4 6.5 MEDIUM· v3 4.9 MEDIUM· v2 A vulnerability in the installer component of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated local attacker to copy user-supplied files to system level directories with system level priv...Show more |
1Westerndigital 2Sandiskssddashboardsetup.exe Westerndigitalssddashboardsetup.exeJun 17, 2026 Feb 19, 2020 N/A· v4 7.8 HIGH· v3 4.4 MEDIUM· v2 Western Digital WesternDigitalSSDDashboardSetup.exe before 3.0.2.0 allows DLL Hijacking. |
Symantec Endpoint Protection (SEP) and Symantec Endpoint Protection Small Business Edition (SEP SBE), prior to 14.2 RU2 MP1 and prior to 14.2.5569.2100 respectively, may be susceptible to a DLL injection vulnerability, w...Show more |
1Atlassian 2Confluence Confluence ServerJun 17, 2026 Feb 6, 2020 N/A· v4 7.8 HIGH· v3 4.4 MEDIUM· v2 The usage of Tomcat in Confluence on the Microsoft Windows operating system before version 7.0.5, and from version 7.1.0 before version 7.1.1 allows local system attackers who have permission to write a DLL file in a dir...Show more |
The usage of Tomcat in Jira before version 8.5.2 allows local attackers with permission to write a dll file to a directory in the global path environmental variable can inject code into via a DLL hijacking vulnerability. |