Vulnerabilities > Uncontrolled Search Path Element

DATE CVE VULNERABILITY TITLE RISK
2022-06-29 CVE-2022-33037 Uncontrolled Search Path Element vulnerability in Orwell-Dev-Cpp Project Orwell-Dev-Cpp 5.11
A binary hijack in Orwell-Dev-Cpp v5.11 allows attackers to execute arbitrary code via a crafted .exe file.
local
low complexity
orwell-dev-cpp-project CWE-427
7.8
2022-06-20 CVE-2022-1824 Uncontrolled Search Path Element vulnerability in Mcafee Consumer Product Removal Tool
An uncontrolled search path vulnerability in McAfee Consumer Product Removal Tool prior to version 10.4.128 could allow a local attacker to perform a sideloading attack by using a specific file name.
local
low complexity
mcafee CWE-427
8.2
2022-06-16 CVE-2017-20051 Uncontrolled Search Path Element vulnerability in Jrsoftware Inno Setup
A vulnerability was found in InnoSetup Installer.
local
low complexity
jrsoftware CWE-427
7.8
2022-06-16 CVE-2017-20052 Uncontrolled Search Path Element vulnerability in Python 2.7.13
A vulnerability classified as problematic was found in Python 2.7.13.
local
low complexity
python CWE-427
7.8
2022-06-15 CVE-2022-22788 Uncontrolled Search Path Element vulnerability in Zoom Meetings and Rooms
The Zoom Opener installer is downloaded by a user from the Launch meeting page, when attempting to join a meeting without having the Zoom Meeting Client installed.
local
low complexity
zoom CWE-427
7.8
2022-06-13 CVE-2022-24077 Uncontrolled Search Path Element vulnerability in Naver Cloud Explorer
Naver Cloud Explorer Beta allows the attacker to execute arbitrary code as System privilege via malicious DLL injection.
local
low complexity
naver CWE-427
7.8
2022-06-10 CVE-2022-29092 Uncontrolled Search Path Element vulnerability in Dell products
Dell SupportAssist Client Consumer versions (3.11.0 and versions prior) and Dell SupportAssist Client Commercial versions (3.2.0 and versions prior) contain a privilege escalation vulnerability.
local
low complexity
dell CWE-427
7.8
2022-06-09 CVE-2017-20018 Uncontrolled Search Path Element vulnerability in Apachefriends Xampp 7.1.10Vc14
A vulnerability was found in XAMPP 7.1.1-0-VC14.
local
low complexity
apachefriends CWE-427
7.8
2022-06-07 CVE-2022-30744 Uncontrolled Search Path Element vulnerability in Samsung Kies
DLL hijacking vulnerability in KiesWrapper in Samsung Kies prior to version 2.6.4.22043_1 allows attacker to execute arbitrary code.
local
low complexity
samsung CWE-427
7.8
2022-05-27 CVE-2022-28394 Uncontrolled Search Path Element vulnerability in Trendmicro Password Manager
EOL Product CVE - Installer of Trend Micro Password Manager (Consumer) versions 3.7.0.1223 and below provided by Trend Micro Incorporated contains an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries (CWE-427).
local
low complexity
trendmicro CWE-427
7.8