Weaknesses of type CWE-427

897 results

Caminho de busca ou elemento não controlado

A aplicação procura por bibliotecas, configurações ou outros recursos em diretórios sem validar adequadamente quais caminhos ela está usando, permitindo que um atacante injete uma versão maliciosa em um local que será encontrado primeiro. Isso acontece porque a ordem ou composição do caminho de busca não é explicitamente controlada.

Example

Um programa Java com classpath que inclui o diretório atual (.) antes de caminhos do sistema; um atacante coloca uma classe maliciosa no diretório de trabalho e ela é carregada em vez da legítima. Ou um script que procura por um arquivo de configuração em múltiplas pastas sem especificar o caminho absoluto, sendo enganado por um arquivo plantado em /tmp.

How to mitigate

Use caminhos absolutos explícitos em vez de relativos; remova diretórios inseguros (como o atual) do caminho de busca; valide a origem e integridade de recursos carregados (checksums, assinaturas); implemente listas de permitidos para diretórios confiáveis.

CVE-2024-36245MEDIUMUncontrolled search path element in some Intel(R) VTune(TM) Profiler software before version 2024.2.0 may allow an authenticated user to potEPSS 0.2%CVE-2024-21843MEDIUMUncontrolled search path for some Intel(R) Computing Improvement Program software before version 2.4.0.10654 may allow an authenticated userEPSS 0.2%CVE-2024-21841MEDIUMUncontrolled search path for some Intel(R) Distribution for GDB software before version 2024.0 may allow an authenticated user to potentiallEPSS 0.2%CVE-2026-18718HIGHGhidra Swift Demangler Analyzer Arbitrary Code Execution via Project StateEPSS 0.2%CVE-2024-22379MEDIUMUncontrolled search path in some Intel(R) Inspector software before version 2024.0 may allow an authenticated user to potentially enable escEPSS 0.2%CVE-2024-28952MEDIUMUncontrolled search path for some Intel(R) IPP software for Windows before version 2021.12.0 may allow an authenticated user to potentially EPSS 0.2%CVE-2022-26086MEDIUMUncontrolled search path element in the PresentMon software maintained by Intel(R) before version 1.7.1 may allow an authenticated user to pEPSS 0.2%CVE-2025-26859HIGHRemoteView PC Application Console versions prior to 6.0.2 contain an uncontrolled search path element vulnerability. If a crafted DLL is plaEPSS 0.2%CVE-2026-40004MEDIUMopenssl.cnf Privilege Escalation Vulnerability in ZTE Cloud PC Client uSmartviewEPSS 0.2%CVE-2022-36380MEDIUMUncontrolled search path in the installer software for some Intel(r) NUC Kit Wireless Adapter drivers for Windows 10 before version 22.40 maEPSS 0.2%CVE-2025-26860HIGHRemoteCall Remote Support Program (for Operator) versions prior to 5.1.0 contain an uncontrolled search path element vulnerability. If a craEPSS 0.2%CVE-2024-21818MEDIUMUncontrolled search path in some Intel(R) PCM software before version 202311 may allow an authenticated user to potentially enable escalatioEPSS 0.2%CVE-2025-26861HIGHRemoteCall Remote Support Program (for Operator) versions prior to 5.3.0 contain an uncontrolled search path element vulnerability. If a craEPSS 0.2%CVE-2026-82649HIGHSiYuan before 3.8.1 Local Privilege Escalation via Uncontrolled Search PathEPSS 0.2%CVE-2026-56090HIGHDell ObjectScale, versions prior to 4.3.0.1, contain(s) an Uncontrolled Search Path Element vulnerability. A low privileged attacker with loEPSS 0.2%CVE-2025-27997HIGHAn issue in Blizzard Battle.net v2.40.0.15267 allows attackers to escalate privileges via placing a crafted shell script or executable into EPSS 0.2%CVE-2023-40155MEDIUMUncontrolled search path for some Intel(R) CST software before version 2.1.10300 may allow an authenticated user to potentially enable escalEPSS 0.2%CVE-2026-16519HIGHGeoVision GV-IP Device Utility DLL Search Order Hijacking VulnerabilityEPSS 0.2%CVE-2024-4130HIGHA DLL hijack vulnerability was reported in Lenovo App Store that could allow a local attacker to execute code with elevated privileges.EPSS 0.2%CVE-2024-4131HIGHA DLL hijack vulnerability was reported in Lenovo Emulator that could allow a local attacker to execute code with elevated privileges.EPSS 0.2%