Weaknesses of type CWE-427

897 results

Caminho de busca ou elemento não controlado

A aplicação procura por bibliotecas, configurações ou outros recursos em diretórios sem validar adequadamente quais caminhos ela está usando, permitindo que um atacante injete uma versão maliciosa em um local que será encontrado primeiro. Isso acontece porque a ordem ou composição do caminho de busca não é explicitamente controlada.

Example

Um programa Java com classpath que inclui o diretório atual (.) antes de caminhos do sistema; um atacante coloca uma classe maliciosa no diretório de trabalho e ela é carregada em vez da legítima. Ou um script que procura por um arquivo de configuração em múltiplas pastas sem especificar o caminho absoluto, sendo enganado por um arquivo plantado em /tmp.

How to mitigate

Use caminhos absolutos explícitos em vez de relativos; remova diretórios inseguros (como o atual) do caminho de busca; valide a origem e integridade de recursos carregados (checksums, assinaturas); implemente listas de permitidos para diretórios confiáveis.

CVE-2022-1098HIGHDelta Electronics DIAEnergie Uncontrolledly Search Path ElementEPSS 0.2%CVE-2026-50773HIGHAn issue in CGM Germany - CompuGroup Medical CGM ISIS MED 2510.1.0.20 allows a remote attacker to execute arbtirary code via a crafted .dll EPSS 0.2%CVE-2023-45248MEDIUMLocal privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Cloud Agent (WindoEPSS 0.2%CVE-2022-22736HIGHIf Firefox was installed to a world-writable directory, a local privilege escalation could occur when Firefox searched the current directoryEPSS 0.2%CVE-2023-39929MEDIUMUncontrolled search path in some Libva software maintained by Intel(R) before version 2.20.0 may allow an authenticated user to potentially EPSS 0.2%CVE-2022-22139HIGHUncontrolled search path in the Intel(R) XTU software before version 7.3.0.33 may allow an authenticated user to potentially enable escalatiEPSS 0.2%CVE-2022-30696—Local privilege escalation due to a DLL hijacking vulnerabilityEPSS 0.2%CVE-2025-32780HIGHBleachBit for Windows Has DLL Untrusted Path VulnerabilityEPSS 0.2%CVE-2024-8299HIGHMalicious Code Execution Vulnerability in GENESIS64, ICONICS Suite, Hyper Historian, MC Works64, and GENESIS32EPSS 0.2%CVE-2026-49241HIGHAngular: Multiple Remote Code Execution Vulnerabilities in Angular Language Service VS Code ExtensionEPSS 0.2%CVE-2024-9852HIGHMalicious Code Execution Vulnerability in GENESIS64, ICONICS Suite, Hyper Historian, MC Works64, and GENESIS32EPSS 0.2%CVE-2024-9497HIGHUncontrolled search path can lead to DLL hijacking in USBXpress 4 SDK installerEPSS 0.2%CVE-2024-9499HIGHUncontrolled search path can lead to DLL hijacking in USBXpress Win 98SE Dev Kit installerEPSS 0.2%CVE-2021-33101HIGHUncontrolled search path in the Intel(R) GPA software before version 21.2 may allow an authenticated user to potentially enable escalation oEPSS 0.2%CVE-2024-9496HIGHUncontrolled search path can lead to DLL hijacking in USBXpress Dev Kit installerEPSS 0.2%CVE-2024-9046HIGHA DLL hijack vulnerability was reported in Lenovo stARstudio that could allow a local attacker to execute code with elevated privileges.EPSS 0.2%CVE-2021-0169MEDIUMUncontrolled Search Path Element in software for Intel(R) PROSet/Wireless Wi-Fi in Windows 10 and 11 may allow a privileged user to potentiaEPSS 0.2%CVE-2025-43553HIGHSubstance3D - Modeler | Uncontrolled Search Path Element (CWE-427)EPSS 0.2%CVE-2022-0025MEDIUMCortex XDR Agent: An Uncontrolled Search Path Element Leads to Local Privilege Escalation (PE) VulnerabilityEPSS 0.2%CVE-2022-24426HIGHDell Command | Update, Dell Update, and Alienware Update version 4.4.0 contains a Local Privilege Escalation Vulnerability in the Advanced DEPSS 0.2%