Vulnerabilities > Untrusted Search Path

DATE CVE VULNERABILITY TITLE RISK
2017-05-12 CVE-2017-2157 Untrusted Search Path vulnerability in Jpki the Public Certification Service FOR Individuals
Untrusted search path vulnerability in installers for The Public Certification Service for Individuals "The JPKI user's software (for Windows 7 and later)" Ver3.1 and earlier, The Public Certification Service for Individuals "The JPKI user's software (for Windows Vista)", The Public Certification Service for Individuals "The JPKI user's software" Ver2.6 and earlier that were available until April 27, 2017 allows remote attackers to gain privileges via a Trojan horse DLL in an unspecified directory.
local
jpki CWE-426
4.4
2017-05-03 CVE-2017-5236 Untrusted Search Path vulnerability in Rapid7 Appspider PRO
Editions of Rapid7 AppSpider Pro installers prior to version 6.14.060 contain a DLL preloading vulnerability, wherein it is possible for the installer to load a malicious DLL located in the current working directory of the installer.
network
rapid7 CWE-426
6.8
2017-04-28 CVE-2017-2156 Untrusted Search Path vulnerability in Vivaldi Installer FOR Windows
Untrusted search path vulnerability in Vivaldi installer for Windows prior to version 1.7.735.48 allows an attacker to execute arbitrary code via a specially crafted executable file in an unspecified directory.
network
vivaldi CWE-426
6.8
2017-04-28 CVE-2017-2149 Untrusted Search Path vulnerability in Toshiba Flashair
Untrusted search path vulnerability in installers of the software for SDHC/SDXC Memory Card with embedded NFC functionality Software Update Tool V1.00.03 and earlier, SDHC Memory Card with embedded wireless LAN functionality FlashAir Configuration Software V3.0.2 and earlier, SDHC Memory Card with embedded wireless LAN functionality FlashAir Software Update tool (SD-WE series<W-03>) V3.00.01, SDHC Memory Card with embedded wireless LAN functionality FlashAir Software Update tool (SD-WD/WC series<W-02>) V2.00.03 and earlier, SDHC Memory Card with embedded wireless LAN functionality FlashAir Software Update tool (SD-WB/WL series) V1.00.04 and earlier, SDHC Memory Card with embedded TransferJet functionality Configuration Software V1.02 and earlier, SDHC Memory Card with embedded TransferJet functionality Software Update tool V1.00.06 and earlier allows remote attackers to gain privileges via a Trojan horse DLL in an unspecified directory.
network
toshiba CWE-426
critical
9.3
2017-04-28 CVE-2017-2130 Untrusted Search Path vulnerability in Securebrain Phishwall Client 3.7.13/3.7.8.1
Untrusted search path vulnerability in the installer of PhishWall Client Internet Explorer version Ver.
6.8
2017-04-28 CVE-2017-2108 Untrusted Search Path vulnerability in Softbank Primedrive Desktop Application
Untrusted search path vulnerability in PrimeDrive Desktop Application 1.4.3 and earlier allows remote attackers to gain privileges via a Trojan horse DLL in an unspecified directory.
local
low complexity
softbank CWE-426
7.2
2017-04-28 CVE-2017-2107 Untrusted Search Path vulnerability in Akky 7-Zip32.Dll
Untrusted search path vulnerability in Self-extracting archive files created by 7-ZIP32.DLL 9.22.00.01 and earlier allows remote attackers to gain privileges via a Trojan horse DLL in an unspecified directory.
local
akky CWE-426
6.9
2017-04-21 CVE-2016-4846 Untrusted Search Path vulnerability in Securebrain Phishwall Client
Untrusted search path vulnerability in the installer of PhishWall Client Internet Explorer before 3.7.8.2.
network
securebrain CWE-426
critical
9.3
2017-04-12 CVE-2017-3007 Untrusted Search Path vulnerability in Adobe Creative Cloud
Adobe Thor versions 3.9.5.353 and earlier have a vulnerability in the directory search path used to find resources, related to Creative Cloud desktop applications.
local
low complexity
adobe microsoft CWE-426
4.6
2017-03-15 CVE-2017-6189 Untrusted Search Path vulnerability in Amazon Kindle for PC 1.3.0.30884
Untrusted search path vulnerability in Amazon Kindle for PC before 1.19 allows local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse DLL in the current working directory of the Kindle Setup installer.
local
amazon CWE-426
4.4