CWE-134
High likelihoodUse of Externally-Controlled Format String
The product uses a function that accepts a format string as an argument, but the format string originates from an external source.
399 vulnerabilities with CWE-134
CVE-2024-50403
HIGH
QNAP QTS and QuTS hero - Use of Externally-Controlled Format String
CVSS 7.2
CVE-2024-50402
HIGH
QNAP QTS and QuTS hero - Use of Externally-Controlled Format String
CVSS 7.2
CVE-2024-42330
CRITICAL
Zabbix 5.0.0-5.4.6 - Use of Externally-Controlled Format String in HttpRequest
CVSS 9.1
CVE-2024-50401
HIGH
QNAP QTS and QuTS hero - Use of Externally-Controlled Format String
CVSS 7.2
CVE-2024-50400
HIGH
QNAP QTS and QuTS hero - Use of Externally-Controlled Format String
CVSS 7.2
CVE-2024-50399
HIGH
QNAP QTS and QuTS hero - Use of Externally-Controlled Format String
CVSS 7.2
CVE-2024-50398
HIGH
QNAP QTS and QuTS hero - Use of Externally-Controlled Format String
CVSS 7.2
CVE-2024-50397
HIGH
QNAP QTS and QuTS hero - Use of Externally-Controlled Format String
CVSS 8.8
CVE-2024-50396
HIGH
QNAP QTS and QuTS hero - Use of Externally-Controlled Format String
CVSS 8.8
CVE-2024-9129
CRITICAL
Zend Server <9.2 - Format String Injection
CVE-2024-45330
HIGH
Fortinet FortiAnalyzer <7.4.3/<7.2.5 - Privilege Escalation
CVSS 7.2
CVE-2024-39529
HIGH
Juniper Junos OS DoS via DNS DGA Detection
CVSS 7.5
CVE-2024-4641
MEDIUM
Moxa OnCell G3470A-LTE Series Firmware < 1.7.7 - Denial of Service via Format String Injection
CVSS 6.3
CVE-2024-6145
HIGH
Actiontec WCB6200Q Firmware - Unauthenticated Remote Code Execution via Cookie Format String
CVSS 8.8
CVE-2024-35845
CRITICAL
Linux Kernel 5.5-6.8.1 Use-After-Free in iwl_fw_ini_debug_info_tlv
CVSS 9.1
CVE-2024-23914
MEDIUM
Merge DICOM Toolkit - Buffer Overflow
CVSS 5.7
CVE-2024-31837
HIGH
DMitry 1.3a - Format String Vulnerability
CVSS 8.4
CVE-2024-23113
CRITICAL
KEV
Fortinet FortiOS/FortiProxy/FortiPAM/FortiSwitchManager Format String Vulnerability via Crafted Packets
CVSS 9.8
CVE-2023-53966
CRITICAL
SOUND4 LinkAndShare Transmitter 1.1.2 - Memory Corruption
CVSS 9.8
CVE-2023-40721
MEDIUM
FortiOS 6.2.0-7.0.13 - Authenticated Remote Code Execution via Format String Vulnerability
CVSS 6.7
CVE-2023-45583
MEDIUM
Fortinet FortiProxy <=7.2.5, <=7.0.11, <=2.0.13, <=1.2.13, <=1.1.6 - Format String Vulnerability via CLI/HTTP
CVSS 6.7
CVE-2023-36640
MEDIUM
Fortinet FortiProxy <7.2.5 - Code Injection
CVSS 6.7
CVE-2023-48784
MEDIUM
FortiOS <7.4.1, <7.2.7, All 6.4 - Code Injection
CVSS 6.7
CVE-2023-41842
MEDIUM
Fortinet FortiAnalyzer 6.2.0-6.4.7 & FortiManager 6.2.0-7.0.10 - Remote Code Execution via Format String Injection
CVSS 6.7
CVE-2023-29181
HIGH
FortiOS 6.0.0-6.2.14, FortiProxy 1.0.0-2.0.12, FortiPAM 1.0.0-1.0.3 - Use of Externally-Controlled Format String
CVSS 8.8
Details
Vulnerabilities
399
Exploit Likelihood
High