CWE-134
High likelihoodUse of Externally-Controlled Format String
The product uses a function that accepts a format string as an argument, but the format string originates from an external source.
388 vulnerabilities with CWE-134
CVE-2013-5135
Apple Remote Desktop < 3.5.4 - Remote Code Execution via VNC Username Format String
CVE-2013-4389
Ruby on Rails 3.0.0-3.2.14 - Denial of Service via Format String in Action Mailer Log Subscriber
CVE-2013-4258
Network Audio System 1.9.3 - Format String Vulnerability in osLogMsg Function
CVE-2013-4147
YARD RADIUS 1.1.2 - Format String Vulnerability in Log and Version Functions
CVE-2013-2852
Linux kernel <3.9.4 - Privilege Escalation
CVE-2013-2851
Linux kernel <3.9.4 - Privilege Escalation
CVE-2013-3560
Debian Linux - Format String Vulnerability
CVE-2013-0929
EMC AlphaStor 4.0 - Remote Code Execution via Format String in rrobotd.exe
CVE-2012-10055
CRITICAL
ComSndFTP FTP Server <1.3.7 Beta - Code Injection
CVE-2012-0824
CRITICAL
gnusound 0.7.5 - Format String Vulnerability
CVSS 9.8
CVE-2012-4426
mcrypt < 2.6.8 - Format String Vulnerability in errors.c and mcrypt.c
CVE-2012-3569
VMware OVF Tool 2.1 - Remote Code Execution via Crafted OVF File
CVE-2012-1152
YAML::LibYAML 0.38 - Denial of Service via Format String Specifiers in Error Reporting
CVE-2012-1151
Perl < 2.18.1 - Format String Vulnerability
CVE-2012-2288
EMC NetWorker 7.6.3-7.6.4 and 8.0 - Remote Code Execution via nsrd RPC Service Format String
CVE-2012-1851
Windows Print Spooler Service - Remote Code Execution via Format String Vulnerability
CVE-2012-2090
FlightGear and SimGear < 2.6.0 - Format String Vulnerability via Aircraft XML Model
CVE-2012-2369
pidgin-otr < 3.2.0 - Remote Code Execution via Format String in Log Message
CVE-2012-0646
iPhone OS < 5.1 - Remote Code Execution via VPN Racoon Configuration File
CVE-2012-0242
Advantech WebAccess < 7.0 - Remote Code Execution via Format String Specifiers
CVE-2012-0809
sudo 1.8.0-1.8.3p1 - Local Use-After-Free via Format String in sudo_debug
CVE-2011-10029
HIGH
Solar FTP Server < 2.1.1 - Denial of Service via USER Command Format String
CVE-2011-1588
HIGH
Thunar < 1.3.1 - Denial of Service via Format String Error in File Name Handling
CVSS 7.8
CVE-2011-4930
Condor 7.2.0-7.6.4 - Format String Vulnerability via Job Hold Reason or Filename
CVE-2011-4357
Clearsilver < 0.10.5 - Format String Vulnerability via Python CGI Kit Error Handling
Details
Vulnerabilities
388
Exploit Likelihood
High