Weaknesses of type CWE-427

897 results

Caminho de busca ou elemento não controlado

A aplicação procura por bibliotecas, configurações ou outros recursos em diretórios sem validar adequadamente quais caminhos ela está usando, permitindo que um atacante injete uma versão maliciosa em um local que será encontrado primeiro. Isso acontece porque a ordem ou composição do caminho de busca não é explicitamente controlada.

Example

Um programa Java com classpath que inclui o diretório atual (.) antes de caminhos do sistema; um atacante coloca uma classe maliciosa no diretório de trabalho e ela é carregada em vez da legítima. Ou um script que procura por um arquivo de configuração em múltiplas pastas sem especificar o caminho absoluto, sendo enganado por um arquivo plantado em /tmp.

How to mitigate

Use caminhos absolutos explícitos em vez de relativos; remova diretórios inseguros (como o atual) do caminho de busca; valide a origem e integridade de recursos carregados (checksums, assinaturas); implemente listas de permitidos para diretórios confiáveis.

CVE-2025-20092MEDIUMUncontrolled search path for some Clock Jitter Tool software before version 6.0.1 may allow an authenticated user to potentially enable escaEPSS 0.1%CVE-2025-40763HIGHA vulnerability has been identified in Altair Grid Engine (All versions < V2026.0.0). Affected products do not properly validate environmentEPSS 0.1%CVE-2026-25191HIGHThe installer of FinalCode Client provided by Digital Arts Inc. contains an issue with the DLL search path. If a user is directed to place aEPSS 0.1%CVE-2024-2207MEDIUMSound Research SECOMN64 Escalation of PrivilegeEPSS 0.1%CVE-2025-48503HIGHA DLL hijacking vulnerability in the AMD Software Installer could allow an attacker to achieve privilege escalation potentially resulting inEPSS 0.1%CVE-2026-22270MEDIUMDell PowerScale OneFS, versions prior to 9.10.1.6 and versions 9.11.0.0 through 9.12.0.1, contains an uncontrolled search path element vulneEPSS 0.1%CVE-2025-0712HIGHAPM Server Uncontrolled Search Path Element can lead to Local Privilege Escalation (LPE) when using the Windows InstallerEPSS 0.1%CVE-2025-12046HIGHA DLL hijacking vulnerability was reported in the Lenovo App Store and Lenovo Browser applications that could allow a local authenticated usEPSS 0.1%CVE-2024-55955MEDIUMAn incorrect permissions assignment vulnerability in Trend Micro Deep Security 20.0 agents between versions 20.0.1-9400 and 20.0.1-23340 couEPSS 0.1%CVE-2025-13152HIGHA potential DLL hijacking vulnerability was reported in Lenovo One Client during an internal security assessment that could allow a local auEPSS 0.1%CVE-2025-20106MEDIUMUncontrolled search path in some software installer for some VTune(TM) Profiler software and Intel(R) oneAPI Base Toolkits before version 20EPSS 0.1%CVE-2025-21093MEDIUMUncontrolled search path element for some Intel(R) Driver &amp; Support Assistant Tool software before version 24.6.49.8 may allow an authenEPSS 0.1%CVE-2026-21420HIGHDell Repository Manager (DRM), versions prior to 3.4.8, contains an Uncontrolled Search Path Element vulnerability. A low privileged attackeEPSS 0.1%CVE-2025-30506MEDIUMUncontrolled search path for some Intel Driver and Support Assistant before version 25.2 within Ring 3: User Applications may allow an escalEPSS 0.1%CVE-2025-57836HIGHAn issue was discovered in Samsung Magician 6.3.0 through 8.3.2 on Windows. The installer creates a temporary folder with weak permissions dEPSS 0.1%CVE-2026-89325HIGHRapid7 Insight Agent: Uncontrolled search path element in InsightVM assessment content leads to local privilege escalationEPSS 0.1%CVE-2025-24923MEDIUMUncontrolled search path in some Intel(R) AI for Enterprise Retrieval-augmented Generation software may allow an authenticated user to potenEPSS 0.1%CVE-2025-20048MEDIUMUncontrolled search path for the Intel(R) Trace Analyzer and Collector software all verions may allow an authenticated user to potentially eEPSS 0.1%CVE-2025-20627MEDIUMUncontrolled search path for some Intel(R) oneAPI DPC++/C++ Compiler software before version 2025.0.1 may allow an authenticated user to potEPSS 0.1%CVE-2025-20017MEDIUMUncontrolled search path for some Intel(R) oneAPI Toolkit and component software installers may allow an authenticated user to potentially eEPSS 0.1%