Fallos del tipo CWE-426

322 resultados

Busca em caminho não confiável

Ocorre quando uma aplicação procura por bibliotecas, executáveis ou arquivos em diretórios cuja ordem ou conteúdo não é totalmente controlado, permitindo que um atacante injete uma versão maliciosa de um arquivo antes da legítima ser encontrada. O risco é a execução de código não autorizado com os privilégios da aplicação.

Ejemplo

Uma aplicação precisa carregar a biblioteca 'libssl.so'. Se o PATH inclui o diretório /tmp antes de /usr/lib, um atacante coloca uma libssl.so maliciosa em /tmp — a aplicação carregará a falsa sem saber. Comum em scripts e instaladores que não usam caminhos absolutos.

Cómo mitigar

Use caminhos absolutos e completos ao fazer busca de arquivos críticos (não confie em PATH ou variáveis de ambiente). Valide integridade e propriedade de arquivos encontrados; configure o PATH explicitamente apenas com diretórios confiáveis; em sistemas Unix, remova '.' e /tmp da ordem de busca.

CVE-2023-27763HIGHAn issue found in Wondershare Technology Co.,Ltd MobileTrans v.4.0.2 allows a remote attacker to execute arbitrary commands via the mobiletrEPSS 0.4%CVE-2023-27771HIGHAn issue found in Wondershare Technology Co.,Ltd Creative Centerr v.1.0.8 allows a remote attacker to execute arbitrary commands via the wonEPSS 0.4%CVE-2023-27760HIGHAn issue found in Wondershare Technology Co, Ltd Filmora v.12.0.9 allows a remote attacker to execute arbitrary commands via the filmora_setEPSS 0.4%CVE-2023-27761HIGHAn issue found in Wondershare Technology Co., Ltd UniConverter v.14.0.0 allows a remote attacker to execute arbitrary commands via the unicoEPSS 0.4%CVE-2023-27769HIGHAn issue found in Wondershare Technology Co.,Ltd PDF Reader v.1.0.1 allows a remote attacker to execute arbitrary commands via the pdfreaderEPSS 0.4%CVE-2023-27768HIGHAn issue found in Wondershare Technology Co.,Ltd PDFelement v9.1.1 allows a remote attacker to execute arbitrary commands via the pdfelementEPSS 0.4%CVE-2026-48565HIGHWindows Narrator Braille Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2020-7279MEDIUMDLL search order hijacking in Host IPSEPSS 0.4%CVE-2026-23888MEDIUMpnpm: Binary ZIP extraction allows arbitrary file write via path traversal (Zip Slip)EPSS 0.4%CVE-2020-7476A CWE-426: Untrusted Search Path vulnerability exists in ZigBee Installation Kit (Versions prior to 1.0.1), which could cause execution of mEPSS 0.4%CVE-2024-55503LOWAn issue in termius before v.9.9.0 allows a local attacker to execute arbitrary code via a crafted script to the DYLD_INSERT_LIBRARIES compoEPSS 0.4%CVE-2020-8317HIGHA DLL search path vulnerability was reported in Lenovo Drivers Management prior to version 2.7.1128.1046 that could allow an authenticated uEPSS 0.4%CVE-2026-16674HIGHIBM i is Affected By Multiple Vulnerabilities in WebSphere Application Server LibertyEPSS 0.4%CVE-2020-6654HIGHDLL HijackingEPSS 0.4%CVE-2025-60718HIGHWindows Administrator Protection Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2019-25257HIGHLogicalDOC Enterprise 7.7.4 Authenticated Command Execution via Binary Path ManipulationEPSS 0.4%CVE-2021-25698The OpenSSL component of the Teradici PCoIP Standard Agent prior to version 21.07.0 was compiled without the no-autoload-config option, whicEPSS 0.4%CVE-2021-25699The OpenSSL component of the Teradici PCoIP Software Client prior to version 21.07.0 was compiled without the no-autoload-config option, whiEPSS 0.4%CVE-2022-31012HIGHGit for Windows' installer can be tricked into executing an untrusted binaryEPSS 0.4%CVE-2021-28246HIGHCA eHealth Performance Manager through 6.3.2.12 is affected by Privilege Escalation via a Dynamically Linked Shared Object Library. A regulaEPSS 0.4%