Vulnerabilities > Uncontrolled Search Path Element

DATE CVE VULNERABILITY TITLE RISK
2019-08-20 CVE-2019-14684 Uncontrolled Search Path Element vulnerability in Trendmicro Password Manager 5.0
A DLL hijacking vulnerability exists in Trend Micro Password Manager 5.0 in which, if exploited, would allow an attacker to load an arbitrary unsigned DLL into the signed service's process.
local
low complexity
trendmicro CWE-427
7.8
2019-08-14 CVE-2019-8062 Uncontrolled Search Path Element vulnerability in Adobe After Effects
Adobe After Effects versions 16 and earlier have an insecure library loading (dll hijacking) vulnerability.
local
low complexity
adobe CWE-427
7.8
2019-08-14 CVE-2019-7961 Uncontrolled Search Path Element vulnerability in Adobe Prelude CC 8.1
Adobe Prelude CC versions 8.1 and earlier have an insecure library loading (dll hijacking) vulnerability.
local
low complexity
adobe CWE-427
7.8
2019-08-14 CVE-2019-7931 Uncontrolled Search Path Element vulnerability in Adobe Premiere PRO CC 13.1.2
Adobe Premiere Pro CC versions 13.1.2 and earlier have an insecure library loading (dll hijacking) vulnerability.
local
low complexity
adobe CWE-427
7.8
2019-08-14 CVE-2019-7870 Uncontrolled Search Path Element vulnerability in Adobe Character Animator 2.1
Adobe Character Animator versions 2.1 and earlier have an insecure library loading (dll hijacking) vulnerability.
local
low complexity
adobe CWE-427
7.8
2019-08-05 CVE-2019-4473 Uncontrolled Search Path Element vulnerability in IBM Java 7.0.0.0/7.1.4.50/8.0
Multiple binaries in IBM SDK, Java Technology Edition 7, 7R, and 8 on the AIX platform use insecure absolute RPATHs, which may facilitate code injection and privilege elevation by local users.
local
low complexity
ibm CWE-427
7.8
2019-07-30 CVE-2019-14242 Uncontrolled Search Path Element vulnerability in Bitdefender products
An issue was discovered in Bitdefender products for Windows (Bitdefender Endpoint Security Tool versions prior to 6.6.8.115; and Bitdefender Antivirus Plus, Bitdefender Internet Security, and Bitdefender Total Security versions prior to 23.0.24.120) that can lead to local code injection.
local
low complexity
bitdefender CWE-427
6.7
2019-07-18 CVE-2019-7956 Uncontrolled Search Path Element vulnerability in Adobe Dreamweaver
Adobe Dreamweaver direct download installer versions 19.0 and below, 18.0 and below have an Insecure Library Loading (DLL hijacking) vulnerability.
local
low complexity
adobe CWE-427
7.8
2019-07-15 CVE-2019-6825 Uncontrolled Search Path Element vulnerability in Schneider-Electric Proclima 6.0.1/6.1
A CWE-427: Uncontrolled Search Path Element vulnerability exists in ProClima (all versions prior to version 8.0.0) which could allow a malicious DLL file, with the same name of any resident DLLs inside the software installation, to execute arbitrary code in all versions of ProClima prior to version 8.0.0.
local
low complexity
schneider-electric CWE-427
7.8
2019-07-13 CVE-2019-5629 Uncontrolled Search Path Element vulnerability in Rapid7 Insight Agent
Rapid7 Insight Agent, version 2.6.3 and prior, suffers from a local privilege escalation due to an uncontrolled DLL search path.
local
low complexity
rapid7 CWE-427
7.8