CWE-427
1,189 CVEs • Abstraction: Base
Uncontrolled Search Path Element
The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.
CVEs (1,189)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Rockwellautomation 2Drivetools Add On Profiles Drivetools SpJun 17, 2026 Mar 18, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Rockwell Automation DriveTools SP v5.13 and below and Drives AOP v4.12 and below both contain a vulnerability that a local attacker with limited privileges may be able to exploit resulting in privilege escalation and com...Show more |
1Utimaco 6Block Safe Firmware Cryptoserver Cp5 FirmwareCryptoserver Cp5 Vs Nfd Firmware+3 moreJun 17, 2026 Mar 18, 2021 N/A· v4 7.8 HIGH· v3 4.4 MEDIUM· v2 Multiple files and folders in Utimaco SecurityServer 4.20.0.4 and 4.31.1.0. are installed with Read/Write permissions for authenticated users, which allows for binaries to be manipulated by non-administrator users. Addit...Show more |
1Dell 3Supportassist Client Promanage Supportassist For Business PcsSupportassist For Home PcsJun 17, 2026 Mar 12, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Dell SupportAssist Client for Consumer PCs versions 3.7.x, 3.6.x, 3.4.x, 3.3.x, Dell SupportAssist Client for Business PCs versions 2.0.x, 2.1.x, 2.2.x, and Dell SupportAssist Client ProManage 1.x contain a DLL injection...Show more |
Untrusted search path vulnerability in Installer of MagicConnect Client program distributed before 2021 March 1 allows an attacker to gain privileges and via a Trojan horse DLL in an unspecified directory and to execute...Show more |
1Owncloud 1Owncloud Desktop Client Jun 17, 2026 Feb 26, 2021 N/A· v4 7.8 HIGH· v3 4.4 MEDIUM· v2 ownCloud owncloud/client before 2.7 allows DLL Injection. The desktop client loaded development plugins from certain directories when they were present. |
1Cisco 1Anyconnect Secure Mobility Client Jun 17, 2026 Feb 17, 2021 N/A· v4 7.8 HIGH· v3 6.9 MEDIUM· v2 A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack on an affected device...Show more |
1Intel 1Trace Analyzer And Collector Jun 17, 2026 Feb 17, 2021 N/A· v4 7.8 HIGH· v3 4.4 MEDIUM· v2 Improper conditions check in the Intel(R) FPGA OPAE Driver for Linux before kernel version 4.17 may allow an authenticated user to potentially enable escalation of privilege via local access. |
1Intel 1Optane Dc Persistent Memory Module Management Jun 17, 2026 Feb 17, 2021 N/A· v4 7.3 HIGH· v3 4.4 MEDIUM· v2 Uncontrolled search path in the Intel(R) Optane(TM) DC Persistent Memory installer for Windows* before version 1.00.00.3506 may allow an authenticated user to potentially enable escalation of privilege via local access. |
1Siemens 2Simatic Process Control System Neo Totally Integrated Automation PortalJun 17, 2026 Feb 9, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A vulnerability has been identified in PCS neo (Administration Console) (All versions < V3.1), TIA Portal (V15, V15.1 and V16). Manipulating certain files in specific folders could allow a local attacker to execute code...Show more |
Acronis True Image for Windows prior to 2021 Update 3 allowed local privilege escalation due to a DLL hijacking vulnerability in multiple components, aka an Untrusted Search Path issue. |
1Trendmicro 1Housecall For Home Networks Jun 17, 2026 Jan 27, 2021 N/A· v4 7.8 HIGH· v3 4.4 MEDIUM· v2 A DLL hijacking vulnerability Trend Micro HouseCall for Home Networks version 5.3.1063 and below could allow an attacker to use a malicious DLL to escalate privileges and perform arbitrary code execution. An attacker mus...Show more |
3Fedoraproject GolangNetapp4Cloud Insights Telegraf Agent FedoraGo+1 moreJun 17, 2026 Jan 26, 2021 N/A· v4 7.5 HIGH· v3 5.1 MEDIUM· v2 Go before 1.14.14 and 1.15.x before 1.15.7 on Windows is vulnerable to Command Injection and remote code execution when using the "go get" command to fetch modules that make use of cgo (for example, cgo can execute a gcc...Show more |
1Cisco 2Advanced Malware Protection For Endpoints ImmunetJun 17, 2026 Jan 20, 2021 N/A· v4 7.3 HIGH· v3 6.9 MEDIUM· v2 A vulnerability in the loading mechanism of specific DLLs of Cisco Advanced Malware Protection (AMP) for Endpoints for Windows and Immunet for Windows could allow an authenticated, local attacker to perform a DLL hijacki...Show more |
Adobe Captivate 2019 version 11.5.1.499 (and earlier) is affected by an uncontrolled search path element vulnerability that could lead to privilege escalation. An attacker with permissions to write to the file system cou...Show more |
InCopy version 15.1.1 (and earlier) for Windows is affected by an uncontrolled search path vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requir...Show more |
Adobe Animate version 21.0 (and earlier) is affected by an uncontrolled search path element that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user inter...Show more |
Adobe Illustrator version 25.0 (and earlier) is affected by an uncontrolled search path element that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user i...Show more |
A vulnerability in the loading process of specific DLLs in Cisco Proximity Desktop for Windows could allow an authenticated, local attacker to load a malicious library. To exploit this vulnerability, the attacker must ha...Show more |
1Cisco 1Anyconnect Secure Mobility Client Jun 17, 2026 Jan 13, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A vulnerability in the Network Access Manager and Web Security Agent components of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL injection attack. To ex...Show more |
Untrusted search path vulnerability in the installer of SKYSEA Client View Ver.1.020.05b to Ver.16.001.01g allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. |