CWE-427
1,189 CVEs • Abstraction: Base
Uncontrolled Search Path Element
The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.
CVEs (1,189)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Trendmicro 5Antivirus + Security 2019 Internet Security 2019Maximum Security 2019+2 moreJun 17, 2026 Aug 21, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 A DLL hijacking vulnerability exists in the Trend Micro Security's 2019 consumer family of products (v15) Folder Shield component and the standalone Trend Micro Ransom Buster (1.0) tool in which, if exploited, would allo...Show more |
A DLL hijacking vulnerability exists in Trend Micro Password Manager 5.0 in which, if exploited, would allow an attacker to load an arbitrary unsigned DLL into the signed service's process. This process is very similar,...Show more |
A DLL hijacking vulnerability exists in Trend Micro Password Manager 5.0 in which, if exploited, would allow an attacker to load an arbitrary unsigned DLL into the signed service's process. This process is very similar,...Show more |
The Rapid7 InsightAppSec broker suffers from a DLL injection vulnerability in the 'prunsrv.exe' component of the product. If exploited, a local user of the system (who must already be authenticated to the operating syste...Show more |
Adobe After Effects versions 16 and earlier have an insecure library loading (dll hijacking) vulnerability. Successful exploitation could lead to arbitrary code execution. |
Adobe Prelude CC versions 8.1 and earlier have an insecure library loading (dll hijacking) vulnerability. Successful exploitation could lead to arbitrary code execution. |
Adobe Premiere Pro CC versions 13.1.2 and earlier have an insecure library loading (dll hijacking) vulnerability. Successful exploitation could lead to arbitrary code execution. |
Adobe Character Animator versions 2.1 and earlier have an insecure library loading (dll hijacking) vulnerability. Successful exploitation could lead to arbitrary code execution. |
Multiple binaries in IBM SDK, Java Technology Edition 7, 7R, and 8 on the AIX platform use insecure absolute RPATHs, which may facilitate code injection and privilege elevation by local users. IBM X-Force ID: 163984. |
1Bitdefender 4Antivirus Plus Endpoint Security ToolInternet Security+1 moreJun 17, 2026 Jul 30, 2019 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 An issue was discovered in Bitdefender products for Windows (Bitdefender Endpoint Security Tool versions prior to 6.6.8.115; and Bitdefender Antivirus Plus, Bitdefender Internet Security, and Bitdefender Total Security v...Show more |
Akeo Consulting Rufus 3.0 and earlier is affected by: DLL search order hijacking. The impact is: Arbitrary code execution WITH escalation of privilege. The component is: Executable installers, portable executables (ALL e...Show more |
Adobe Dreamweaver direct download installer versions 19.0 and below, 18.0 and below have an Insecure Library Loading (DLL hijacking) vulnerability. Successful exploitation could lead to Privilege Escalation in the contex...Show more |
A CWE-427: Uncontrolled Search Path Element vulnerability exists in ProClima (all versions prior to version 8.0.0) which could allow a malicious DLL file, with the same name of any resident DLLs inside the software insta...Show more |
Rapid7 Insight Agent, version 2.6.3 and prior, suffers from a local privilege escalation due to an uncontrolled DLL search path. Specifically, when Insight Agent 2.6.3 and prior starts, the Python interpreter attempts to...Show more |
1Londontrustmedia 1Private Internet Access Vpn Client Jun 17, 2026 Jul 11, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v82 for Linux could allow an authenticated, local attacker to run arbitrary code with elevated privileges. The root_runner.64 binary is s...Show more |
A vulnerability in the loading mechanism of specific dynamic link libraries in Cisco Jabber for Windows could allow an authenticated, local attacker to perform a DLL preloading attack. To exploit this vulnerability, the...Show more |
3Haxx NetappOracle9Curl Enterprise Manager Ops CenterHttp Server+6 moreJun 17, 2026 Jul 2, 2019 N/A· v4 7.8 HIGH· v3 4.4 MEDIUM· v2 A non-privileged user or program can put code and a config file in a known non-privileged path (under C:/usr/local/) that will make curl <= 7.65.1 automatically run the code (as an openssl "engine") on invocation. If tha...Show more |
2Dell Pc Doctor3Supportassist For Business Pcs Supportassist For Home PcsToolboxJun 17, 2026 Jun 25, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 PC-Doctor Toolbox before 7.3 has an Uncontrolled Search Path Element. |
1Londontrustmedia 1Private Internet Access Jun 17, 2026 Jun 21, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client 1.0.2 (build 02363) for Windows could allow an authenticated, local attacker to run arbitrary code with elevated privileges. On startup,...Show more |
1Zohocorp 18Manageengine Analytics Plus Manageengine Browser Security PlusManageengine Desktop Central+15 moreJun 17, 2026 Jun 18, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Multiple Zoho ManageEngine products suffer from local privilege escalation due to improper permissions for the %SYSTEMDRIVE%\ManageEngine directory and its sub-folders. Moreover, the services associated with said product...Show more |