Weaknesses of type CWE-427

897 results

Caminho de busca ou elemento não controlado

A aplicação procura por bibliotecas, configurações ou outros recursos em diretórios sem validar adequadamente quais caminhos ela está usando, permitindo que um atacante injete uma versão maliciosa em um local que será encontrado primeiro. Isso acontece porque a ordem ou composição do caminho de busca não é explicitamente controlada.

Example

Um programa Java com classpath que inclui o diretório atual (.) antes de caminhos do sistema; um atacante coloca uma classe maliciosa no diretório de trabalho e ela é carregada em vez da legítima. Ou um script que procura por um arquivo de configuração em múltiplas pastas sem especificar o caminho absoluto, sendo enganado por um arquivo plantado em /tmp.

How to mitigate

Use caminhos absolutos explícitos em vez de relativos; remova diretórios inseguros (como o atual) do caminho de busca; valide a origem e integridade de recursos carregados (checksums, assinaturas); implemente listas de permitidos para diretórios confiáveis.

CVE-2024-39365MEDIUMUncontrolled search path for the FPGA Support Package for the Intel(R) oneAPI DPC++/C++ Compiler software for Windows before version 2024.2 EPSS 0.2%CVE-2023-29504MEDIUMUncontrolled search path element in some Intel(R) RealSense(TM) Dynamic Calibration software before version 2.13.1.0 may allow an authenticaEPSS 0.2%CVE-2024-32857HIGHDell Peripheral Manager, versions prior to 1.7.6, contain an uncontrolled search path element vulnerability. An attacker could potentially EPSS 0.2%CVE-2024-39813MEDIUMUncontrolled search path for some EPCT software before version 1.42.8.0 may allow an authenticated user to potentially enable escalation of EPSS 0.2%CVE-2025-11761HIGHHP Client Management Script Library – Security UpdateEPSS 0.2%CVE-2024-21830MEDIUMUncontrolled search path in some Intel(R) VPL software before version 2023.4.0 may allow an authenticated user to potentially enable escalatEPSS 0.2%CVE-2024-37142HIGHDell Peripheral Manager, versions prior to 1.7.6, contain an uncontrolled search path element vulnerability. An attacker could potentially eEPSS 0.2%CVE-2024-39284MEDIUMUncontrolled search path for some Intel(R) Advisor software before version 2024.2 may allow an authenticated user to potentially enable escaEPSS 0.2%CVE-2024-36291MEDIUMUncontrolled search path for some Intel(R) Chipset Software Installation Utility before version 10.1.19867.8574 may allow an authenticated uEPSS 0.2%CVE-2024-24852MEDIUMUncontrolled search path in some Intel(R) Ethernet Adapter Complete Driver Pack install before versions 29.1 may allow an authenticated userEPSS 0.2%CVE-2024-36283MEDIUMUncontrolled search path for the Intel(R) Thread Director Visualizer software before version 1.0.1 may allow an authenticated user to potentEPSS 0.2%CVE-2024-39372MEDIUMUncontrolled search path for the Intel(R) XTU software for Windows before version 7.14.2.14 may allow an authenticated user to potentially eEPSS 0.2%CVE-2024-32938MEDIUMUncontrolled search path for some Intel(R) MPI Library for Windows software before version 2021.13 may allow an authenticated user to potentEPSS 0.2%CVE-2023-51711HIGHAn issue was discovered in Regify Regipay Client for Windows version 4.5.1.0 allows DLL hijacking: a user can trigger the execution of arbitEPSS 0.2%CVE-2024-36280MEDIUMUncontrolled search path for some Intel(R) High Level Synthesis Compiler software before version 24.2 may allow an authenticated user to potEPSS 0.2%CVE-2025-48506HIGHUncontrolled search paths in Vitis™ Unified installation path on local Windows machines could allow DLL injection into these install paths, EPSS 0.2%CVE-2021-31853HIGHMDE DLL Search Order Hijacking vulnerabilityEPSS 0.2%CVE-2023-43751MEDIUMUncontrolled search path in Intel(R) Graphics Command Center Service bundled in some Intel(R) Graphics Windows DCH driver software before veEPSS 0.2%CVE-2026-92838HIGHGeoVision GV-Remote E-Map dll hijacking vulnerabilityEPSS 0.2%CVE-2023-22283MEDIUMBIG-IP Edge Client for Windows vulnerabilityEPSS 0.2%