CWE-134
High likelihoodUse of Externally-Controlled Format String
The product uses a function that accepts a format string as an argument, but the format string originates from an external source.
399 vulnerabilities with CWE-134
CVE-2023-6764
HIGH
Zyxel ATP/USG FLEX Series Firmware 4.32-5.37 Patch 1 - Remote Code Execution via IPSec VPN Format String
CVSS 8.1
CVE-2023-6399
MEDIUM
Zyxel ATP-USG FLEX- USG20-W-H <5.37.1 - DoS
CVSS 5.7
CVE-2023-24590
HIGH
Gallagher Controller 6000 <8.60.231116a - Use After Free
CVSS 7.5
CVE-2023-36639
HIGH
Fortinet FortiProxy 7.0.0-7.0.10 and 7.2.0-7.2.4 - Use of Externally-Controlled Format String via API Requests
CVSS 7.2
CVE-2023-48221
HIGH
wire-avs < 9.2.22 - Remote Format String Vulnerability
CVSS 7.3
CVE-2023-5746
CRITICAL
Synology BC500 and TC500 Firmware < 1.0.5-0185 - Remote Code Execution via Format String in CGI Component
CVSS 9.8
CVE-2023-41349
HIGH
ASUS router RT-AX88U - Format String Attack
CVSS 8.8
CVE-2023-39240
HIGH
ASUS RT-AX56U V2 Firmware - Authenticated Remote Code Execution via Format String in iperf Client API
CVSS 7.2
CVE-2023-39239
HIGH
ASUS RT-AX56U V2 Firmware - Authenticated Remote Code Execution via Format String in General Function API
CVSS 7.2
CVE-2023-39238
HIGH
ASUS RT-AX56U V2 - Authenticated Remote Code Execution via Format String in set_iperf3_svr.cgi
CVSS 7.2
CVE-2023-4746
HIGH
TOTOLINK N200RE V5 9.3.5u.6437_B20230519 - Format String Vulnerability in Validity_check Function
CVSS 8.8
CVE-2023-35087
CRITICAL
ASUS RT-AX56U V2 & RT-AC86U Firmware - Remote Code Execution via Format String in AiMesh
CVSS 9.8
CVE-2023-35086
HIGH
ASUS RT-AX56U V2 & RT-AC86U RCE via Format String in logmessage_normal
CVSS 7.2
CVE-2023-33011
HIGH
Zyxel Firewalls and WLAN Controllers 5.00-5.36 Patch 2 - Unauthenticated Remote Code Execution via PPPoE Configuration
CVSS 8.8
CVE-2023-2186
HIGH
Triangle MicroWorks' SCADA Data Gateway <= v5.01.03 - Info Disclosu...
CVSS 8.2
CVE-2023-21497
MEDIUM
Samsung Android - Use of Externally-Controlled Format String in mPOS TUI Trustlet
CVSS 4.4
CVE-2023-22923
MEDIUM
Zyxel NBG-418N v2 Firmware < V1.00(AARP.14)C0 - Authenticated Denial of Service via Format String Vulnerability
CVSS 6.5
CVE-2023-25492
MEDIUM
Lenovo ThinkAgile Firmware - Authenticated Denial of Service via Format String Injection
CVSS 6.3
CVE-2023-25815
LOW
Git for Windows < 2.40.1 - Path Traversal via Fake Localized Messages
CVSS 3.3
CVE-2023-23783
MEDIUM
FortiWeb 6.4.0-6.4.1 and 7.0.0-7.0.1 - Remote Code Execution via Format String Injection
CVSS 6.7
CVE-2023-21420
HIGH
Samsung Android STST TA - Use of Externally-Controlled Format String
CVSS 7.3
CVE-2023-22374
HIGH
F5 BIG-IP Access Policy Manager 14.1.4.6-14.1.5 - Authenticated Format String Injection via iControl SOAP
CVSS 8.5
CVE-2022-26941
CRITICAL
Motorola MTM5000 Series Firmware - Format String Vulnerability via AT+CTGL Command
CVSS 9.6
CVE-2022-43953
MEDIUM
Fortinet FortiOS <7.2.4 - Code Injection
CVSS 6.7
CVE-2022-43619
MEDIUM
D-Link DIR-1935 < 1.03 - Authenticated Remote Code Execution via ConfigFileUpload Format String
CVSS 6.8
Details
Vulnerabilities
399
Exploit Likelihood
High