Weaknesses of type CWE-427

897 results

Caminho de busca ou elemento não controlado

A aplicação procura por bibliotecas, configurações ou outros recursos em diretórios sem validar adequadamente quais caminhos ela está usando, permitindo que um atacante injete uma versão maliciosa em um local que será encontrado primeiro. Isso acontece porque a ordem ou composição do caminho de busca não é explicitamente controlada.

Example

Um programa Java com classpath que inclui o diretório atual (.) antes de caminhos do sistema; um atacante coloca uma classe maliciosa no diretório de trabalho e ela é carregada em vez da legítima. Ou um script que procura por um arquivo de configuração em múltiplas pastas sem especificar o caminho absoluto, sendo enganado por um arquivo plantado em /tmp.

How to mitigate

Use caminhos absolutos explícitos em vez de relativos; remova diretórios inseguros (como o atual) do caminho de busca; valide a origem e integridade de recursos carregados (checksums, assinaturas); implemente listas de permitidos para diretórios confiáveis.

CVE-2021-22775—A CWE-427: Uncontrolled Search Path Element vulnerability exists in GP-Pro EX,V4.09.250 and prior, that could cause local code execution witEPSS 0.3%CVE-2024-7326HIGHIObit DualSafe Password Manager BPL RTL120.BPL uncontrolled search pathEPSS 0.3%CVE-2022-23449—A vulnerability has been identified in SIMATIC Energy Manager Basic (All versions < V7.3 Update 1), SIMATIC Energy Manager PRO (All versionsEPSS 0.3%CVE-2020-6785HIGHUncontrolled Search Path Element in Bosch BVMS and BVMS ViewerEPSS 0.3%CVE-2022-34235HIGHAdobe Premiere Elements Uncontrolled Search Path Element Privilege EscalationEPSS 0.3%CVE-2021-1536MEDIUMCisco Webex Meetings, Webex Network Recording Player, and Webex Teams DLL Injection VulnerabilityEPSS 0.3%CVE-2025-27237HIGHDLL injection in Zabbix Agent and Agent 2 via OpenSSL configurationEPSS 0.3%CVE-2026-22619HIGHEaton Intelligent Power Protector (IPP) is affected by insecure library loading in its executable, which could lead to arbitrary code executEPSS 0.3%CVE-2021-36631MEDIUMUntrusted search path vulnerability in Baidunetdisk Version 7.4.3 and earlier allows an attacker to gain privileges via a Trojan horse DLL iEPSS 0.3%CVE-2025-4525HIGHDiscord WINSTA.dll uncontrolled search pathEPSS 0.3%CVE-2019-3750MEDIUMDell Command Update versions prior to 3.1 contain an Arbitrary File Deletion Vulnerability. A local authenticated malicious user with low prEPSS 0.3%CVE-2019-3749MEDIUMDell Command Update versions prior to 3.1 contain an Arbitrary File Deletion Vulnerability. A local authenticated malicious user with low prEPSS 0.3%CVE-2021-4007HIGHRapid7 Insight Agent Privilege EscalationEPSS 0.3%CVE-2021-1593HIGHCisco Packet Tracer for Windows DLL Injection VulnerabilityEPSS 0.3%CVE-2023-4632HIGHAn uncontrolled search path vulnerability was reported in Lenovo System Update that could allow an attacker with local access to execute codEPSS 0.3%CVE-2022-22528—SAP Adaptive Server Enterprise (ASE) - version 16.0, installation makes an entry in the system PATH environment variable in Windows platformEPSS 0.3%CVE-2022-22996HIGHSanDisk Professional G-RAID 4/8 Software Utility, Privilege EscalationEPSS 0.3%CVE-2022-48077HIGHGenymotion Desktop v3.3.2 was discovered to contain a DLL hijacking vulnerability that allows attackers to escalate privileges and execute aEPSS 0.3%CVE-2023-22947HIGHInsecure folder permissions in the Windows installation path of Shibboleth Service Provider (SP) before 3.4.1 allow an unprivileged local atEPSS 0.3%CVE-2025-5129HIGHSangfor 零信任访问控制系统 aTrust MSASN1.dll uncontrolled search pathEPSS 0.3%