CWE-134

High likelihood

Use of Externally-Controlled Format String

Parent: CWE-668 - Exposure of Resource to Wrong Sphere

The product uses a function that accepts a format string as an argument, but the format string originates from an external source.

389 vulnerabilities with CWE-134
CVE-2008-3871
UltraISO < 9.3.3.2685 - Remote Code Execution via DAA or ISZ Filename Format String
CVE-2008-6520
Xitami Web Server 2.5c2 - Remote Code Execution via SSI Filter Format String
CVE-2008-6519
Xitami 2.2a-2.5c2 - Remote Code Execution via Format String in LRWP Request
CVE-2008-6441
Unreal Engine - Remote Code Execution via Format String Vulnerability
CVE-2008-6395
3Com Wireless 8760 Dual Radio - Denial of Service via Malformed HTTP POST Request
CVE-2008-5982
BMC PATROL Agent < 3.7.30 - Remote Code Execution via Format String in Version Number
CVE-2008-5660
Vinagre 0.5.x-0.5.1 and 2.x-2.24.1 - Remote Code Execution via Format String in URI or VNC Response
CVE-2008-3963
MySQL 5.0 < 5.0.66, 5.1 < 5.1.26, 6.0 < 6.0.6 - Denial of Service via Empty Bit-String Literal
CVE-2008-3940
HP TCP/IP Services for OpenVMS 5.x - Privilege Escalation
CVE-2008-3734
Ipswitch WS_FTP Home 2007.0.0.2 and WS_FTP Professional 2007.1.0.0 - Format String Vulnerability via FTP Server Greeting
CVE-2008-3533
yelp < 2.24 - Remote Code Execution via Format String in URI Handler
CVE-2008-0965
OpenSolaris < snv_96 - Remote Code Execution via SMB Packet Format String Specifiers
CVE-2008-3116
Snail Game 5th Street - Remote Code Execution via Chat Message Format String
CVE-2008-2310
Mac OS X < 10.5.4 - Remote Code Execution via c++filt Format String
CVE-2008-0963
EMC DiskXtender MediaStor 6.20.060 - Authenticated Remote Code Execution via Format String Vulnerability
CVE-2008-1658
PolicyKit <0.7 - DoS/Code Injection
CVE-2008-1705
IBM solidDB 06.00.1018 - Remote Code Execution via Format String Specifiers in Logging Function
CVE-2008-1401
MG-SOFT Net Inspector <6.5.0.828 - RCE
CVE-2008-1333
Asterisk Open Source <1.6.0-beta6 - RCE
CVE-2008-0989
Apple Mac OS X 10.5.2 - Local Format String Vulnerability via mDNSResponderHelper
CVE-2008-1357
McAfee Common Management Agent <= 3.6.0.574 - Remote Code Execution via Format String in AgentWakeup Request
CVE-2008-1206
Linux Kiss Server 1.2 - Format String
CVE-2008-0072
Evolution < 2.12.3 - Remote Code Execution via Encrypted Message Format String
CVE-2008-1127
Crysis 1.1.1.5879 - Authenticated Remote Code Execution via Format String in User Name
CVE-2008-1120
Mirabilis ICQ 6 build 6043 - Remote Code Execution via Format String in HTML Code Generation
Details
Vulnerabilities 389
Exploit Likelihood High