Vulnerabilities > Untrusted Search Path

DATE CVE VULNERABILITY TITLE RISK
2021-08-03 CVE-2021-21562 Untrusted Search Path vulnerability in Dell EMC Powerscale Onefs
Dell EMC PowerScale OneFS contains an untrusted search path vulnerability.
local
low complexity
dell CWE-426
4.4
2021-07-21 CVE-2021-25698 Untrusted Search Path vulnerability in Teradici Pcoip Standard Agent
The OpenSSL component of the Teradici PCoIP Standard Agent prior to version 21.07.0 was compiled without the no-autoload-config option, which allowed an attacker to elevate to the privileges of the running process via placing a specially crafted dll in a build configuration directory.
local
low complexity
teradici CWE-426
7.8
2021-07-21 CVE-2021-25699 Untrusted Search Path vulnerability in Teradici Pcoip Client 19.08.3
The OpenSSL component of the Teradici PCoIP Software Client prior to version 21.07.0 was compiled without the no-autoload-config option, which allowed an attacker to elevate to the privileges of the running process via placing a specially crafted dll in a build configuration directory.
local
low complexity
teradici CWE-426
7.8
2021-04-30 CVE-2021-26807 Untrusted Search Path vulnerability in GOG Galaxy 2.0.28.9
GalaxyClient version 2.0.28.9 loads unsigned DLLs such as zlib1.dll, libgcc_s_dw2-1.dll and libwinpthread-1.dll from PATH, which allows an attacker to potentially run code locally through unsigned DLL loading.
local
low complexity
gog CWE-426
7.8
2021-04-09 CVE-2021-29221 Untrusted Search Path vulnerability in Erlang Erlang/Otp
A local privilege escalation vulnerability was discovered in Erlang/OTP prior to version 23.2.3.
local
high complexity
erlang CWE-426
7.0
2021-04-08 CVE-2021-3146 Untrusted Search Path vulnerability in Dolby Audio X2
The Dolby Audio X2 (DAX2) API service before 0.8.8.90 on Windows allows local users to gain privileges.
local
low complexity
dolby CWE-426
7.8
2021-03-26 CVE-2021-28249 Untrusted Search Path vulnerability in CA Ehealth Performance Manager
CA eHealth Performance Manager through 6.3.2.12 is affected by Privilege Escalation via a Dynamically Linked Shared Object Library.
local
low complexity
ca CWE-426
8.8
2021-03-26 CVE-2021-28246 Untrusted Search Path vulnerability in Broadcom Ehealth
CA eHealth Performance Manager through 6.3.2.12 is affected by Privilege Escalation via a Dynamically Linked Shared Object Library.
local
low complexity
broadcom CWE-426
7.8
2021-03-12 CVE-2021-21078 Untrusted Search Path vulnerability in Adobe Creative Cloud Desktop Application
Adobe Creative Cloud Desktop Application version 5.3 (and earlier) is affected by an Unquoted Service Path vulnerability in CCXProcess that could allow an attacker to achieve arbitrary code execution in the process of the current user.
local
low complexity
adobe CWE-426
6.5
2021-02-12 CVE-2021-22980 Untrusted Search Path vulnerability in F5 Big-Ip Access Policy Manager
In Edge Client version 7.2.x before 7.2.1.1, 7.1.9.x before 7.1.9.8, and 7.1.x-7.1.8.x before 7.1.8.5, an untrusted search path vulnerability in the BIG-IP APM Client Troubleshooting Utility (CTU) for Windows could allow an attacker to load a malicious DLL library from its current directory.
local
low complexity
f5 CWE-426
7.8