Vulnerabilities > Untrusted Search Path

DATE CVE VULNERABILITY TITLE RISK
2017-11-16 CVE-2017-12313 Untrusted Search Path vulnerability in Cisco Packet Tracer
An untrusted search path (aka DLL Preload) vulnerability in the Cisco Network Academy Packet Tracer software could allow an authenticated, local attacker to execute arbitrary code via DLL hijacking if a local user with administrative privileges executes the installer in the current working directory where a crafted DLL has been placed by an attacker.
local
low complexity
cisco CWE-426
6.7
2017-11-16 CVE-2017-12312 Untrusted Search Path vulnerability in Cisco Advanced Malware Protection for Endpoints 3.1.0
An untrusted search path (aka DLL Preloading) vulnerability in the Cisco Immunet antimalware installer could allow an authenticated, local attacker to execute arbitrary code via DLL hijacking if a local user with administrative privileges executes the installer in the current working directory where a crafted DLL has been placed by an attacker.
local
low complexity
cisco CWE-426
6.7
2017-11-13 CVE-2017-10885 Untrusted Search Path vulnerability in Sbisec Hyper SBI 2.2
Untrusted search path vulnerability in HYPER SBI Ver.
local
low complexity
sbisec CWE-426
7.8
2017-11-13 CVE-2016-6803 Untrusted Search Path vulnerability in Apache Openoffice
An installer defect known as an "unquoted Windows search path vulnerability" affected the Apache OpenOffice before 4.1.3 installers for Windows.
local
low complexity
apache CWE-426
7.8
2017-11-02 CVE-2017-10825 Untrusted Search Path vulnerability in Flets-W Flets Easy Setup Tool 1.2.0
Untrusted search path vulnerability in Installer of Flets Easy Setup Tool Ver1.2.0 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
local
low complexity
flets-w CWE-426
7.8
2017-11-01 CVE-2017-15566 Untrusted Search Path vulnerability in Schedmd Slurm
Insecure SPANK environment variable handling exists in SchedMD Slurm before 16.05.11, 17.x before 17.02.9, and 17.11.x before 17.11.0rc2, allowing privilege escalation to root during Prolog or Epilog execution.
local
low complexity
schedmd CWE-426
7.8
2017-10-26 CVE-2017-5996 Untrusted Search Path vulnerability in Beyondtrust Remote Support
The agent in Bomgar Remote Support 15.2.x before 15.2.3, 16.1.x before 16.1.5, and 16.2.x before 16.2.4 allows DLL hijacking because of weak %SYSTEMDRIVE%\ProgramData permissions.
local
low complexity
beyondtrust CWE-426
7.8
2017-10-12 CVE-2017-10865 Untrusted Search Path vulnerability in Hitachi-Solutions Confidential File Decryption
Untrusted search path vulnerability in HIBUN Confidential File Decryption program prior to 10.50.0.5 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
local
low complexity
hitachi-solutions CWE-426
7.8
2017-10-12 CVE-2017-10864 Untrusted Search Path vulnerability in Hitachi-Solutions Confidential File Viewer
Untrusted search path vulnerability in Installer of HIBUN Confidential File Viewer prior to 11.20.0001 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
local
low complexity
hitachi-solutions CWE-426
7.8
2017-10-12 CVE-2017-10863 Untrusted Search Path vulnerability in Hitachi-Solutions Confidential File Decryption
Untrusted search path vulnerability in HIBUN Confidential File Decryption program prior to 10.50.0.5 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
local
low complexity
hitachi-solutions CWE-426
7.8