Vulnerabilities > Untrusted Search Path

DATE CVE VULNERABILITY TITLE RISK
2021-02-11 CVE-2021-21055 Untrusted Search Path vulnerability in Adobe Dreamweaver
Adobe Dreamweaver versions 21.0 (and earlier) and 20.2 (and earlier) is affected by an untrusted search path vulnerability that could result in information disclosure.
high complexity
adobe CWE-426
6.2
2021-01-15 CVE-2021-21237 Untrusted Search Path vulnerability in GIT Large File Storage Project GIT Large File Storage
Git LFS is a command line extension for managing large files with Git.
7.8
2021-01-13 CVE-2020-35686 Untrusted Search Path vulnerability in Soundresearch Dchu Model Software Component Modules 2.0.9.17
The SECOMN service in Sound Research DCHU model software component modules (APO) through 2.0.9.17, delivered on HP Windows 10 computers, may allow escalation of privilege via a fake DLL.
local
low complexity
soundresearch CWE-426
7.8
2020-12-15 CVE-2020-29482 Untrusted Search Path vulnerability in multiple products
An issue was discovered in Xen through 4.14.x.
local
low complexity
xen debian fedoraproject CWE-426
6.0
2020-11-20 CVE-2020-4739 Untrusted Search Path vulnerability in IBM DB2
IBM DB2 Accessories Suite for Linux, UNIX, and Windows, DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local authenticated attacker to execute arbitrary code on the system, caused by DLL search order hijacking vulnerability in Microsoft Windows client.
local
low complexity
ibm CWE-426
7.8
2020-11-18 CVE-2020-27695 Untrusted Search Path vulnerability in Trendmicro products
Trend Micro Security 2020 (Consumer) contains a vulnerability in the installer package that could be exploited by placing a malicious DLL in a local directory which can lead to obtaining administrative privileges during the installation of the product.
local
low complexity
trendmicro CWE-426
7.8
2020-11-02 CVE-2020-6014 Untrusted Search Path vulnerability in Checkpoint Endpoint Security E80.96/E81.30
Check Point Endpoint Security Client for Windows, with Anti-Bot or Threat Emulation blades installed, before version E83.20, tries to load a non-existent DLL during a query for the Domain Name.
local
low complexity
checkpoint CWE-426
6.5
2020-10-28 CVE-2020-5144 Untrusted Search Path vulnerability in Sonicwall Global VPN Client 4.10.4.0314
SonicWall Global VPN client version 4.10.4.0314 and earlier allows unprivileged windows user to elevate privileges to SYSTEM through loaded process hijacking vulnerability.
local
low complexity
sonicwall CWE-426
7.8
2020-10-23 CVE-2020-5977 Untrusted Search Path vulnerability in Nvidia Geforce Experience
NVIDIA GeForce Experience, all versions prior to 3.20.5.70, contains a vulnerability in NVIDIA Web Helper NodeJS Web Server in which an uncontrolled search path is used to load a node module, which may lead to code execution, denial of service, escalation of privileges, and information disclosure.
local
low complexity
nvidia CWE-426
7.8
2020-10-14 CVE-2020-8338 Untrusted Search Path vulnerability in Lenovo Diagnostics
A DLL search path vulnerability was reported in Lenovo Diagnostics prior to version 4.35.4 that could allow a user with local access to execute code on the system.
local
low complexity
lenovo CWE-426
7.8