Vulnerabilities > Uncontrolled Search Path Element

DATE CVE VULNERABILITY TITLE RISK
2020-02-20 CVE-2020-8601 Uncontrolled Search Path Element vulnerability in Trendmicro vulnerability Protection 2.0
Trend Micro Vulnerability Protection 2.0 is affected by a vulnerability that could allow an attack to use the product installer to load other DLL files located in the same directory.
local
low complexity
trendmicro CWE-427
4.6
2020-02-20 CVE-2019-14688 Uncontrolled Search Path Element vulnerability in Trendmicro products
Trend Micro has repackaged installers for several Trend Micro products that were found to utilize a version of an install package that had a DLL hijack vulnerability that could be exploited during a new product installation.
network
high complexity
trendmicro microsoft CWE-427
5.1
2020-02-19 CVE-2020-3153 Uncontrolled Search Path Element vulnerability in Cisco Anyconnect Secure Mobility Client 4.8.00175/4.8.01090
A vulnerability in the installer component of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated local attacker to copy user-supplied files to system level directories with system level privileges.
local
low complexity
cisco CWE-427
4.9
2020-02-19 CVE-2020-8959 Uncontrolled Search Path Element vulnerability in Westerndigital products
Western Digital WesternDigitalSSDDashboardSetup.exe before 3.0.2.0 allows DLL Hijacking.
4.4
2020-02-06 CVE-2019-20406 Uncontrolled Search Path Element vulnerability in Atlassian Confluence
The usage of Tomcat in Confluence on the Microsoft Windows operating system before version 7.0.5, and from version 7.1.0 before version 7.1.1 allows local system attackers who have permission to write a DLL file in a directory in the global path environmental variable variable to inject code & escalate their privileges via a DLL hijacking vulnerability.
4.4
2020-02-06 CVE-2019-20400 Uncontrolled Search Path Element vulnerability in Atlassian Jira Server
The usage of Tomcat in Jira before version 8.5.2 allows local attackers with permission to write a dll file to a directory in the global path environmental variable can inject code into via a DLL hijacking vulnerability.
4.4
2020-01-30 CVE-2013-0725 Uncontrolled Search Path Element vulnerability in Hexagongeospatial Erdas ER Viewer 13.0
ERDAS ER Viewer 13.0 has dwmapi.dll and irml.dll libraries arbitrary code execution vulnerabilities
6.9
2020-01-22 CVE-2019-6858 Uncontrolled Search Path Element vulnerability in Schneider-Electric MSX Configurator
A CWE-427:Uncontrolled Search Path Element vulnerability exists in MSX Configurator (Software Version prior to V1.0.8.1), which could cause privilege escalation when injecting a malicious DLL.
4.4
2020-01-17 CVE-2019-14600 Uncontrolled Search Path Element vulnerability in Intel Snmp Subagent Stand-Alone
Uncontrolled search path element in the installer for Intel(R) SNMP Subagent Stand-Alone for Windows* may allow an authenticated user to potentially enable escalation of privilege via local access.
local
low complexity
intel CWE-427
4.6
2020-01-14 CVE-2016-6592 Uncontrolled Search Path Element vulnerability in Symantec Norton Download Manager
A vulnerability was found in Symantec Norton Download Manager versions prior to 5.6.
local
low complexity
symantec CWE-427
4.6