CWE-426 · 658 записей
Untrusted Search Path
CVE этого класса
658 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
67На этой неделе | CVE-2012-1854Готовый эксплойт | Untrusted search path vulnerability in VBE6.dll in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Microsoft Visual Basimicrosoft · office · CWE-426 | Высокая7,8 | KEV | 21,0 % | 10 июл. 2012 г. |
67На этой неделе | CVE-2022-22047Готовый эксплойт | Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1507 · CWE-426 | Высокая7,8 | KEV | 18,8 % | 12 июл. 2022 г. |
58В плане | CVE-2015-0096Готовый эксплойт | Untrusted search path vulnerability in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 Smicrosoft · windows 7 · CWE-426 | Критическая9,3 | — | 71,0 % | 11 мар. 2015 г. |
41В плане | CVE-2023-30330Proof of concept | SoftExpert (SE) Excellence Suite 2.x versions before 2.1.3 is vulnerable to Local File Inclusion in the function /se/v42300/generic/gn_defausoftexpert · excellence suite · CWE-426 | Критическая9,8 | — | 5,9 % | 11 мая 2023 г. |
40В плане | CVE-2016-10009Proof of concept | Untrusted search path vulnerability in ssh-agent.c in ssh-agent in OpenSSH before 7.4 allows remote attackers to execute arbitrary local PKCopenbsd · openssh · CWE-426 | Высокая7,3 | — | 37,4 % | 4 янв. 2017 г. |
40В плане | CVE-2016-0016Proof of concept | Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Winmicrosoft · windows 10 · CWE-426 | Высокая7,8 | — | 29,7 % | 13 янв. 2016 г. |
40В плане | CVE-2011-2019Эксплойта нет | Untrusted search path vulnerability in Microsoft Internet Explorer 9 on Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 allows microsoft · internet explorer · CWE-426 | Критическая9,3 | — | 11,1 % | 13 дек. 2011 г. |
40В плане | CVE-2018-19486Эксплойта нет | Git before 2.19.2 on Linux and UNIX executes commands from the current working directory (as if '.' were at the end of $PATH) in certain caslinux · linux kernel · CWE-426 | Критическая9,8 | — | 4,1 % | 23 нояб. 2018 г. |
40В плане | CVE-2020-15801Эксплойта нет | In Python 3.8.4, sys.path restrictions specified in a python38._pth file are ignored, allowing code to be loaded from arbitrary locations.python · python · CWE-426 | Критическая9,8 | — | 3,5 % | 16 июл. 2020 г. |
40В плане | CVE-2011-4125Эксплойта нет | A untrusted search path issue was found in Calibre at devices/linux_mount_helper.c leading to the ability of unprivileged users to execute acalibre-ebook · calibre · CWE-426 | Критическая9,8 | — | 2,3 % | 26 окт. 2021 г. |
40В плане | CVE-2022-26184Эксплойта нет | Poetry v1.1.9 and below was discovered to contain an untrusted search path which causes the application to behave in unexpected ways when uspython-poetry · poetry · CWE-426 | Критическая9,8 | — | 1,9 % | 21 мар. 2022 г. |
39Наблюдать | CVE-2017-12414Эксплойта нет | Format Factory 4.1.0 has a DLL Hijacking Vulnerability because an untrusted search path is used for msimg32.dll, WindowsCodecs.dll, and dwmapcfreetime · format factory · CWE-426 | Критическая9,8 | — | 1,6 % | 3 авг. 2017 г. |
39Наблюдать | CVE-2017-2225Эксплойта нет | Untrusted search path vulnerability in EbidSettingChecker.exe (version 1.0.0.0) allows an attacker to gain privileges via a Trojan horse DLLmext · ebidsettingchecker · CWE-426 | Критическая9,8 | — | 1,5 % | 7 июл. 2017 г. |
39Наблюдать | CVE-2023-26036Эксплойта нет | ZoneMinder contains Local File Inclusion vulnerabilityzoneminder · zoneminder · CWE-426 | Критическая9,8 | — | 0,9 % | 24 февр. 2023 г. |
39Наблюдать | CVE-2024-35260Эксплойта нет | Microsoft Dataverse Remote Code Execution Vulnerabilitymicrosoft · power platform · CWE-426 | Критическая9,8 | — | 0,8 % | 27 июн. 2024 г. |
39Наблюдать | CVE-2022-3734Эксплойта нет | Redis on Windows dbghelp.dll uncontrolled search pathredis · redis · CWE-426 | Критическая9,8 | — | 0,6 % | 28 окт. 2022 г. |
39Наблюдать | CVE-2024-38462Эксплойта нет | iRODS before 4.3.2 provides an msiSendMail function with a problematic dependency on the mail binary, such as in the mailMS.cpp#L94-L106 refirods · irods · CWE-426 | Критическая9,8 | — | 0,6 % | 16 июн. 2024 г. |
39Наблюдать | CVE-2025-26155Эксплойта нет | NCP Secure Enterprise Client 13.18 and NCP Secure Entry Windows Client 13.19 have an Untrusted Search Path vulnerability.ncp-e · ncp secure entry client · CWE-426 | Критическая9,8 | — | 0,6 % | 26 нояб. 2025 г. |
39Наблюдать | CVE-2026-78155Эксплойта нет | Untrusted Search Path in StackGresongres · stackgres · CWE-426 | Критическая9,9 | — | 0,5 % | 23 авг. 2026 г. |
38Наблюдать | CVE-2012-2040Эксплойта нет | Untrusted search path vulnerability in the installer in Adobe Flash Player before 10.3.183.20 and 11.x before 11.3.300.257 on Windows and Maadobe · flash player · CWE-426 | Критическая9,3 | — | 4,0 % | 8 июн. 2012 г. |
38Наблюдать | CVE-2010-4833Эксплойта нет | Untrusted search path vulnerability in modules/engines/ms-windows/xp_theme.c in GTK+ before 2.24.0 allows local users to gain privileges viagnome · gtk · CWE-426 | Критическая9,3 | — | 2,0 % | 6 сент. 2011 г. |
38Наблюдать | CVE-2011-5158Эксплойта нет | Multiple untrusted search path vulnerabilities in the DMTGUI2.EXE and DvInesLogFileViewer.Exe components in DATEV Grundpaket Basis CD23.20 adatev · grundpaket basis · CWE-426 | Критическая9,3 | — | 2,0 % | 7 сент. 2012 г. |
37Наблюдать | CVE-2018-12589Proof of concept | Polaris Office 2017 8.1 allows attackers to execute arbitrary code via a Trojan horse puiframeworkproresenu.dll file in the current working polarisoffice · polaris office 2017 · CWE-426 | Высокая7,8 | — | 20,1 % | 28 июн. 2018 г. |
37Наблюдать | CVE-2024-26198Эксплойта нет | Microsoft Exchange Server Remote Code Execution Vulnerabilitymicrosoft · exchange server · CWE-426 | Высокая8,8 | — | 6,8 % | 12 мар. 2024 г. |
37Наблюдать | CVE-2025-23266Proof of concept | NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, where an attacker could nvidia · container toolkit · CWE-426 | Критическая9,0 | — | 3,2 % | 17 июл. 2025 г. |
- CVE-2012-185467На этой неделе
Untrusted search path vulnerability in VBE6.dll in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Microsoft Visual Basi
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 21 %microsoft · office10 июл. 2012 г.
- CVE-2022-2204767На этой неделе
Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 19 %microsoft · windows 10 150712 июл. 2022 г.
- CVE-2015-009658В плане
Untrusted search path vulnerability in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 S
КритическаяCVSS 9,3Готовый эксплойтEPSS 71 %microsoft · windows 711 мар. 2015 г.
- CVE-2023-3033041В плане
SoftExpert (SE) Excellence Suite 2.x versions before 2.1.3 is vulnerable to Local File Inclusion in the function /se/v42300/generic/gn_defau
КритическаяCVSS 9,8Proof of conceptEPSS 6 %softexpert · excellence suite11 мая 2023 г.
- CVE-2016-1000940В плане
Untrusted search path vulnerability in ssh-agent.c in ssh-agent in OpenSSH before 7.4 allows remote attackers to execute arbitrary local PKC
ВысокаяCVSS 7,3Proof of conceptEPSS 37 %openbsd · openssh4 янв. 2017 г.
- CVE-2016-001640В плане
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Win
ВысокаяCVSS 7,8Proof of conceptEPSS 30 %microsoft · windows 1013 янв. 2016 г.
- CVE-2011-201940В плане
Untrusted search path vulnerability in Microsoft Internet Explorer 9 on Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 allows
КритическаяCVSS 9,3Эксплойта нетEPSS 11 %microsoft · internet explorer13 дек. 2011 г.
- CVE-2018-1948640В плане
Git before 2.19.2 on Linux and UNIX executes commands from the current working directory (as if '.' were at the end of $PATH) in certain cas
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %linux · linux kernel23 нояб. 2018 г.
- CVE-2020-1580140В плане
In Python 3.8.4, sys.path restrictions specified in a python38._pth file are ignored, allowing code to be loaded from arbitrary locations.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %python · python16 июл. 2020 г.
- CVE-2011-412540В плане
A untrusted search path issue was found in Calibre at devices/linux_mount_helper.c leading to the ability of unprivileged users to execute a
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %calibre-ebook · calibre26 окт. 2021 г.
- CVE-2022-2618440В плане
Poetry v1.1.9 and below was discovered to contain an untrusted search path which causes the application to behave in unexpected ways when us
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %python-poetry · poetry21 мар. 2022 г.
- CVE-2017-1241439Наблюдать
Format Factory 4.1.0 has a DLL Hijacking Vulnerability because an untrusted search path is used for msimg32.dll, WindowsCodecs.dll, and dwma
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %pcfreetime · format factory3 авг. 2017 г.
- CVE-2017-222539Наблюдать
Untrusted search path vulnerability in EbidSettingChecker.exe (version 1.0.0.0) allows an attacker to gain privileges via a Trojan horse DLL
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %mext · ebidsettingchecker7 июл. 2017 г.
- CVE-2023-2603639Наблюдать
ZoneMinder contains Local File Inclusion vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %zoneminder · zoneminder24 февр. 2023 г.
- CVE-2024-3526039Наблюдать
Microsoft Dataverse Remote Code Execution Vulnerability
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %microsoft · power platform27 июн. 2024 г.
- CVE-2022-373439Наблюдать
Redis on Windows dbghelp.dll uncontrolled search path
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %redis · redis28 окт. 2022 г.
- CVE-2024-3846239Наблюдать
iRODS before 4.3.2 provides an msiSendMail function with a problematic dependency on the mail binary, such as in the mailMS.cpp#L94-L106 ref
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %irods · irods16 июн. 2024 г.
- CVE-2025-2615539Наблюдать
NCP Secure Enterprise Client 13.18 and NCP Secure Entry Windows Client 13.19 have an Untrusted Search Path vulnerability.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %ncp-e · ncp secure entry client26 нояб. 2025 г.
- CVE-2026-7815539Наблюдать
Untrusted Search Path in StackGres
КритическаяCVSS 9,9Эксплойта нетEPSS 1 %ongres · stackgres23 авг. 2026 г.
- CVE-2012-204038Наблюдать
Untrusted search path vulnerability in the installer in Adobe Flash Player before 10.3.183.20 and 11.x before 11.3.300.257 on Windows and Ma
КритическаяCVSS 9,3Эксплойта нетEPSS 4 %adobe · flash player8 июн. 2012 г.
- CVE-2010-483338Наблюдать
Untrusted search path vulnerability in modules/engines/ms-windows/xp_theme.c in GTK+ before 2.24.0 allows local users to gain privileges via
КритическаяCVSS 9,3Эксплойта нетEPSS 2 %gnome · gtk6 сент. 2011 г.
- CVE-2011-515838Наблюдать
Multiple untrusted search path vulnerabilities in the DMTGUI2.EXE and DvInesLogFileViewer.Exe components in DATEV Grundpaket Basis CD23.20 a
КритическаяCVSS 9,3Эксплойта нетEPSS 2 %datev · grundpaket basis7 сент. 2012 г.
- CVE-2018-1258937Наблюдать
Polaris Office 2017 8.1 allows attackers to execute arbitrary code via a Trojan horse puiframeworkproresenu.dll file in the current working
ВысокаяCVSS 7,8Proof of conceptEPSS 20 %polarisoffice · polaris office 201728 июн. 2018 г.
- CVE-2024-2619837Наблюдать
Microsoft Exchange Server Remote Code Execution Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 7 %microsoft · exchange server12 мар. 2024 г.
- CVE-2025-2326637Наблюдать
NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, where an attacker could
КритическаяCVSS 9,0Proof of conceptEPSS 3 %nvidia · container toolkit17 июл. 2025 г.