Vulnerabilities > Uncontrolled Search Path Element

DATE CVE VULNERABILITY TITLE RISK
2022-07-21 CVE-2022-32498 Uncontrolled Search Path Element vulnerability in Dell Powerstore Command Line Interface
Dell EMC PowerStore, Versions prior to v3.0.0.0 contain a DLL Hijacking vulnerability in PSTCLI.
local
low complexity
dell CWE-427
7.8
2022-07-18 CVE-2022-34900 Uncontrolled Search Path Element vulnerability in Parallels Access 6.5.4(39313)
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Access 6.5.3 (39313) Agent.
local
low complexity
parallels CWE-427
7.8
2022-07-18 CVE-2022-34901 Uncontrolled Search Path Element vulnerability in Parallels Access 6.5.4(39316)
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Access 6.5.4 (39316) Agent.
local
low complexity
parallels CWE-427
7.8
2022-07-18 CVE-2022-34902 Uncontrolled Search Path Element vulnerability in Parallels Access 6.5.4(39316)
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Access 6.5.4 (39316) Agent.
local
low complexity
parallels CWE-427
7.8
2022-07-18 CVE-2021-42923 Uncontrolled Search Path Element vulnerability in Showmypc 3606
ShowMyPC 3606 on Windows suffers from a DLL hijack vulnerability.
local
low complexity
showmypc CWE-427
7.3
2022-07-14 CVE-2022-32222 Uncontrolled Search Path Element vulnerability in multiple products
A cryptographic vulnerability exists on Node.js on linux in versions of 18.x prior to 18.40.0 which allowed a default path for openssl.cnf that might be accessible under some circumstances to a non-admin user instead of /etc/ssl as was the case in versions prior to the upgrade to OpenSSL 3.
network
low complexity
nodejs siemens CWE-427
5.3
2022-07-14 CVE-2022-32223 Uncontrolled Search Path Element vulnerability in Nodejs Node.Js
Node.js is vulnerable to Hijack Execution Flow: DLL Hijacking under certain conditions on Windows platforms.This vulnerability can be exploited if the victim has the following dependencies on a Windows machine:* OpenSSL has been installed and “C:\Program Files\Common Files\SSL\openssl.cnf” exists.Whenever the above conditions are present, `node.exe` will search for `providers.dll` in the current user directory.After that, `node.exe` will try to search for `providers.dll` by the DLL Search Order in Windows.It is possible for an attacker to place the malicious file `providers.dll` under a variety of paths and exploit this vulnerability.
local
low complexity
nodejs CWE-427
7.3
2022-06-30 CVE-2017-20123 Uncontrolled Search Path Element vulnerability in Sparklabs Viscosity 1.6.7
A vulnerability was found in Viscosity 1.6.7.
local
low complexity
sparklabs CWE-427
7.8
2022-06-29 CVE-2022-33035 Uncontrolled Search Path Element vulnerability in Netsarang Xlpd 7.0.0094
XLPD v7.0.0094 and below contains an unquoted service path vulnerability which allows local users to launch processes with elevated privileges.
local
low complexity
netsarang CWE-427
7.8
2022-06-29 CVE-2022-33036 Uncontrolled Search Path Element vulnerability in Embarcadero Dev-C++ 6.3
A binary hijack in Embarcadero Dev-CPP v6.3 allows attackers to execute arbitrary code via a crafted .exe file.
local
low complexity
embarcadero CWE-427
7.8