Vulnerabilities > Uncontrolled Search Path Element

DATE CVE VULNERABILITY TITLE RISK
2020-08-13 CVE-2020-8687 Uncontrolled Search Path Element vulnerability in Intel Rste Software Raid
Uncontrolled search path in the installer for Intel(R) RSTe Software RAID Driver for the Intel(R) Server Board M10JNP2SB before version 4.7.0.1119 may allow an authenticated user to potentially enable escalation of privilege via local access.
local
low complexity
intel CWE-427
7.8
2020-08-12 CVE-2020-15596 Uncontrolled Search Path Element vulnerability in HP products
The ALPS ALPINE touchpad driver before 8.2206.1717.634, as used on various Dell, HP, and Lenovo laptops, allows attackers to conduct Path Disclosure attacks via a "fake" DLL file.
local
low complexity
hp CWE-427
6.7
2020-08-11 CVE-2020-13177 Uncontrolled Search Path Element vulnerability in Teradici Graphics Agent and Pcoip Standard Agent
The support bundler in Teradici PCoIP Standard Agent for Windows and Graphics Agent for Windows versions prior to 20.04.1 and 20.07.0 does not use hard coded paths for certain Windows binaries, which allows an attacker to gain elevated privileges via execution of a malicious binary placed in the system path.
local
low complexity
teradici CWE-427
7.8
2020-08-10 CVE-2020-15657 Uncontrolled Search Path Element vulnerability in Mozilla Firefox
Firefox could be made to load attacker-supplied DLL files from the installation directory.
local
low complexity
mozilla CWE-427
7.8
2020-07-29 CVE-2020-16143 Uncontrolled Search Path Element vulnerability in Seafile Seafile-Client 7.0.8
The seafile-client client 7.0.8 for Seafile is vulnerable to DLL hijacking because it loads exchndl.dll from the current working directory.
local
low complexity
seafile CWE-427
7.8
2020-07-21 CVE-2020-15724 Uncontrolled Search Path Element vulnerability in 360Totalsecurity 360 Total Security
In the version 12.1.0.1005 and below of 360 Total Security, when the Gamefolde calls GameChrome.exe, there exists a local privilege escalation vulnerability.
local
low complexity
360totalsecurity CWE-427
7.8
2020-07-21 CVE-2020-15723 Uncontrolled Search Path Element vulnerability in 360Totalsecurity 360 Total Security
In the version 12.1.0.1004 and below of 360 Total Security, when the main process of 360 Total Security calls GameChrome.exe, there exists a local privilege escalation vulnerability.
local
low complexity
360totalsecurity CWE-427
7.8
2020-07-21 CVE-2020-15722 Uncontrolled Search Path Element vulnerability in 360Totalsecurity 360 Total Security
In version 12.1.0.1004 and below of 360 Total Security,when TPI calls the browser process, there exists a local privilege escalation vulnerability.
local
low complexity
360totalsecurity CWE-427
7.8
2020-07-09 CVE-2020-12423 Uncontrolled Search Path Element vulnerability in Mozilla Firefox
When the Windows DLL "webauthn.dll" was missing from the Operating System, and a malicious one was placed in a folder in the user's %PATH%, Firefox may have loaded the DLL, leading to arbitrary code execution.
local
low complexity
mozilla CWE-427
7.8
2020-07-06 CVE-2020-9100 Uncontrolled Search Path Element vulnerability in Huawei Hisuite
Earlier than HiSuite 10.1.0.500 have a DLL hijacking vulnerability.
local
low complexity
huawei CWE-427
7.8