Weaknesses of type CWE-427

897 results

Caminho de busca ou elemento não controlado

A aplicação procura por bibliotecas, configurações ou outros recursos em diretórios sem validar adequadamente quais caminhos ela está usando, permitindo que um atacante injete uma versão maliciosa em um local que será encontrado primeiro. Isso acontece porque a ordem ou composição do caminho de busca não é explicitamente controlada.

Example

Um programa Java com classpath que inclui o diretório atual (.) antes de caminhos do sistema; um atacante coloca uma classe maliciosa no diretório de trabalho e ela é carregada em vez da legítima. Ou um script que procura por um arquivo de configuração em múltiplas pastas sem especificar o caminho absoluto, sendo enganado por um arquivo plantado em /tmp.

How to mitigate

Use caminhos absolutos explícitos em vez de relativos; remova diretórios inseguros (como o atual) do caminho de busca; valide a origem e integridade de recursos carregados (checksums, assinaturas); implemente listas de permitidos para diretórios confiáveis.

CVE-2026-26098HIGHUncontrolled Search Path Element in Owl opdsEPSS 0.2%CVE-2026-83598HIGHNetdata: Local Privilege Escalation in Netdata Agent Windows installer via PowerShell Profile Hijack in MSI RepairEPSS 0.2%CVE-2023-25182MEDIUMUncontrolled search path element in the Intel(R) Unite(R) Client software for Mac before version 4.2.11 may allow an authenticated user to pEPSS 0.2%CVE-2025-10581HIGHA potential DLL hijacking vulnerability was discovered in the Lenovo PC Manager during an internal security assessment that could allow a loEPSS 0.2%CVE-2024-53977MEDIUMA vulnerability has been identified in ModelSim (All versions < V2025.1), Questa (All versions < V2025.1). An example setup script containedEPSS 0.2%CVE-2025-20108MEDIUMUncontrolled search path element for some Intel(R) Network Adapter Driver installers for Windows 11 before version 29.4 may allow an authentEPSS 0.2%CVE-2025-61161HIGHDLL hijacking vulnerability in Evope Collector 1.1.6.9.0 and related components load the wtsapi32.dll library from an uncontrolled search paEPSS 0.2%CVE-2025-7427MEDIUMUncontrolled Search Path Element in Arm Development Studio before 2025EPSS 0.2%CVE-2026-44609HIGHLocal privilege escalation due to EXE hijacking vulnerability. The following products are affected: Acronis DeviceLock DLP (Windows) before EPSS 0.2%CVE-2026-44682HIGHLocal privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis DeviceLock DLP (Windows) before EPSS 0.2%CVE-2026-50033HIGHLocal privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis DeviceLock DLP (Windows) before EPSS 0.2%CVE-2024-21769MEDIUMUncontrolled search path in some Intel(R) Ethernet Connection I219-LM install software may allow an authenticated user to potentially enableEPSS 0.2%CVE-2024-21766MEDIUMUncontrolled search path for some Intel(R) oneAPI Math Kernel Library software before version 2024.1 may allow an authenticated user to poteEPSS 0.2%CVE-2024-46895MEDIUMUncontrolled search path for some Intel(R) Arc™ &amp; Iris(R) Xe graphics software before version 32.0.101.6083/32.0.101.5736 may allow an aEPSS 0.2%CVE-2024-39833MEDIUMUncontrolled search path for some Intel(R) QAT software before version 2.3.0 may allow an authenticated user to potentially enable escalatioEPSS 0.2%CVE-2025-20043MEDIUMUncontrolled search path for some Intel(R) RealSense™ SDK software before version 2.56.2 may allow an authenticated user to potentially enabEPSS 0.2%CVE-2024-21857MEDIUMUncontrolled search path for some Intel(R) oneAPI Compiler software before version 2024.1 may allow an authenticated user to potentially enaEPSS 0.2%CVE-2024-23491MEDIUMUncontrolled search path in some Intel(R) Distribution for GDB software before version 2024.0.1 may allow an authenticated user to potentialEPSS 0.2%CVE-2024-47800MEDIUMUncontrolled search path for some Intel(R) Graphics Driver software may allow an authenticated user to potentially enable escalation of privEPSS 0.2%CVE-2024-23489MEDIUMUncontrolled search path for some Intel(R) VROC software before version 8.6.0.1191 may allow an authenticated user to potentially enable escEPSS 0.2%