Weaknesses of type CWE-427

897 results

Caminho de busca ou elemento não controlado

A aplicação procura por bibliotecas, configurações ou outros recursos em diretórios sem validar adequadamente quais caminhos ela está usando, permitindo que um atacante injete uma versão maliciosa em um local que será encontrado primeiro. Isso acontece porque a ordem ou composição do caminho de busca não é explicitamente controlada.

Example

Um programa Java com classpath que inclui o diretório atual (.) antes de caminhos do sistema; um atacante coloca uma classe maliciosa no diretório de trabalho e ela é carregada em vez da legítima. Ou um script que procura por um arquivo de configuração em múltiplas pastas sem especificar o caminho absoluto, sendo enganado por um arquivo plantado em /tmp.

How to mitigate

Use caminhos absolutos explícitos em vez de relativos; remova diretórios inseguros (como o atual) do caminho de busca; valide a origem e integridade de recursos carregados (checksums, assinaturas); implemente listas de permitidos para diretórios confiáveis.

CVE-2025-20015MEDIUMUncontrolled search path element for some Intel(R) Ethernet Connection software before version 29.4 may allow an authenticated user to potenEPSS 0.2%CVE-2024-39833MEDIUMUncontrolled search path for some Intel(R) QAT software before version 2.3.0 may allow an authenticated user to potentially enable escalatioEPSS 0.2%CVE-2024-21766MEDIUMUncontrolled search path for some Intel(R) oneAPI Math Kernel Library software before version 2024.1 may allow an authenticated user to poteEPSS 0.2%CVE-2024-23489MEDIUMUncontrolled search path for some Intel(R) VROC software before version 8.6.0.1191 may allow an authenticated user to potentially enable escEPSS 0.2%CVE-2024-47795MEDIUMUncontrolled search path for some Intel(R) oneAPI DPC++/C++ Compiler software before version 2025.0.0 may allow an authenticated user to potEPSS 0.2%CVE-2024-46895MEDIUMUncontrolled search path for some Intel(R) Arc™ &amp; Iris(R) Xe graphics software before version 32.0.101.6083/32.0.101.5736 may allow an aEPSS 0.2%CVE-2026-3091MEDIUMAn uncontrolled search path element vulnerability in Synology Presto Client before 2.1.3-0672 allows local users to read or write arbitrary EPSS 0.2%CVE-2024-22376MEDIUMUncontrolled search path element in some installation software for Intel(R) Ethernet Adapter Driver Pack before version 28.3 may allow an auEPSS 0.2%CVE-2025-52541HIGHA DLL hijacking vulnerability in Vivado could allow a local attacker to achieve privilege escalation, potentially resulting in arbitrary codEPSS 0.2%CVE-2022-50808HIGHCoolerMaster MasterPlus 1.8.5 - 'MPService' Unquoted Service PathEPSS 0.2%CVE-2025-20079MEDIUMUncontrolled search path for some Intel(R) Advisor software may allow an authenticated user to potentially enable escalation of privilege viEPSS 0.2%CVE-2023-51710MEDIUMEMS SQL Manager 3.6.2 (build 55333) for Oracle allows DLL hijacking: a user can trigger the execution of arbitrary code every time the produEPSS 0.2%CVE-2023-2355MEDIUMLocal privilege escalation due to a DLL hijacking vulnerability. The following products are affected: Acronis Snap Deploy (Windows) before bEPSS 0.2%CVE-2025-62185MEDIUMIn Ankitects Anki before 25.02.5, a crafted shared deck can place a YouTube downloader executable in the media folder, and this is executed EPSS 0.2%CVE-2024-47194MEDIUMA vulnerability has been identified in ModelSim (All versions < V2024.3), Questa (All versions < V2024.3). vish2.exe in affected applicationEPSS 0.2%CVE-2024-47195MEDIUMA vulnerability has been identified in ModelSim (All versions < V2024.3), Questa (All versions < V2024.3). gdb.exe in affected applications EPSS 0.2%CVE-2024-47196MEDIUMA vulnerability has been identified in ModelSim (All versions < V2025.2), Questa (All versions < V2025.2). vsimk.exe in affected applicationEPSS 0.2%CVE-2024-23909MEDIUMUncontrolled search path in some Intel(R) FPGA SDK for OpenCL(TM) software technology may allow an authenticated user to potentially enable EPSS 0.1%CVE-2025-64695HIGHUncontrolled search path element issue exists in the installer of LogStare Collector (for Windows). If exploited, arbitrary code may be execEPSS 0.1%CVE-2024-21784MEDIUMUncontrolled search path for some Intel(R) IPP Cryptography software before version 2021.11 may allow an authenticated user to potentially eEPSS 0.1%