Weaknesses of type CWE-427

897 results

Caminho de busca ou elemento não controlado

A aplicação procura por bibliotecas, configurações ou outros recursos em diretórios sem validar adequadamente quais caminhos ela está usando, permitindo que um atacante injete uma versão maliciosa em um local que será encontrado primeiro. Isso acontece porque a ordem ou composição do caminho de busca não é explicitamente controlada.

Example

Um programa Java com classpath que inclui o diretório atual (.) antes de caminhos do sistema; um atacante coloca uma classe maliciosa no diretório de trabalho e ela é carregada em vez da legítima. Ou um script que procura por um arquivo de configuração em múltiplas pastas sem especificar o caminho absoluto, sendo enganado por um arquivo plantado em /tmp.

How to mitigate

Use caminhos absolutos explícitos em vez de relativos; remova diretórios inseguros (como o atual) do caminho de busca; valide a origem e integridade de recursos carregados (checksums, assinaturas); implemente listas de permitidos para diretórios confiáveis.

CVE-2023-24591MEDIUMUncontrolled search path in some Intel(R) Binary Configuration Tool software before version 3.4.4 may allow an authenticated user to potentiEPSS 0.2%CVE-2023-36493MEDIUMUncontrolled search path in some Intel(R) SDK for OpenCL(TM) Applications software may allow an authenticated user to potentially enable escEPSS 0.2%CVE-2023-35769MEDIUMUncontrolled search path in some Intel(R) CIP software before version 2.4.10577 may allow an authenticated user to potentially enable escalaEPSS 0.2%CVE-2026-3775HIGHFoxit PDF Editor/Reader Update Service Uncontrolled Search Path Element Local Privilege Escalation VulnerabilityEPSS 0.2%CVE-2025-13051CRITICALWindows service used an uncontrolled search path element will cause unauthorized code execution with localsystem privilegesEPSS 0.2%CVE-2025-41670HIGHUntrusted Search PathEPSS 0.2%CVE-2022-36840MEDIUMDLL hijacking vulnerability in Samsung Update Setup prior to version 2.2.9.50 allows attackers to execute arbitrary code.EPSS 0.2%CVE-2023-28759HIGHAn issue was discovered in Veritas NetBackup before 10.0 on Windows. A vulnerability in the way the client validates the path to a DLL priorEPSS 0.2%CVE-2023-39932MEDIUMUncontrolled search path in the Intel(R) SUR for Gameplay Software before version 2.0.1901 may allow a privillaged user to potentially enablEPSS 0.2%CVE-2026-38972HIGHNotepad3 through 6.25.822.1 contains a DLL search-order hijacking vulnerability in the About-dialog code path in src/Notepad3.c. The applicaEPSS 0.2%CVE-2024-21831MEDIUMUncontrolled search path in some Intel(R) Processor Diagnostic Tool software before version 4.1.9.41 may allow an authenticated user to poteEPSS 0.2%CVE-2024-53588HIGHA DLL hijacking vulnerability in iTop VPN v16.0 allows attackers to execute arbitrary code via placing a crafted DLL file into the path \ProEPSS 0.2%CVE-2025-64772HIGHThe installer of INZONE Hub 1.0.10.3 to 1.0.17.0 contains an issue with the DLL search path, which may lead to insecurely loading Dynamic LiEPSS 0.2%CVE-2024-47942HIGHA vulnerability has been identified in Solid Edge SE2024 (All versions < V224.0 Update 9). The affected applications suffer from a DLL hijacEPSS 0.2%CVE-2024-28099HIGHVT STUDIO Ver.8.32 and earlier contains an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries. As aEPSS 0.2%CVE-2026-25676HIGHThe installer of M-Track Duo HD version 1.0.0 contains an issue with the DLL search path, which may lead to insecurely loading Dynamic Link EPSS 0.2%CVE-2026-26050HIGHThe installer for ジョブログ集計/分析ソフトウェア RICOHジョブログ集計ツール versions prior to Ver.1.3.7 contains an issue with the DLL search path, which may lead toEPSS 0.2%CVE-2024-29734HIGHUncontrolled search path element issue exists in SonicDICOM Media Viewer 2.3.2 and earlier, which may lead to insecurely loading Dynamic LinEPSS 0.2%CVE-2020-8895HIGHDLL Hijacking in Google Earth Pro Windows installerEPSS 0.2%CVE-2024-9494HIGHUncontrolled search path can lead to DLL hijacking in CP210 VCP Win 2k installerEPSS 0.2%