CWE-134

High likelihood

Use of Externally-Controlled Format String

Parent: CWE-668 - Exposure of Resource to Wrong Sphere

The product uses a function that accepts a format string as an argument, but the format string originates from an external source.

399 vulnerabilities with CWE-134
CVE-2023-6764 HIGH
Zyxel ATP/USG FLEX Series Firmware 4.32-5.37 Patch 1 - Remote Code Execution via IPSec VPN Format String
CVSS 8.1
CVE-2023-6399 MEDIUM
Zyxel ATP-USG FLEX- USG20-W-H <5.37.1 - DoS
CVSS 5.7
CVE-2023-24590 HIGH
Gallagher Controller 6000 <8.60.231116a - Use After Free
CVSS 7.5
CVE-2023-36639 HIGH
Fortinet FortiProxy 7.0.0-7.0.10 and 7.2.0-7.2.4 - Use of Externally-Controlled Format String via API Requests
CVSS 7.2
CVE-2023-48221 HIGH
wire-avs < 9.2.22 - Remote Format String Vulnerability
CVSS 7.3
CVE-2023-5746 CRITICAL
Synology BC500 and TC500 Firmware < 1.0.5-0185 - Remote Code Execution via Format String in CGI Component
CVSS 9.8
CVE-2023-41349 HIGH
ASUS router RT-AX88U - Format String Attack
CVSS 8.8
CVE-2023-39240 HIGH
ASUS RT-AX56U V2 Firmware - Authenticated Remote Code Execution via Format String in iperf Client API
CVSS 7.2
CVE-2023-39239 HIGH
ASUS RT-AX56U V2 Firmware - Authenticated Remote Code Execution via Format String in General Function API
CVSS 7.2
CVE-2023-39238 HIGH
ASUS RT-AX56U V2 - Authenticated Remote Code Execution via Format String in set_iperf3_svr.cgi
CVSS 7.2
CVE-2023-4746 HIGH
TOTOLINK N200RE V5 9.3.5u.6437_B20230519 - Format String Vulnerability in Validity_check Function
CVSS 8.8
CVE-2023-35087 CRITICAL
ASUS RT-AX56U V2 & RT-AC86U Firmware - Remote Code Execution via Format String in AiMesh
CVSS 9.8
CVE-2023-35086 HIGH
ASUS RT-AX56U V2 & RT-AC86U RCE via Format String in logmessage_normal
CVSS 7.2
CVE-2023-33011 HIGH
Zyxel Firewalls and WLAN Controllers 5.00-5.36 Patch 2 - Unauthenticated Remote Code Execution via PPPoE Configuration
CVSS 8.8
CVE-2023-2186 HIGH
Triangle MicroWorks' SCADA Data Gateway <= v5.01.03 - Info Disclosu...
CVSS 8.2
CVE-2023-21497 MEDIUM
Samsung Android - Use of Externally-Controlled Format String in mPOS TUI Trustlet
CVSS 4.4
CVE-2023-22923 MEDIUM
Zyxel NBG-418N v2 Firmware < V1.00(AARP.14)C0 - Authenticated Denial of Service via Format String Vulnerability
CVSS 6.5
CVE-2023-25492 MEDIUM
Lenovo ThinkAgile Firmware - Authenticated Denial of Service via Format String Injection
CVSS 6.3
CVE-2023-25815 LOW
Git for Windows < 2.40.1 - Path Traversal via Fake Localized Messages
CVSS 3.3
CVE-2023-23783 MEDIUM
FortiWeb 6.4.0-6.4.1 and 7.0.0-7.0.1 - Remote Code Execution via Format String Injection
CVSS 6.7
CVE-2023-21420 HIGH
Samsung Android STST TA - Use of Externally-Controlled Format String
CVSS 7.3
CVE-2023-22374 HIGH
F5 BIG-IP Access Policy Manager 14.1.4.6-14.1.5 - Authenticated Format String Injection via iControl SOAP
CVSS 8.5
CVE-2022-26941 CRITICAL
Motorola MTM5000 Series Firmware - Format String Vulnerability via AT+CTGL Command
CVSS 9.6
CVE-2022-43953 MEDIUM
Fortinet FortiOS <7.2.4 - Code Injection
CVSS 6.7
CVE-2022-43619 MEDIUM
D-Link DIR-1935 < 1.03 - Authenticated Remote Code Execution via ConfigFileUpload Format String
CVSS 6.8
Details
Vulnerabilities 399
Exploit Likelihood High