Weaknesses of type CWE-426

322 results

Caminho de busca não confiável

Ocorre quando a aplicação busca por bibliotecas, executáveis ou arquivos em diretórios cuja ordem ou conteúdo pode ser controlado por um atacante. Se um diretório não confiável vem antes de um diretório legítimo no PATH (ou em lógica de busca customizada), o atacante injeta um arquivo malicioso com o mesmo nome para ser carregado no lugar do original.

Example

Um software Windows busca 'config.dll' primeiro no diretório atual antes de procurar em System32. Um atacante coloca uma DLL maliciosa com esse nome na pasta de trabalho; quando o software executa, carrega a versão maliciosa e compromete a máquina.

How to mitigate

Especifique sempre caminhos absolutos completos ao carregar bibliotecas e executáveis, evitando buscas dinâmicas em PATH. Em Unix/Linux, remova ou coloque o diretório atual (.) ao final do PATH, nunca no início; no Windows, configure DLL search order e use mecanismos como SetDllDirectory para restringir onde as DLLs são procuradas.

CVE-2023-27763HIGHAn issue found in Wondershare Technology Co.,Ltd MobileTrans v.4.0.2 allows a remote attacker to execute arbitrary commands via the mobiletrEPSS 0.4%CVE-2023-27771HIGHAn issue found in Wondershare Technology Co.,Ltd Creative Centerr v.1.0.8 allows a remote attacker to execute arbitrary commands via the wonEPSS 0.4%CVE-2023-27760HIGHAn issue found in Wondershare Technology Co, Ltd Filmora v.12.0.9 allows a remote attacker to execute arbitrary commands via the filmora_setEPSS 0.4%CVE-2023-27761HIGHAn issue found in Wondershare Technology Co., Ltd UniConverter v.14.0.0 allows a remote attacker to execute arbitrary commands via the unicoEPSS 0.4%CVE-2023-27769HIGHAn issue found in Wondershare Technology Co.,Ltd PDF Reader v.1.0.1 allows a remote attacker to execute arbitrary commands via the pdfreaderEPSS 0.4%CVE-2023-27768HIGHAn issue found in Wondershare Technology Co.,Ltd PDFelement v9.1.1 allows a remote attacker to execute arbitrary commands via the pdfelementEPSS 0.4%CVE-2026-48565HIGHWindows Narrator Braille Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2020-7279MEDIUMDLL search order hijacking in Host IPSEPSS 0.4%CVE-2026-23888MEDIUMpnpm: Binary ZIP extraction allows arbitrary file write via path traversal (Zip Slip)EPSS 0.4%CVE-2020-7476—A CWE-426: Untrusted Search Path vulnerability exists in ZigBee Installation Kit (Versions prior to 1.0.1), which could cause execution of mEPSS 0.4%CVE-2024-55503LOWAn issue in termius before v.9.9.0 allows a local attacker to execute arbitrary code via a crafted script to the DYLD_INSERT_LIBRARIES compoEPSS 0.4%CVE-2020-8317HIGHA DLL search path vulnerability was reported in Lenovo Drivers Management prior to version 2.7.1128.1046 that could allow an authenticated uEPSS 0.4%CVE-2026-16674HIGHIBM i is Affected By Multiple Vulnerabilities in WebSphere Application Server LibertyEPSS 0.4%CVE-2020-6654HIGHDLL HijackingEPSS 0.4%CVE-2025-60718HIGHWindows Administrator Protection Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2019-25257HIGHLogicalDOC Enterprise 7.7.4 Authenticated Command Execution via Binary Path ManipulationEPSS 0.4%CVE-2021-25698—The OpenSSL component of the Teradici PCoIP Standard Agent prior to version 21.07.0 was compiled without the no-autoload-config option, whicEPSS 0.4%CVE-2021-25699—The OpenSSL component of the Teradici PCoIP Software Client prior to version 21.07.0 was compiled without the no-autoload-config option, whiEPSS 0.4%CVE-2022-31012HIGHGit for Windows' installer can be tricked into executing an untrusted binaryEPSS 0.4%CVE-2021-28246HIGHCA eHealth Performance Manager through 6.3.2.12 is affected by Privilege Escalation via a Dynamically Linked Shared Object Library. A regulaEPSS 0.4%