Weaknesses of type CWE-427

897 results

Caminho de busca ou elemento não controlado

A aplicação procura por bibliotecas, configurações ou outros recursos em diretórios sem validar adequadamente quais caminhos ela está usando, permitindo que um atacante injete uma versão maliciosa em um local que será encontrado primeiro. Isso acontece porque a ordem ou composição do caminho de busca não é explicitamente controlada.

Example

Um programa Java com classpath que inclui o diretório atual (.) antes de caminhos do sistema; um atacante coloca uma classe maliciosa no diretório de trabalho e ela é carregada em vez da legítima. Ou um script que procura por um arquivo de configuração em múltiplas pastas sem especificar o caminho absoluto, sendo enganado por um arquivo plantado em /tmp.

How to mitigate

Use caminhos absolutos explícitos em vez de relativos; remova diretórios inseguros (como o atual) do caminho de busca; valide a origem e integridade de recursos carregados (checksums, assinaturas); implemente listas de permitidos para diretórios confiáveis.

CVE-2024-28099HIGHVT STUDIO Ver.8.32 and earlier contains an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries. As aEPSS 0.2%CVE-2024-9495HIGHUncontrolled search path can lead to DLL hijacking in CP210x VCP Windows installerEPSS 0.2%CVE-2025-31931MEDIUMUncontrolled search path for the Instrumentation and Tracing Technology API (ITT API) software before version 3.25.4 within Ring 3: User AppEPSS 0.2%CVE-2024-28131HIGHEasyRange Ver 1.41 contains an issue with the executable file search path when displaying an extracted file on Explorer, which may lead to lEPSS 0.2%CVE-2026-56795HIGHDell Server Update Utility, versions prior to 26.07.01, contains an Uncontrolled Search Path Element vulnerability. A low privileged attackeEPSS 0.2%CVE-2024-29734HIGHUncontrolled search path element issue exists in SonicDICOM Media Viewer 2.3.2 and earlier, which may lead to insecurely loading Dynamic LinEPSS 0.2%CVE-2026-26050HIGHThe installer for ジョブログ集計/分析ソフトウェア RICOHジョブログ集計ツール versions prior to Ver.1.3.7 contains an issue with the DLL search path, which may lead toEPSS 0.2%CVE-2022-34755MEDIUM A CWE-427 - Uncontrolled Search Path Element vulnerability exists that could allow an attacker with a local privileged account to place a sEPSS 0.2%CVE-2024-9494HIGHUncontrolled search path can lead to DLL hijacking in CP210 VCP Win 2k installerEPSS 0.2%CVE-2026-4962HIGHUltraVNC Service version.dll uncontrolled search pathEPSS 0.2%CVE-2024-33578HIGHA DLL hijack vulnerability was reported in Lenovo Leyun that could allow a local attacker to execute code with elevated privileges.EPSS 0.2%CVE-2024-21774MEDIUMUncontrolled search path in some Intel(R) Processor Identification Utility software before versions 6.10.34.1129, 7.1.6 may allow an authentEPSS 0.2%CVE-2022-34396HIGH Dell OpenManage Server Administrator (OMSA) version 10.3.0.0 and earlier contains a DLL Injection Vulnerability. A local low privileged autEPSS 0.2%CVE-2022-32498MEDIUMDell EMC PowerStore, Versions prior to v3.0.0.0 contain a DLL Hijacking vulnerability in PSTCLI. A local attacker can potentially exploit thEPSS 0.2%CVE-2024-47006MEDIUMUncontrolled search path for the Intel(R) RealSense D400 Series Universal Windows Platform (UWP) Driver for Windows(R) 10 all versions may aEPSS 0.2%CVE-2026-30478HIGHA Dynamic-link Library Injection vulnerability in GatewayGeo MapServer for Windows version 5 allows attackers to escalate privileges via a cEPSS 0.2%CVE-2024-12530HIGHInsecure Dynamic-Link Library (DLL) Load vulnerabilityEPSS 0.2%CVE-2026-5271MEDIUMPossible to hijack modules in current working directoryEPSS 0.2%CVE-2023-25779MEDIUMUncontrolled search path element in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user EPSS 0.2%CVE-2025-30167HIGHJupyter Core on Windows Has Uncontrolled Search Path Element Local Privilege Escalation VulnerabilityEPSS 0.2%