Vulnerabilities > Uncontrolled Search Path Element

DATE CVE VULNERABILITY TITLE RISK
2021-09-08 CVE-2021-36216 Uncontrolled Search Path Element vulnerability in Linecorp Line
LINE for Windows 6.2.1.2289 and before allows arbitrary code execution via malicious DLL injection.
local
low complexity
linecorp CWE-427
7.8
2021-08-26 CVE-2021-20793 Uncontrolled Search Path Element vulnerability in Sony Audio USB Driver and HAP Music Transfer
Untrusted search path vulnerability in the installer of Sony Audio USB Driver V1.10 and prior and the installer of HAP Music Transfer Ver.1.3.0 and prior allows an attacker to gain privileges and execute arbitrary code via a Trojan horse DLL in an unspecified directory.
local
low complexity
sony CWE-427
7.8
2021-08-24 CVE-2021-28594 Uncontrolled Search Path Element vulnerability in Adobe Creative Cloud Desktop Application 2.4
Adobe Creative Cloud Desktop Application (installer) version 2.4 (and earlier) is affected by an Uncontrolled Search Path Element vulnerability.
local
low complexity
adobe CWE-427
7.8
2021-08-18 CVE-2021-37617 Uncontrolled Search Path Element vulnerability in Nextcloud Desktop
The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with a computer.
local
low complexity
nextcloud CWE-427
7.3
2021-08-17 CVE-2021-3633 Uncontrolled Search Path Element vulnerability in Lenovo Drivers Management 2.7.1128.1046
A DLL preloading vulnerability was reported in Lenovo Driver Management prior to version 2.9.0719.1104 that could allow privilege escalation.
local
low complexity
lenovo CWE-427
7.8
2021-08-12 CVE-2021-38086 Uncontrolled Search Path Element vulnerability in Acronis Cyber Protect 15
Acronis Cyber Protect 15 for Windows prior to build 27009 and Acronis Agent for Windows prior to build 26226 allowed local privilege escalation via DLL hijacking.
local
low complexity
acronis CWE-427
7.8
2021-08-11 CVE-2021-36770 Uncontrolled Search Path Element vulnerability in multiple products
Encode.pm, as distributed in Perl through 5.34.0, allows local users to gain privileges via a Trojan horse Encode::ConfigLocal library (in the current working directory) that preempts dynamic module loading.
local
low complexity
p5-encode-project fedoraproject CWE-427
7.8
2021-08-11 CVE-2021-38571 Uncontrolled Search Path Element vulnerability in Foxitsoftware Foxit Reader
An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4.
local
low complexity
foxitsoftware CWE-427
7.8
2021-08-11 CVE-2021-0160 Uncontrolled Search Path Element vulnerability in Intel Avermedia Capture Card
Uncontrolled search path in some Intel(R) NUC Pro Chassis Element AverMedia Capture Card drivers before version 3.0.64.143 may allow an authenticated user to potentially enable escalation of privilege via local access.
local
low complexity
intel CWE-427
7.8
2021-08-05 CVE-2021-32580 Uncontrolled Search Path Element vulnerability in Acronis True Image 2021
Acronis True Image prior to 2021 Update 4 for Windows allowed local privilege escalation due to DLL hijacking.
local
low complexity
acronis CWE-427
7.8