İçeriğe atla
Noroxi

CWE-426 · 659 kayıt

Untrusted Search Path

Bu sınıftaki CVE’ler

658 kayıt

  • CVE-2012-1854
    67Bu hafta

    Untrusted search path vulnerability in VBE6.dll in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Microsoft Visual Basi

    YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %21

    microsoft · office10 Tem 2012

  • CVE-2022-22047
    67Bu hafta

    Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability

    YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %19

    microsoft · windows 10 150712 Tem 2022

  • CVE-2015-0096
    58Planlayın

    Untrusted search path vulnerability in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 S

    KritikCVSS 9,3SilahlaştırılmışEPSS %71

    microsoft · windows 711 Mar 2015

  • CVE-2023-30330
    41Planlayın

    SoftExpert (SE) Excellence Suite 2.x versions before 2.1.3 is vulnerable to Local File Inclusion in the function /se/v42300/generic/gn_defau

    KritikCVSS 9,8Kavram kanıtıEPSS %6

    softexpert · excellence suite11 May 2023

  • CVE-2016-10009
    40Planlayın

    Untrusted search path vulnerability in ssh-agent.c in ssh-agent in OpenSSH before 7.4 allows remote attackers to execute arbitrary local PKC

    YüksekCVSS 7,3Kavram kanıtıEPSS %37

    openbsd · openssh4 Oca 2017

  • CVE-2016-0016
    40Planlayın

    Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Win

    YüksekCVSS 7,8Kavram kanıtıEPSS %30

    microsoft · windows 1013 Oca 2016

  • CVE-2011-2019
    40Planlayın

    Untrusted search path vulnerability in Microsoft Internet Explorer 9 on Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 allows

    KritikCVSS 9,3İstismar yokEPSS %11

    microsoft · internet explorer13 Ara 2011

  • CVE-2018-19486
    40Planlayın

    Git before 2.19.2 on Linux and UNIX executes commands from the current working directory (as if '.' were at the end of $PATH) in certain cas

    KritikCVSS 9,8İstismar yokEPSS %4

    linux · linux kernel23 Kas 2018

  • CVE-2020-15801
    40Planlayın

    In Python 3.8.4, sys.path restrictions specified in a python38._pth file are ignored, allowing code to be loaded from arbitrary locations.

    KritikCVSS 9,8İstismar yokEPSS %3

    python · python16 Tem 2020

  • CVE-2011-4125
    40Planlayın

    A untrusted search path issue was found in Calibre at devices/linux_mount_helper.c leading to the ability of unprivileged users to execute a

    KritikCVSS 9,8İstismar yokEPSS %2

    calibre-ebook · calibre26 Eki 2021

  • CVE-2022-26184
    40Planlayın

    Poetry v1.1.9 and below was discovered to contain an untrusted search path which causes the application to behave in unexpected ways when us

    KritikCVSS 9,8İstismar yokEPSS %2

    python-poetry · poetry21 Mar 2022

  • CVE-2017-12414
    39İzleyin

    Format Factory 4.1.0 has a DLL Hijacking Vulnerability because an untrusted search path is used for msimg32.dll, WindowsCodecs.dll, and dwma

    KritikCVSS 9,8İstismar yokEPSS %2

    pcfreetime · format factory3 Ağu 2017

  • CVE-2017-2225
    39İzleyin

    Untrusted search path vulnerability in EbidSettingChecker.exe (version 1.0.0.0) allows an attacker to gain privileges via a Trojan horse DLL

    KritikCVSS 9,8İstismar yokEPSS %1

    mext · ebidsettingchecker7 Tem 2017

  • CVE-2023-26036
    39İzleyin

    ZoneMinder contains Local File Inclusion vulnerability

    KritikCVSS 9,8İstismar yokEPSS %1

    zoneminder · zoneminder24 Şub 2023

  • CVE-2024-35260
    39İzleyin

    Microsoft Dataverse Remote Code Execution Vulnerability

    KritikCVSS 9,8İstismar yokEPSS %1

    microsoft · power platform27 Haz 2024

  • CVE-2022-3734
    39İzleyin

    Redis on Windows dbghelp.dll uncontrolled search path

    KritikCVSS 9,8İstismar yokEPSS %1

    redis · redis28 Eki 2022

  • CVE-2024-38462
    39İzleyin

    iRODS before 4.3.2 provides an msiSendMail function with a problematic dependency on the mail binary, such as in the mailMS.cpp#L94-L106 ref

    KritikCVSS 9,8İstismar yokEPSS %1

    irods · irods16 Haz 2024

  • CVE-2025-26155
    39İzleyin

    NCP Secure Enterprise Client 13.18 and NCP Secure Entry Windows Client 13.19 have an Untrusted Search Path vulnerability.

    KritikCVSS 9,8İstismar yokEPSS %1

    ncp-e · ncp secure entry client26 Kas 2025

  • CVE-2026-78155
    39İzleyin

    Untrusted Search Path in StackGres

    KritikCVSS 9,9İstismar yokEPSS %1

    ongres · stackgres23 Ağu 2026

  • CVE-2012-2040
    38İzleyin

    Untrusted search path vulnerability in the installer in Adobe Flash Player before 10.3.183.20 and 11.x before 11.3.300.257 on Windows and Ma

    KritikCVSS 9,3İstismar yokEPSS %4

    adobe · flash player8 Haz 2012

  • CVE-2010-4833
    38İzleyin

    Untrusted search path vulnerability in modules/engines/ms-windows/xp_theme.c in GTK+ before 2.24.0 allows local users to gain privileges via

    KritikCVSS 9,3İstismar yokEPSS %2

    gnome · gtk6 Eyl 2011

  • CVE-2011-5158
    38İzleyin

    Multiple untrusted search path vulnerabilities in the DMTGUI2.EXE and DvInesLogFileViewer.Exe components in DATEV Grundpaket Basis CD23.20 a

    KritikCVSS 9,3İstismar yokEPSS %2

    datev · grundpaket basis7 Eyl 2012

  • CVE-2018-12589
    37İzleyin

    Polaris Office 2017 8.1 allows attackers to execute arbitrary code via a Trojan horse puiframeworkproresenu.dll file in the current working

    YüksekCVSS 7,8Kavram kanıtıEPSS %20

    polarisoffice · polaris office 201728 Haz 2018

  • CVE-2024-26198
    37İzleyin

    Microsoft Exchange Server Remote Code Execution Vulnerability

    YüksekCVSS 8,8İstismar yokEPSS %7

    microsoft · exchange server12 Mar 2024

  • CVE-2025-23266
    37İzleyin

    NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, where an attacker could

    KritikCVSS 9,0Kavram kanıtıEPSS %3

    nvidia · container toolkit17 Tem 2025

Tüm zafiyet sınıfları