Vulnerabilities > Uncontrolled Search Path Element

DATE CVE VULNERABILITY TITLE RISK
2018-10-02 CVE-2018-11072 Uncontrolled Search Path Element vulnerability in Dell Digital Delivery
Dell Digital Delivery versions prior to 3.5.1 contain a DLL Injection Vulnerability.
local
low complexity
dell CWE-427
7.8
2018-09-12 CVE-2018-12163 Uncontrolled Search Path Element vulnerability in Intel IOT Developers KIT 4.0
A DLL injection vulnerability in the Intel IoT Developers Kit 4.0 installer may allow an authenticated user to potentially escalate privileges using file modification via local access.
local
low complexity
intel CWE-427
4.8
2018-09-12 CVE-2018-13806 Uncontrolled Search Path Element vulnerability in Siemens TD Keypad Designer
A vulnerability has been identified in SIEMENS TD Keypad Designer (All versions).
local
low complexity
siemens CWE-427
7.8
2018-08-23 CVE-2018-14797 Uncontrolled Search Path Element vulnerability in Emerson Deltav
Emerson DeltaV DCS versions 11.3.1, 12.3.1, 13.3.0, 13.3.1, R5 allow a specially crafted DLL file to be placed in the search path and loaded as an internal and valid DLL, which may allow arbitrary code execution.
local
low complexity
emerson CWE-427
7.8
2018-08-22 CVE-2018-5238 Uncontrolled Search Path Element vulnerability in Symantec Norton Power Eraser and Symdiag
Norton Power Eraser (prior to 5.3.0.24) and SymDiag (prior to 2.1.242) may be susceptible to a DLL Preloading vulnerability, which is a type of issue that can occur when an application looks to call a DLL for execution and an attacker provides a malicious DLL to use instead.
local
low complexity
symantec CWE-427
7.8
2018-08-22 CVE-2018-5235 Uncontrolled Search Path Element vulnerability in Symantec Norton Utilities
Norton Utilities (prior to 16.0.3.44) may be susceptible to a DLL Preloading vulnerability, which is a type of issue that can occur when an application looks to call a DLL for execution and an attacker provides a malicious DLL to use instead.
high complexity
symantec CWE-427
6.0
2018-07-25 CVE-2018-8090 Uncontrolled Search Path Element vulnerability in Quickheal Antivirus Pro, Internet Security and Total Security
Quick Heal Total Security 64 bit 17.00 (QHTS64.exe), (QHTSFT64.exe) - Version 10.0.1.38; Quick Heal Total Security 32 bit 17.00 (QHTS32.exe), (QHTSFT32.exe) - Version 10.0.1.38; Quick Heal Internet Security 64 bit 17.00 (QHIS64.exe), (QHISFT64.exe) - Version 10.0.0.37; Quick Heal Internet Security 32 bit 17.00 (QHIS32.exe), (QHISFT32.exe) - Version 10.0.0.37; Quick Heal AntiVirus Pro 64 bit 17.00 (QHAV64.exe), (QHAVFT64.exe) - Version 10.0.0.37; and Quick Heal AntiVirus Pro 32 bit 17.00 (QHAV32.exe), (QHAVFT32.exe) - Version 10.0.0.37 allow DLL Hijacking because of Insecure Library Loading.
local
low complexity
quickheal CWE-427
7.8
2018-07-20 CVE-2018-12805 Uncontrolled Search Path Element vulnerability in Adobe Connect
Adobe Connect versions 9.7.5 and earlier have an Insecure Library Loading vulnerability.
network
low complexity
adobe CWE-427
critical
9.8
2018-07-11 CVE-2018-11049 Uncontrolled Search Path Element vulnerability in multiple products
RSA Identity Governance and Lifecycle, RSA Via Lifecycle and Governance, and RSA IMG releases have an uncontrolled search vulnerability.
local
low complexity
emc rsa CWE-427
7.3
2018-07-09 CVE-2018-1000622 Uncontrolled Search Path Element vulnerability in Rust-Lang Rust
The Rust Programming Language rustdoc version Between 0.8 and 1.27.0 contains a CWE-427: Uncontrolled Search Path Element vulnerability in rustdoc plugins that can result in local code execution as a different user.
local
low complexity
rust-lang CWE-427
7.8