Vulnerabilities > Untrusted Search Path

DATE CVE VULNERABILITY TITLE RISK
2023-07-11 CVE-2023-36536 Untrusted Search Path vulnerability in Zoom Rooms
Untrusted search path in the installer for Zoom Rooms for Windows before version 5.15.0 may allow an authenticated user to enable an escalation of privilege via local access.
local
low complexity
zoom CWE-426
7.8
2023-06-26 CVE-2023-34144 Untrusted Search Path vulnerability in Trendmicro Apex ONE 14.0.10349/2019
An untrusted search path vulnerability in the Trend Micro Apex One and Apex One as a Service security agent could allow a local attacker to escalate their privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. This is a similar, but not identical vulnerability as CVE-2023-34145.
local
low complexity
trendmicro CWE-426
7.8
2023-06-26 CVE-2023-34145 Untrusted Search Path vulnerability in Trendmicro Apex ONE 14.0.10349/2019
An untrusted search path vulnerability in the Trend Micro Apex One and Apex One as a Service security agent could allow a local attacker to escalate their privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. This is a similar, but not identical vulnerability as CVE-2023-34144.
local
low complexity
trendmicro CWE-426
7.8
2023-04-18 CVE-2023-28143 Untrusted Search Path vulnerability in Qualys Cloud Agent
Qualys Cloud Agent for macOS (versions 2.5.1-75 before 3.7) installer allows a local escalation of privilege bounded only to the time of installation and only on older macOSX (macOS 10.15 and older) versions. Attackers may exploit incorrect file permissions to give them ROOT command execution privileges on the host.
local
high complexity
qualys CWE-426
7.0
2023-03-22 CVE-2023-26358 Untrusted Search Path vulnerability in Adobe Creative Cloud
Creative Cloud version 5.9.1 (and earlier) is affected by an Untrusted Search Path vulnerability that might allow attackers to execute their own programs, access unauthorized data files, or modify configuration in unexpected ways.
local
low complexity
adobe CWE-426
7.8
2023-02-25 CVE-2023-26036 Untrusted Search Path vulnerability in Zoneminder
ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras.
network
low complexity
zoneminder CWE-426
critical
9.8
2023-02-25 CVE-2023-26038 Untrusted Search Path vulnerability in Zoneminder
ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras.
network
low complexity
zoneminder CWE-426
6.5
2023-02-23 CVE-2023-23920 Untrusted Search Path vulnerability in multiple products
An untrusted search path vulnerability exists in Node.js.
local
low complexity
nodejs debian CWE-426
4.2
2023-02-15 CVE-2023-22368 Untrusted Search Path vulnerability in Elecom Camera Assistant and Quickfiledealer
Untrusted search path vulnerability in ELECOM Camera Assistant 1.00 and QuickFileDealer Ver.1.2.1 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
local
low complexity
elecom CWE-426
7.8
2023-02-14 CVE-2023-22743 Untrusted Search Path vulnerability in GIT for Windows Project GIT for Windows
Git for Windows is the Windows port of the revision control system Git.
local
low complexity
git-for-windows-project CWE-426
7.3