CWE-134

High likelihood

Use of Externally-Controlled Format String

Parent: CWE-668 - Exposure of Resource to Wrong Sphere

The product uses a function that accepts a format string as an argument, but the format string originates from an external source.

389 vulnerabilities with CWE-134
CVE-2008-1055
SurgeMail < 38k4 and WebMail < 3.1s - Remote Code Execution via Format String in Page Parameter
CVE-2008-0945
Ipswitch IM Server < 2.0.8.1 - Authenticated Denial of Service via Format String in IP Address Field
CVE-2008-0764
Larson Network Print Server < 9.4.2 - Remote Code Execution via Format String in USEP Command
CVE-2008-0755
cyanPrintIP and Opium4 OPI Server < 4.10.1030 - Remote Code Execution via Format String in LPD Queue Name
CVE-2007-6625
Novell Identity Manager 3.5.1 - Denial of Service via Format String in Platform Service Process
CVE-2007-4708
Apple Mac OS X 10.4.11 - Remote Code Execution via Address Book URL Handler Format String
CVE-2007-6273
SonicWALL GLobal VPN Client <4.0.0.810 - RCE
CVE-2007-6183
Ruby-GNOME2 < 0.17.0 - Use-After-Free in mdiag_initialize
CVE-2007-3880
Sun Remote Services Net Connect 3.2.3-3.2.4 - Local Privilege Escalation via Format String in srsexec
CVE-2007-5396
Miranda IM 0.7.1 - Remote Code Execution via Format String in Yahoo Buddy Authorization
CVE-2007-5825
Firefly Media Server <= 0.2.4 - Remote Code Execution via Format String in HTTP Authorization Header
CVE-2007-5740
Perdition Mail Retrieval Proxy < 1.17 - Remote Code Execution via IMAP Tag Format String Injection
CVE-2007-5545
TIBCO SmartPGM FX - Remote Code Execution via Format String Specifiers
CVE-2007-5561
Oracle Enterprise Grid Console Server 10.2.0.1 - Remote Code Execution via Format String in HTTP URI
CVE-2007-3675
Kaspersky Online Scanner < 5.0.93 - Remote Code Execution via Format String Vulnerability
CVE-2007-3917
Wesnoth 1.2.x < 1.2.7 and 1.3.x < 1.3.9 - Denial of Service via Multiplayer Message Truncation
CVE-2007-5262
Battlefront Dropteam < 1.3.3 - Remote Code Execution via Format String in Packet 0x01
CVE-2007-5265
dawn_of_time < 1.69s_beta4 - Remote Code Execution via Format String in Username or Password
CVE-2007-5247
First Encounter Assault Recon < 1.08 - Remote Code Execution via Format String in PB_Y or PB_U Packets
CVE-2007-5248
Doom 3 < 1.3.1, Quake 4 < 1.4.2, Prey < 1.3 - Remote Code Execution via Format String in PB_Y/PB_U Packets
CVE-2007-5184
smbftpd 0.96 - Remote Code Execution via Format String in Directory Name
CVE-2007-4832
CellFactor Revolution < 1.03 - Remote Code Execution via Format String in Nickname
CVE-2007-4754
Alien Arena 2007 < 6.10 - Denial of Service via Format String in Nickname
CVE-2007-4550
ALPass 2.7 English and 3.02 Korean - Remote Code Execution via Format String Specifiers in APW File
CVE-2007-4273
IBM DB2 Universal Database < 8.0 and < 9.1 - Local Code Execution via Format String Attack
Details
Vulnerabilities 389
Exploit Likelihood High