CWE-427
1,189 CVEs • Abstraction: Base
Uncontrolled Search Path Element
The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.
CVEs (1,189)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Comodo 1Comodo Internet Security Jun 17, 2026 Nov 18, 2019 N/A· v4 7.8 HIGH· v3 4.4 MEDIUM· v2 An issue was discovered in signmgr.dll 6.5.0.819 in Comodo Internet Security through 12.0. A DLL Preloading vulnerability allows an attacker to implant an unsigned DLL named iLog.dll in a partially unprotected product di...Show more |
1Symantec 1Endpoint Protection Jun 17, 2026 Nov 15, 2019 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 Symantec Endpoint Protection, prior to 14.2 RU2, may be susceptible to an unsigned code execution vulnerability, which may allow an individual to execute code without a resident proper digital signature. |
Adobe Illustrator CC versions 23.1 and earlier have an insecure library loading (dll hijacking) vulnerability. Successful exploitation could lead to privilege escalation. |
Adobe Animate CC versions 19.2.1 and earlier have an insecure library loading (dll hijacking) vulnerability. Successful exploitation could lead to privilege escalation. |
1Nvidia 2Geforce Experience Gpu DriverJun 17, 2026 Nov 12, 2019 N/A· v4 6.5 MEDIUM· v3 6.9 MEDIUM· v2 NVIDIA GeForce Experience (prior to 3.20.1) and Windows GPU Display Driver (all versions) contains a vulnerability in the local service provider component in which an attacker with local system and privileged access can...Show more |
NVIDIA GeForce Experience, all versions prior to 3.20.0.118, contains a vulnerability when GameStream is enabled in which an attacker with local system access can load the Intel graphics driver DLLs without validating th...Show more |
NVIDIA Windows GPU Display Driver, R390 driver version, contains a vulnerability in NVIDIA Control Panel in which it incorrectly loads Windows system DLLs without validating the path or signature (also known as a binary...Show more |
A malicious DLL preload vulnerability in Fortinet FortiClient for Windows 6.2.0 and below allows a privileged attacker to perform arbitrary code execution via forging that DLL. |
2Avas!t Avg2Anti Virus AntivirusJun 17, 2026 Oct 23, 2019 N/A· v4 7.8 HIGH· v3 4.4 MEDIUM· v2 An issue was discovered in Avast antivirus before 19.8 and AVG antivirus before 19.8. A DLL Preloading vulnerability allows an attacker to implant %WINDIR%\system32\wbemcomn.dll, which is loaded into a protected-light pr...Show more |
1Trendmicro 1Anti Threat Toolkit Jun 17, 2026 Oct 21, 2019 N/A· v4 7.8 HIGH· v3 5.1 MEDIUM· v2 Trend Micro Anti-Threat Toolkit (ATTK) versions 1.62.0.1218 and below have a vulnerability that may allow an attacker to place malicious files in the same directory, potentially leading to arbitrary remote code execution...Show more |
NSA Ghidra before 9.0.2 is vulnerable to DLL hijacking because it loads jansi.dll from the current working directory. |
A potential security vulnerability has been identified with certain versions of HP Touchpoint Analytics prior to version 4.1.4.2827. This vulnerability may allow a local attacker with administrative privileges to execute...Show more |
1Dell 2Encryption Endpoint Security Suite EnterpriseJun 17, 2026 Oct 7, 2019 N/A· v4 7.3 HIGH· v3 6.9 MEDIUM· v2 The vulnerability is limited to the installers of Dell Encryption Enterprise versions prior to 10.4.0 and Dell Endpoint Security Suite Enterprise versions prior to 2.4.0. This issue is exploitable only during the install...Show more |
JetBrains ReSharper installers for versions before 2019.2 had a DLL Hijacking vulnerability. |
1Dell 1Update Package Framework Jun 17, 2026 Sep 24, 2019 N/A· v4 6.7 MEDIUM· v3 6.2 MEDIUM· v2 An Uncontrolled Search Path Vulnerability is applicable to the following: Dell Update Package (DUP) Framework file versions prior to 19.1.0.413, and Framework file versions prior to 103.4.6.69 used in Dell EMC Servers. D...Show more |
Adobe application manager installer version 10.0 have an Insecure Library Loading (DLL hijacking) vulnerability. Successful exploitation could lead to Arbitrary Code Execution in the context of the current user. |
Prior to 0.1, AIX builds of Eclipse OMR contain unused RPATHs which may facilitate code injection and privilege elevation by local users. |
1Ibm 1Db2 High Performance Unload Load Jun 17, 2026 Aug 26, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 IBM DB2 High Performance Unload load for LUW 6.1, 6.1.0.1, 6.1.0.1 IF1, 6.1.0.2, 6.1.0.2 IF1, and 6.1.0.1 IF2 db2hpum_debug is a setuid root binary which trusts the PATH environment variable. A low privileged user can ex...Show more |
1Autodesk 11Advance Steel AutocadAutocad Architecture+8 moreJun 17, 2026 Aug 23, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 DLL preloading vulnerability in versions 2017, 2018, 2019, and 2020 of Autodesk Advanced Steel, Civil 3D, AutoCAD, AutoCAD LT, AutoCAD Architecture, AutoCAD Electrical, AutoCAD Map 3D, AutoCAD Mechanical, AutoCAD MEP, Au...Show more |
DLL preloading vulnerability in Autodesk Design Review versions 2011, 2012, 2013, and 2018. An attacker may trick a user into opening a malicious DWF file that may leverage a DLL preloading vulnerability, which may resul...Show more |