CWE-426 不可信的搜索路径 类弱点 249 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-426 属于不信任搜索路径漏洞,指程序使用外部提供的路径查找关键资源,导致可能访问不受控的文件。攻击者常通过操纵环境变量或配置,将恶意程序或数据注入搜索路径,从而执行任意代码或窃取敏感信息。开发者应避免使用动态搜索路径,改用硬编码的绝对路径,或严格验证路径来源及权限,确保仅加载受信任目录下的资源,以阻断攻击链。
#define DIR "/restricted/directory" char cmd[500]; sprintf(cmd, "ls -l %480s", DIR); /* Raise privileges to those needed for accessing DIR. */ RaisePrivileges(...); system(cmd); DropPrivileges(...); ...
The user sets the PATH to reference a directory under the attacker's control, such as "/my/dir/". The attacker creates a malicious program called "ls", and puts that program in /my/dir The user executes the program. When system() is executed, the shell consults the PATH to find the ls program The program finds the attacker's malicious program, "/my/dir/ls". It doesn't find "/bin/ls" because PATH does not contain "/bin/". The program executes the attacker's malicious program with the raised privileges.
... String home = System.getProperty("APPHOME"); String cmd = home + INITCMD; java.lang.Runtime.getRuntime().exec(cmd); ...
| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2022-3734 | Redis Labs Redis 代码问题漏洞 — Redis | 6.3 | Medium | 2022-10-28 |
| CVE-2022-0074 | Litespeed Technologie OpenLiteSpeed 代码问题漏洞 — OpenLiteSpeed Web Server | 8.8 | High | 2022-10-27 |
| CVE-2022-36070 | Poetry 代码问题漏洞 — poetry | 7.3 | High | 2022-09-07 |
| CVE-2022-31012 | Git for Windows 代码问题漏洞 — git | 8.2 | High | 2022-07-12 |
| CVE-2017-20123 | Sparklabs Viscosity 代码问题漏洞 — Viscosity | 8.8 | High | 2022-06-30 |
| CVE-2022-24826 | Git Lfs 代码问题漏洞 — git-lfs | 9.8 | Critical | 2022-04-19 |
| CVE-2022-0014 | Palo Alto Networks Cortex XDR 代码问题漏洞 — Cortex XDR Agent | 6.7 | Medium | 2022-01-12 |
| CVE-2011-4125 | Calibre 代码问题漏洞 — Calibre | 9.8 | - | 2021-10-27 |
| CVE-2021-36297 | SupportAssist Client 代码问题漏洞 — SupportAssist Client Consumer | 7.8 | High | 2021-09-28 |
| CVE-2021-31841 | Mcafee McAfee Agent 数据伪造问题漏洞 — McAfee Agent for Windows | 8.2 | High | 2021-09-22 |
| CVE-2021-37617 | Nextcloud Desktop Client 代码问题漏洞 — security-advisories | 7.3 | High | 2021-08-18 |
| CVE-2021-21562 | Dell Technologies Dell PowerScale OneFS代码问题漏洞 — PowerScale OneFS | 4.4 | Medium | 2021-08-02 |
| CVE-2021-25698 | Teradici PCoIP Standard Agent代码问题漏洞 — - PCoIP Standard Agent - PCoIP Graphics Agent - PCoIP Software Client | 7.8 | - | 2021-07-21 |
| CVE-2021-25699 | Teradici PCoIP Software Agent 代码问题漏洞 — - PCoIP Standard Agent - PCoIP Graphics Agent - PCoIP Software Client | 7.8 | - | 2021-07-21 |
| CVE-2021-21078 | Adobe Creative Cloud Desktop Application 代码问题漏洞 — Creative Cloud (desktop component) | 7.3 | - | 2021-03-12 |
| CVE-2021-21055 | Adobe Dreamweaver 代码问题漏洞 — Dreamweaver | 6.2 | Medium | 2021-02-11 |
| CVE-2021-21237 | Git Lfs 代码问题漏洞 — git-lfs | 7.2 | High | 2021-01-15 |
| CVE-2020-5144 | SonicWall Global VPN client 代码问题漏洞 — SonicWall Global VPN Client | 8.4 | - | 2020-10-28 |
| CVE-2020-6023 | Check Point ZoneAlarm 代码问题漏洞 — Check Point ZoneAlarm | 7.8 | - | 2020-10-27 |
| CVE-2020-8338 | Lenovo Diagnostics 代码问题漏洞 — Diagnostics | 7.8 | High | 2020-10-14 |
| CVE-2020-10733 | PostgreSQL 代码问题漏洞 — PostgreSQL | 7.8 | - | 2020-09-16 |
| CVE-2020-7315 | McAfee Agent 代码问题漏洞 — MA for Windows | 6.0 | Medium | 2020-09-10 |
| CVE-2020-8317 | Lenovo Drivers Management 代码问题漏洞 — Drivers Management | 7.3 | High | 2020-07-24 |
| CVE-2020-7279 | McAfee Host Intrusion Prevention System 代码问题漏洞 — McAfee Host Intrusion Prevention System (Host IPS) for Windows | 4.6 | Medium | 2020-06-10 |
| CVE-2019-6196 | Lenovo安装包代码问题漏洞 — Installation Packages | 6.7 | Medium | 2020-06-09 |
| CVE-2019-6173 | Lenovo安装包代码问题漏洞 — Installation Packages | 6.7 | Medium | 2020-06-09 |
| CVE-2020-7490 | Schneider Electric Vijeo Designer Basic和Vijeo Designer 代码问题漏洞 — Vijeo Designer Basic (V1.1 HotFix 15 and prior) and Vijeo Designer (V6.9 SP9 and prior) | 7.8 | - | 2020-04-22 |
| CVE-2020-8096 | Bitdefender High-Level Antimalware SDK 代码问题漏洞 — High-Level Antimalware SDK for Windows | 6.3 | Medium | 2020-04-07 |
| CVE-2020-7476 | Schneider Electric ZigBee Installation Toolkit 代码问题漏洞 — ZigBee Installation Toolkit (Versions prior to 1.0.1) | 7.8 | - | 2020-03-23 |
| CVE-2019-17099 | Bitdefender Endpoint Security Tool 代码问题漏洞 — EPSecurityService.exe | 5.3 | Medium | 2020-01-27 |
CWE-426(不可信的搜索路径) 是常见的弱点类别,本平台收录该类弱点关联的 249 条 CVE 漏洞。