CWE-427
1,189 CVEs • Abstraction: Base
Uncontrolled Search Path Element
The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.
CVEs (1,189)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
ExifTool 8.32 allows local users to gain privileges by creating a %TEMP%\par-%username%\cache-exiftool-8.32 folder with a victim's username, and then copying a Trojan horse ws32_32.dll file into this new folder, aka DLL...Show more |
1Cisco 1Advanced Malware Protection For Endpoints Nov 21, 2024 Nov 13, 2018 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 A vulnerability in the DLL loading component of Cisco Advanced Malware Protection (AMP) for Endpoints on Windows could allow an authenticated, local attacker to disable system scanning services or take other actions to p...Show more |
1Schneider Electric 1Software Update Utility Jun 17, 2026 Nov 2, 2018 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 A DLL hijacking vulnerability exists in Schneider Electric Software Update (SESU), all versions prior to V2.2.0, which could allow an attacker to execute arbitrary code on the targeted system when placing a specific DLL...Show more |
1Fujielectric 1Energy Savings Estimator Nov 21, 2024 Oct 24, 2018 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 An uncontrolled search path element (DLL Hijacking) vulnerability has been identified in Fuji Electric Energy Savings Estimator versions V.1.0.2.0 and prior. Exploitation of this vulnerability could give an attacker acce...Show more |
1Adobe 1Technical Communications Suite Nov 21, 2024 Oct 17, 2018 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Adobe Technical Communications Suite versions 1.0.5.1 and below have an insecure library loading (dll hijacking) vulnerability. Successful exploitation could lead to privilege escalation. |
Dell Digital Delivery versions prior to 3.5.1 contain a DLL Injection Vulnerability. A local authenticated malicious user with advance knowledge of the application workflow could potentially load and execute a malicious...Show more |
A DLL injection vulnerability in the Intel IoT Developers Kit 4.0 installer may allow an authenticated user to potentially escalate privileges using file modification via local access. |
1Intel 1Data Migration Software Nov 21, 2024 Sep 12, 2018 N/A· v4 5.3 MEDIUM· v3 4.6 MEDIUM· v2 DLL injection vulnerability in software installer for Intel Data Center Migration Center Software v3.1 and before may allow an authenticated user to potentially execute code using default directory permissions via local...Show more |
A vulnerability has been identified in SIEMENS TD Keypad Designer (All versions). A DLL hijacking vulnerability exists in all versions of SIEMENS TD Keypad Designer which could allow an attacker to execute code with the...Show more |
Emerson DeltaV DCS versions 11.3.1, 12.3.1, 13.3.0, 13.3.1, R5 allow a specially crafted DLL file to be placed in the search path and loaded as an internal and valid DLL, which may allow arbitrary code execution. |
1Symantec 2Norton Power Eraser SymdiagNov 21, 2024 Aug 22, 2018 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Norton Power Eraser (prior to 5.3.0.24) and SymDiag (prior to 2.1.242) may be susceptible to a DLL Preloading vulnerability, which is a type of issue that can occur when an application looks to call a DLL for execution a...Show more |
Norton Utilities (prior to 16.0.3.44) may be susceptible to a DLL Preloading vulnerability, which is a type of issue that can occur when an application looks to call a DLL for execution and an attacker provides a malicio...Show more |
1Quickheal 3Antivirus Pro Internet SecurityTotal SecurityJun 17, 2026 Jul 25, 2018 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Quick Heal Total Security 64 bit 17.00 (QHTS64.exe), (QHTSFT64.exe) - Version 10.0.1.38; Quick Heal Total Security 32 bit 17.00 (QHTS32.exe), (QHTSFT32.exe) - Version 10.0.1.38; Quick Heal Internet Security 64 bit 17.00...Show more |
Adobe Connect versions 9.7.5 and earlier have an Insecure Library Loading vulnerability. Successful exploitation could lead to privilege escalation. |
2Emc Rsa3Rsa Identity Governance And Lifecycle Rsa Identity Management And GovernanceRsa Via Lifecycle And GovernanceNov 21, 2024 Jul 11, 2018 N/A· v4 7.3 HIGH· v3 6.9 MEDIUM· v2 RSA Identity Governance and Lifecycle, RSA Via Lifecycle and Governance, and RSA IMG releases have an uncontrolled search vulnerability. The installation scripts set an environment variable in an unintended manner. A loc...Show more |
The Rust Programming Language rustdoc version Between 0.8 and 1.27.0 contains a CWE-427: Uncontrolled Search Path Element vulnerability in rustdoc plugins that can result in local code execution as a different user. This...Show more |
The "pingsender" executable used by the Firefox Health Report dynamically loads a system copy of libcurl, which an attacker could replace. This allows for privilege escalation as the replaced libcurl code will run with F...Show more |
Adobe ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions have an exploitable Insecure Library Loading vulnerability. Successful exploitation could lead to local privilege escalation. |
1Intel 18Dual Band Wireless Ac 3160 Dual Band Wireless Ac 3165Dual Band Wireless Ac 3168+15 moreNov 21, 2024 May 10, 2018 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 DLL injection vulnerability in the installation executables (Autorun.exe and Setup.exe) for Intel's wireless drivers and related software in Intel Dual Band Wireless-AC, Tri-Band Wireless-AC and Wireless-AC family of pro...Show more |
Advantech WebAccess 8.1 and earlier contains a DLL hijacking vulnerability which may allow an attacker to run a malicious DLL file within the search path resulting in execution of arbitrary code. |