Vulnerabilities > Uncontrolled Search Path Element

DATE CVE VULNERABILITY TITLE RISK
2022-12-19 CVE-2022-42945 Uncontrolled Search Path Element vulnerability in Autodesk DWG Trueview 2023
DWG TrueViewTM 2023 version has a DLL Search Order Hijacking vulnerability.
local
low complexity
autodesk CWE-427
7.8
2022-12-13 CVE-2022-43722 Uncontrolled Search Path Element vulnerability in Siemens Sicam Pas/Pqs
A vulnerability has been identified in SICAM PAS/PQS (All versions < V7.0).
local
low complexity
siemens CWE-427
7.8
2022-12-12 CVE-2022-38395 Uncontrolled Search Path Element vulnerability in HP Fusion and Support Assistant
HP Support Assistant uses HP Performance Tune-up as a diagnostic tool.
local
low complexity
hp CWE-427
7.8
2022-11-30 CVE-2022-3859 Uncontrolled Search Path Element vulnerability in Trellix Agent
An uncontrolled search path vulnerability exists in Trellix Agent (TA) for Windows in versions prior to 5.7.8.
local
low complexity
trellix CWE-427
6.7
2022-11-23 CVE-2022-43751 Uncontrolled Search Path Element vulnerability in Mcafee Total Protection
McAfee Total Protection prior to version 16.0.49 contains an uncontrolled search path element vulnerability due to the use of a variable pointing to a subdirectory that may be controllable by an unprivileged user.
local
low complexity
mcafee CWE-427
7.8
2022-11-21 CVE-2022-40746 Uncontrolled Search Path Element vulnerability in IBM I Access Client Solutions
IBM i Access Family 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.0 could allow a local authenticated attacker to execute arbitrary code on the system, caused by DLL search order hijacking vulnerability.
local
high complexity
ibm CWE-427
6.7
2022-11-21 CVE-2022-45422 Uncontrolled Search Path Element vulnerability in LG Smart Share
When LG SmartShare is installed, local privilege escalation is possible through DLL Hijacking attack.
local
low complexity
lg CWE-427
7.8
2022-11-18 CVE-2022-31694 Uncontrolled Search Path Element vulnerability in Installbuilder
InstallBuilder Qt installers built with versions previous to 22.10 try to load DLLs from the installer binary parent directory when displaying popups.
local
low complexity
installbuilder CWE-427
7.3
2022-11-17 CVE-2022-28766 Uncontrolled Search Path Element vulnerability in Zoom Meetings and Rooms
Windows 32-bit versions of the Zoom Client for Meetings before 5.12.6 and Zoom Rooms for Conference Room before version 5.12.6 are susceptible to a DLL injection vulnerability.
local
low complexity
zoom CWE-427
7.3
2022-11-17 CVE-2022-36924 Uncontrolled Search Path Element vulnerability in Zoom Rooms
The Zoom Rooms Installer for Windows prior to 5.12.6 contains a local privilege escalation vulnerability.
local
low complexity
zoom CWE-427
7.8