CWE-134

High likelihood

Use of Externally-Controlled Format String

Parent: CWE-668 - Exposure of Resource to Wrong Sphere

The product uses a function that accepts a format string as an argument, but the format string originates from an external source.

379 vulnerabilities with CWE-134
CVE-2022-26392 LOW
Baxter Spectrum WBM - Format String
CVSS 3.1
CVE-2022-34747 CRITICAL
Zyxel Nas326 Firmware - Format String Vulnerability
CVSS 9.8
CVE-2022-22299 HIGH
FortiADC/FortiProxy <6.3 - Format String
CVSS 7.8
CVE-2022-2652 MEDIUM
Kernel - Info Disclosure, DoS
CVSS 6.0
CVE-2022-31753 HIGH
Huawei Emui - Format String Vulnerability
CVSS 7.5
CVE-2022-1215 HIGH
Freedesktop Libinput < 1.18.2 - Format String Vulnerability
CVSS 7.8
CVE-2022-26674 CRITICAL
ASUS RT-AX88U - RCE
CVSS 9.8
CVE-2022-27177 CRITICAL
Netflix Consoleme < 1.2.2 - Format String Vulnerability
CVSS 9.8
CVE-2022-24051 HIGH
MariaDB CONNECT - Privilege Escalation
CVSS 7.8
CVE-2021-34970 MEDIUM
Foxit Pdf Editor < 10.1.5.37672 - Format String Vulnerability
CVSS 5.5
CVE-2021-42911 CRITICAL
Draytek Vigor2960 Firmware < 1.5.1.3 - Format String Vulnerability
CVSS 9.8
CVE-2021-41193 CRITICAL
wire-avs <7.1.12 - RCE
CVSS 9.8
CVE-2021-43041 HIGH
Kaseya Unitrends Backup <10.5.5 - Format String
CVSS 8.8
CVE-2021-37735 MEDIUM
Arubanetworks Aruba Instant < 6.5.4.18 - Format String Vulnerability
CVSS 5.3
CVE-2021-25489 LOW KEV
Modem Interface Driver <SMR Oct-2021 Release 1 - Buffer Overflow
CVSS 3.3
CVE-2021-36161 CRITICAL
Apache Dubbo <2.7.13 - RCE
CVSS 9.8
CVE-2021-33886 HIGH
Bbraun Spacecom2 < 012u000062 - Format String Vulnerability
CVSS 8.1
CVE-2021-28846 MEDIUM
Trendnet Tew-755ap Firmware - Format String Vulnerability
CVSS 6.5
CVE-2021-32785 MEDIUM
Apache 2.x <2.4.9 - Command Injection
CVSS 5.3
CVE-2021-35331 HIGH
Tcl 8.6.11 - Code Injection
CVSS 7.8
CVE-2021-33535 HIGH
Weidmueller Industrial WLAN - RCE
CVSS 8.8
CVE-2021-29740 HIGH
IBM Spectrum Scale < 5.0.5.7 - Format String Vulnerability
CVSS 7.8
CVE-2021-30145 HIGH
mpv <0.33.0 - RCE
CVSS 7.8
CVE-2021-20307 CRITICAL
Libpano13 < 2.9.19 - Format String Vulnerability
CVSS 9.8
CVE-2020-36619 MEDIUM
multimon-ng <1.2.0 - Format String
CVSS 5.5
Details
Vulnerabilities 379
Exploit Likelihood High