Weaknesses of type CWE-427

897 results

Caminho de busca ou elemento não controlado

A aplicação procura por bibliotecas, configurações ou outros recursos em diretórios sem validar adequadamente quais caminhos ela está usando, permitindo que um atacante injete uma versão maliciosa em um local que será encontrado primeiro. Isso acontece porque a ordem ou composição do caminho de busca não é explicitamente controlada.

Example

Um programa Java com classpath que inclui o diretório atual (.) antes de caminhos do sistema; um atacante coloca uma classe maliciosa no diretório de trabalho e ela é carregada em vez da legítima. Ou um script que procura por um arquivo de configuração em múltiplas pastas sem especificar o caminho absoluto, sendo enganado por um arquivo plantado em /tmp.

How to mitigate

Use caminhos absolutos explícitos em vez de relativos; remova diretórios inseguros (como o atual) do caminho de busca; valide a origem e integridade de recursos carregados (checksums, assinaturas); implemente listas de permitidos para diretórios confiáveis.

CVE-2026-24502HIGHDell Command | Intel vPro Out of Band, versions prior to 4.7.0, contain an Uncontrolled Search Path Element vulnerability. A low privileged EPSS 0.2%CVE-2026-50100HIGHMultiple printer drivers provided by Ricoh Company, Ltd. and KONICA MINOLTA JAPAN, INC. contain a privilege escalation vulnerability. If thiEPSS 0.2%CVE-2023-42920HIGHClaris International has fixed a dylib hijacking vulnerability in the FileMaker Pro.app and Claris Pro.app versions on macOS.EPSS 0.2%CVE-2025-5471HIGHDylib Hijacking in Yandex TelemostEPSS 0.2%CVE-2025-69784HIGHA local, non-privileged attacker can abuse a vulnerable IOCTL interface exposed by the OpenEDR 2.5.1.0 kernel driver to modify the DLL injecEPSS 0.2%CVE-2025-66835HIGHTrueConf Client 8.5.2 is vulnerable to DLL hijacking via crafted wfapi.dll allowing local attackers to execute arbitrary code within the useEPSS 0.2%CVE-2026-41373MEDIUMOpenClaw < 2026.3.31 - Compiler Binary Substitution via Environment Variable Override in Host Execution PolicyEPSS 0.2%CVE-2024-21861MEDIUMUncontrolled search path in some Intel(R) GPA Framework software before version 2023.4 may allow an authenticated user to potentially enableEPSS 0.2%CVE-2024-34167MEDIUMUncontrolled search path for the Intel(R) Server Board S2600ST Family BIOS and Firmware Update software all versions may allow an authenticaEPSS 0.2%CVE-2026-6645HIGHInsecure Search Path Vulnerability in PaperCut Print Deploy Client for WindowsEPSS 0.2%CVE-2025-0069HIGHDLL Hijacking vulnerability in SAPSetupEPSS 0.2%CVE-2023-29187MEDIUMDLL Hijacking vulnerability in SapSetup (Software Installation Program)EPSS 0.2%CVE-2026-47274MEDIUMpam_usb: Uncontrolled search path in pam_usb tools allows privilege escalation via PATH manipulationEPSS 0.2%CVE-2023-45320MEDIUMUncontrolled search path element in some Intel(R) VTune(TM) Profiler software before version 2024.0 may allow an authenticated user to potenEPSS 0.2%CVE-2026-4545HIGHFlos Freeware Notepad2 PROPSYS.dll uncontrolled search pathEPSS 0.2%CVE-2026-3787HIGHUltraVNC Windows Service cryptbase.dll uncontrolled search pathEPSS 0.2%CVE-2025-59889HIGHImproper authentication of library files in the Eaton IPP software installer could lead to arbitrary code execution of an attacker with the EPSS 0.2%CVE-2025-11940HIGHLibreWolf Installer setup.nsi uncontrolled search pathEPSS 0.2%CVE-2026-22561MEDIUMUncontrolled search path elements in Anthropic Claude for Windows installer (Claude Setup.exe) versions prior to 1.1.3363 allow local privilEPSS 0.2%CVE-2026-42936HIGHThe installer of HYPER SBI 2 insecurely loads Dynamic Link Libraries. If there is a crafted DLL at the same directory when invoking the affeEPSS 0.2%