Weaknesses of type CWE-427

897 results

Caminho de busca ou elemento não controlado

A aplicação procura por bibliotecas, configurações ou outros recursos em diretórios sem validar adequadamente quais caminhos ela está usando, permitindo que um atacante injete uma versão maliciosa em um local que será encontrado primeiro. Isso acontece porque a ordem ou composição do caminho de busca não é explicitamente controlada.

Example

Um programa Java com classpath que inclui o diretório atual (.) antes de caminhos do sistema; um atacante coloca uma classe maliciosa no diretório de trabalho e ela é carregada em vez da legítima. Ou um script que procura por um arquivo de configuração em múltiplas pastas sem especificar o caminho absoluto, sendo enganado por um arquivo plantado em /tmp.

How to mitigate

Use caminhos absolutos explícitos em vez de relativos; remova diretórios inseguros (como o atual) do caminho de busca; valide a origem e integridade de recursos carregados (checksums, assinaturas); implemente listas de permitidos para diretórios confiáveis.

CVE-2024-4130HIGHA DLL hijack vulnerability was reported in Lenovo App Store that could allow a local attacker to execute code with elevated privileges.EPSS 0.2%CVE-2026-56090HIGHDell ObjectScale, versions prior to 4.3.0.1, contain(s) an Uncontrolled Search Path Element vulnerability. A low privileged attacker with loEPSS 0.2%CVE-2026-16519HIGHGeoVision GV-IP Device Utility DLL Search Order Hijacking VulnerabilityEPSS 0.2%CVE-2025-34420HIGHMailEnable < 10.54 DLL Hijacking via Unsafe Loading of MEAIAM.DLLEPSS 0.2%CVE-2023-43064HIGHIBM i code executionEPSS 0.2%CVE-2023-39254MEDIUMDell Update Package (DUP), Versions prior to 4.9.10 contain an Uncontrolled Search Path vulnerability. A malicious user with local access toEPSS 0.2%CVE-2025-34417HIGHMailEnable < 10.54 DLL Hijacking via Unsafe Loading of MEAISO.DLLEPSS 0.2%CVE-2025-34416HIGHMailEnable < 10.54 DLL Hijacking via Unsafe Loading of MEAIPO.DLLEPSS 0.2%CVE-2025-34422HIGHMailEnable < 10.54 DLL Hijacking via Unsafe Loading of MEAIPC.DLLEPSS 0.2%CVE-2026-66344MEDIUMNetKids iMark, provided by Integrated Systems Technologies, Inc., contains an Uncontrolled Search Path Element vulnerability (CWE-427). An aEPSS 0.2%CVE-2025-5469HIGHDylib Hijacking in Yandex MessengerEPSS 0.2%CVE-2024-37130HIGHDell OpenManage Server Administrator, versions 11.0.1.0 and prior, contains a Local Privilege Escalation vulnerability via XSL Hijacking. A EPSS 0.2%CVE-2026-23755HIGHD-Link D-View 8 Installer DLL Preloading via Uncontrolled Search PathEPSS 0.2%CVE-2022-34848MEDIUMUncontrolled search path for the Intel(R) NUC Pro Software Suite before version 2.0.0.3 may allow an authenticated user to potentially enablEPSS 0.2%CVE-2023-28823MEDIUMUncontrolled search path in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.1.493 may allow an authenticatEPSS 0.2%CVE-2022-38101MEDIUMUncontrolled search path in some Intel(R) NUC Chaco Canyon BIOS update software before version iFlashV Windows 5.13.00.2105 may allow an autEPSS 0.2%CVE-2025-10215HIGHDLL search path hijacking vulnerabilityEPSS 0.2%CVE-2024-45246HIGHDiebold Nixdorf – CWE-427: Uncontrolled Search Path ElementEPSS 0.2%CVE-2023-34355MEDIUMUncontrolled search path element for some Intel(R) Server Board M10JNP2SB integrated BMC video drivers before version 3.0 for Microsoft WindEPSS 0.2%CVE-2026-9593HIGHiDTM FDI Unauthorized Debug Interface EnablementEPSS 0.2%