Vulnerabilities > Untrusted Search Path

DATE CVE VULNERABILITY TITLE RISK
2019-04-17 CVE-2019-8453 Untrusted Search Path vulnerability in Checkpoint Zonealarm
Some of the DLLs loaded by Check Point ZoneAlarm up to 15.4.062 are taken from directories where all users have write permissions.
local
low complexity
checkpoint CWE-426
5.5
2019-04-17 CVE-2018-10959 Untrusted Search Path vulnerability in Beyondtrust Avecto Defendpoint
Avecto Defendpoint 4 prior to 4.4 SR6 and 5 prior to 5.1 SR1 has an Untrusted Search Path vulnerability, exploitable by modifying environment variables to trigger automatic elevation of an attacker's process launch.
network
low complexity
beyondtrust CWE-426
7.5
2019-04-10 CVE-2019-6154 Untrusted Search Path vulnerability in Lenovo Bootable USB
A DLL search path vulnerability was reported in Lenovo Bootable Generator, prior to version Mar-2019, that could allow a malicious user with local access to execute code on the system.
local
low complexity
lenovo CWE-426
7.8
2019-04-09 CVE-2019-0809 Untrusted Search Path vulnerability in Microsoft Visual Studio 2017 15.9
A remote code execution vulnerability exists when the Visual Studio C++ Redistributable Installer improperly validates input before loading dynamic link library (DLL) files, aka 'Visual Studio Remote Code Execution Vulnerability'.
local
low complexity
microsoft CWE-426
7.8
2019-03-21 CVE-2018-18913 Untrusted Search Path vulnerability in Opera Browser
Opera before 57.0.3098.106 is vulnerable to a DLL Search Order hijacking attack where an attacker can send a ZIP archive composed of an HTML page along with a malicious DLL to the target.
local
low complexity
opera CWE-426
7.8
2019-03-21 CVE-2019-6724 Untrusted Search Path vulnerability in Barracuda VPN Client 5.0/5.0.2.5
The barracudavpn component of the Barracuda VPN Client prior to version 5.0.2.7 for Linux, macOS, and OpenBSD runs as a privileged process and can allow an unprivileged local attacker to load a malicious library, resulting in arbitrary code executing as root.
local
low complexity
barracuda CWE-426
7.8
2019-03-12 CVE-2019-5922 Untrusted Search Path vulnerability in Microsoft Teams
Untrusted search path vulnerability in The installer of Microsoft Teams allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
local
low complexity
microsoft CWE-426
7.8
2019-03-12 CVE-2019-5921 Untrusted Search Path vulnerability in Microsoft Windows 7
Untrusted search path vulnerability in Windows 7 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
local
low complexity
microsoft CWE-426
7.8
2019-02-13 CVE-2019-5913 Untrusted Search Path vulnerability in Micco Lhmelting
Untrusted search path vulnerability in the installer of LHMelting (LHMelting for Win32 Ver 1.65.3.6 and earlier) allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
local
low complexity
micco CWE-426
7.8
2019-02-13 CVE-2019-5912 Untrusted Search Path vulnerability in Micco Unarj32.Dll
Untrusted search path vulnerability in the installer of UNARJ32.DLL (UNARJ32.DLL for Win32 Ver 1.10.1.25 and earlier) allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
local
low complexity
micco CWE-426
7.8