Vulnerabilities > Uncontrolled Search Path Element

DATE CVE VULNERABILITY TITLE RISK
2018-06-11 CVE-2017-7836 Uncontrolled Search Path Element vulnerability in Mozilla Firefox
The "pingsender" executable used by the Firefox Health Report dynamically loads a system copy of libcurl, which an attacker could replace.
local
low complexity
mozilla CWE-427
7.8
2018-05-19 CVE-2018-4938 Uncontrolled Search Path Element vulnerability in Adobe Coldfusion 11.0/2016
Adobe ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions have an exploitable Insecure Library Loading vulnerability.
local
low complexity
adobe CWE-427
7.8
2018-05-10 CVE-2018-3649 Uncontrolled Search Path Element vulnerability in Intel products
DLL injection vulnerability in the installation executables (Autorun.exe and Setup.exe) for Intel's wireless drivers and related software in Intel Dual Band Wireless-AC, Tri-Band Wireless-AC and Wireless-AC family of products allows a local attacker to cause escalation of privilege via remote code execution.
local
low complexity
intel CWE-427
7.8
2018-05-09 CVE-2017-5175 Uncontrolled Search Path Element vulnerability in Advantech Webaccess
Advantech WebAccess 8.1 and earlier contains a DLL hijacking vulnerability which may allow an attacker to run a malicious DLL file within the search path resulting in execution of arbitrary code.
local
low complexity
advantech CWE-427
7.8
2018-04-26 CVE-2017-14010 Uncontrolled Search Path Element vulnerability in Spidercontrol Scada Microbrowser 1.6.30.144
In SpiderControl MicroBrowser Windows XP, Vista 7, 8 and 10, Versions 1.6.30.144 and prior, an uncontrolled search path element vulnerability has been identified which could be exploited by placing a specially crafted DLL file in the search path.
local
low complexity
spidercontrol CWE-427
7.8
2018-03-27 CVE-2018-6766 Uncontrolled Search Path Element vulnerability in Swisscom Tvmediahelper 1.1.0.50
Swisscom TVMediaHelper 1.1.0.50 contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on the targeted system.
local
low complexity
swisscom CWE-427
7.8
2018-03-27 CVE-2018-6765 Uncontrolled Search Path Element vulnerability in Swisscom Myswisscomassistant 2.17.1.1065
Swisscom MySwisscomAssistant 2.17.1.1065 contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on the targeted system.
local
low complexity
swisscom CWE-427
7.8
2018-02-06 CVE-2018-5457 Uncontrolled Search Path Element vulnerability in Vyaire Carefusion Upgrade Utility 2.0.2.2
A uncontrolled search path element issue was discovered in Vyaire Medical CareFusion Upgrade Utility used with Windows XP systems, Versions 2.0.2.2 and prior versions.
local
high complexity
vyaire CWE-427
7.0
2018-01-18 CVE-2017-5170 Uncontrolled Search Path Element vulnerability in Moxa Softnvr-Ia Live View
An Uncontrolled Search Path Element issue was discovered in Moxa SoftNVR-IA Live Viewer, Version 3.30.3122 and prior versions.
network
low complexity
moxa CWE-427
7.2
2017-11-16 CVE-2017-16777 Uncontrolled Search Path Element vulnerability in Hashicorp Vagrant 5.0.3
If HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) 5.0.3 is installed but VMware Fusion is not, a local attacker can create a fake application directory and exploit the suid sudo helper in order to escalate to root.
local
low complexity
hashicorp CWE-427
7.8