Weaknesses of type CWE-427

896 results

Caminho de busca ou elemento não controlado

A aplicação procura por bibliotecas, configurações ou outros recursos em diretórios sem validar adequadamente quais caminhos ela está usando, permitindo que um atacante injete uma versão maliciosa em um local que será encontrado primeiro. Isso acontece porque a ordem ou composição do caminho de busca não é explicitamente controlada.

Example

Um programa Java com classpath que inclui o diretório atual (.) antes de caminhos do sistema; um atacante coloca uma classe maliciosa no diretório de trabalho e ela é carregada em vez da legítima. Ou um script que procura por um arquivo de configuração em múltiplas pastas sem especificar o caminho absoluto, sendo enganado por um arquivo plantado em /tmp.

How to mitigate

Use caminhos absolutos explícitos em vez de relativos; remova diretórios inseguros (como o atual) do caminho de busca; valide a origem e integridade de recursos carregados (checksums, assinaturas); implemente listas de permitidos para diretórios confiáveis.

CVE-2024-11859HIGHDLL Search Order Hijacking in ESET products for WindowsEPSS 2.1%CVE-2021-3840HIGHA dependency confusion vulnerability was reported in the Antilles open-source software prior to version 1.0.1 that could allow for remote coEPSS 2.0%CVE-2021-21011HIGHUncontrolled Search Path Element in Adobe Captivate 2019EPSS 2.0%CVE-2017-14010—In SpiderControl MicroBrowser Windows XP, Vista 7, 8 and 10, Versions 1.6.30.144 and prior, an uncontrolled search path element vulnerabilitEPSS 2.0%CVE-2021-35982HIGHAdobe Reader DC Windows Installer Uncontrolled Search Path element could lead to Arbitrary Code ExecutionEPSS 1.8%CVE-2022-32223—Node.js is vulnerable to Hijack Execution Flow: DLL Hijacking under certain conditions on Windows platforms.This vulnerability can be exploiEPSS 1.8%CVE-2020-10616—Opto 22 SoftPAC Project Version 9.6 and prior. SoftPAC does not specify the path of multiple imported .dll files. Therefore, an attacker canEPSS 1.7%CVE-2023-25143CRITICALAn uncontrolled search path element vulnerability in the Trend Micro Apex One Server installer could allow an attacker to achieve a remote cEPSS 1.7%CVE-2018-14797—Emerson DeltaV DCS versions 11.3.1, 12.3.1, 13.3.0, 13.3.1, R5 allow a specially crafted DLL file to be placed in the search path and loadedEPSS 1.7%CVE-2021-21070MEDIUMPrivilege Escalation Vulnerability in Adobe RoboHelpEPSS 1.6%CVE-2022-43310HIGHAn Uncontrolled Search Path Element in Foxit Software released Foxit Reader v11.2.118.51569 allows attackers to escalate privileges when seaEPSS 1.6%CVE-2017-5175—Advantech WebAccess 8.1 and earlier contains a DLL hijacking vulnerability which may allow an attacker to run a malicious DLL file within thEPSS 1.6%CVE-2019-6534—The uncontrolled search path element vulnerability in Gemalto Sentinel UltraPro Client Library ux32w.dll Versions 1.3.0, 1.3.1, and 1.3.2 enEPSS 1.5%CVE-2022-24767HIGHGitHub: Git for Windows' uninstaller vulnerable to DLL hijacking when run under the SYSTEM user account.EPSS 1.5%CVE-2017-5170—An Uncontrolled Search Path Element issue was discovered in Moxa SoftNVR-IA Live Viewer, Version 3.30.3122 and prior versions. An uncontrollEPSS 1.5%CVE-2018-13806—A vulnerability has been identified in SIEMENS TD Keypad Designer (All versions). A DLL hijacking vulnerability exists in all versions of SIEPSS 1.4%CVE-2022-2333HIGHHoneywell SoftMaster Uncontrolled Search Path ElementEPSS 1.4%CVE-2017-6051—An Uncontrolled Search Path Element issue was discovered in BLF-Tech LLC VisualView HMI Version 9.9.14.0 and prior. The uncontrolled search EPSS 1.4%CVE-2017-6033—A DLL Hijacking issue was discovered in Schneider Electric Interactive Graphical SCADA System (IGSS) Software, Version 12 and previous versiEPSS 1.3%CVE-2022-34825CRITICALUncontrolled Search Path Element in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLUSTERPRO X 5.0EPSS 1.3%