Vulnerabilities > Untrusted Search Path

DATE CVE VULNERABILITY TITLE RISK
2022-11-17 CVE-2022-23748 Untrusted Search Path vulnerability in Audinate Dante Application Library
mDNSResponder.exe is vulnerable to DLL Sideloading attack.
local
low complexity
audinate CWE-426
7.8
2022-11-09 CVE-2022-31253 Untrusted Search Path vulnerability in Opensuse Openldap2
A Untrusted Search Path vulnerability in openldap2 of openSUSE Factory allows local attackers with control of the ldap user or group to change ownership of arbitrary directory entries to this user/group, leading to escalation to root.
local
low complexity
opensuse CWE-426
7.8
2022-10-28 CVE-2022-3734 Untrusted Search Path vulnerability in Redis
A vulnerability was found in a port or fork of Redis.
network
low complexity
redis CWE-426
critical
9.8
2022-10-27 CVE-2022-0074 Untrusted Search Path vulnerability in Litespeedtech Openlitespeed
Untrusted Search Path vulnerability in LiteSpeed Technologies OpenLiteSpeed Web Server and LiteSpeed Web Server Container allows Privilege Escalation.
network
low complexity
litespeedtech CWE-426
8.8
2022-10-18 CVE-2021-3305 Untrusted Search Path vulnerability in Feishu 3.40.3/3.41.3
Beijing Feishu Technology Co., Ltd Feishu v3.40.3 was discovered to contain an untrusted search path vulnerability.
local
low complexity
feishu CWE-426
7.8
2022-09-26 CVE-2022-39245 Untrusted Search Path vulnerability in Makedeb Mist
Mist is the command-line interface for the makedeb Package Repository.
local
low complexity
makedeb CWE-426
7.8
2022-07-12 CVE-2022-22047 Untrusted Search Path vulnerability in Microsoft products
Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability
local
low complexity
microsoft CWE-426
7.8
2022-07-12 CVE-2022-31012 Untrusted Search Path vulnerability in Gitforwindows GIT 2.34.1
Git for Windows is a fork of Git that contains Windows-specific patches.
4.4
2022-07-12 CVE-2021-36666 Untrusted Search Path vulnerability in Druva Insync Client
An issue was discovered in Druva 6.9.0 for MacOS, allows attackers to gain escalated local privileges via the inSyncDecommission.
local
low complexity
druva CWE-426
7.8
2022-05-20 CVE-2022-28964 Untrusted Search Path vulnerability in Avast Premium Security 19.8.2393/20.8.2429
An arbitrary file write vulnerability in Avast Premium Security before v21.11.2500 (build 21.11.6809.528) allows attackers to cause a Denial of Service (DoS) via a crafted DLL file.
local
avast CWE-426
5.4