CWE-134

High likelihood

Use of Externally-Controlled Format String

Parent: CWE-668 - Exposure of Resource to Wrong Sphere

The product uses a function that accepts a format string as an argument, but the format string originates from an external source.

379 vulnerabilities with CWE-134
CVE-2023-21420 HIGH
Samsung Android - Format String Vulnerability
CVSS 7.3
CVE-2023-22374 HIGH
BIG-IP - Format String
CVSS 8.5
CVE-2022-26941 CRITICAL
Motorola MTM5000 series - RCE
CVSS 9.6
CVE-2022-43953 MEDIUM
Fortinet FortiOS <7.2.4 - Code Injection
CVSS 6.7
CVE-2022-43619 MEDIUM
D-Link DIR-1935 1.03 - RCE
CVSS 6.8
CVE-2022-43869 MEDIUM
IBM Spectrum Scale & Elastic Storage System <5.1.2.8, <6.1.4.1 - DoS
CVSS 6.5
CVE-2022-4639 MEDIUM
sslh - Format String
CVSS 5.6
CVE-2022-3724 MEDIUM
Wireshark < 3.6.8 - Format String Vulnerability
CVSS 6.3
CVE-2022-3023 CRITICAL
GitHub pingcap/tidb <6.4.0-6.1.3. - Buffer Overflow
CVSS 9.8
CVE-2022-35887 HIGH
Abode Systems iota - Format String Injection
CVSS 8.8
CVE-2022-35886 HIGH
Abode Systems iota - Format String Injection
CVSS 8.8
CVE-2022-35885 HIGH
Abode Systems iota - Format String Injection
CVSS 8.8
CVE-2022-35884 HIGH
Abode Systems iota - Format String Injection
CVSS 8.8
CVE-2022-35881 HIGH
Abode Systems iota - Format String Injection
CVSS 8.8
CVE-2022-35880 HIGH
Abode Systems iota - Format String Injection
CVSS 8.8
CVE-2022-35879 HIGH
Abode Systems iota - Format String Injection
CVSS 8.8
CVE-2022-35878 HIGH
Abode Systems iota - Format String Injection
CVSS 8.8
CVE-2022-35877 CRITICAL
Abode Systems iota - Format String Injection
CVSS 9.8
CVE-2022-35876 CRITICAL
Abode Systems iota - Format String Injection
CVSS 9.8
CVE-2022-35875 CRITICAL
Abode Systems iota - Format String Injection
CVSS 9.8
CVE-2022-35874 CRITICAL
Abode Systems iota - Format String Injection
CVSS 9.8
CVE-2022-35244 CRITICAL
Goabode Iota All-in-one Security Kit ... - Format String Vulnerability
CVSS 9.8
CVE-2022-33938 CRITICAL
Abode Systems, Inc. iota - Format String Injection
CVSS 9.8
CVE-2022-40604 HIGH
Apache Airflow < 2.3.4 - Format String Vulnerability
CVSS 7.5
CVE-2022-26393 MEDIUM
Baxter Spectrum WBM - Format String
CVSS 5.0
Details
Vulnerabilities 379
Exploit Likelihood High