CWE-134

High likelihood

Use of Externally-Controlled Format String

Parent: CWE-668 - Exposure of Resource to Wrong Sphere

The product uses a function that accepts a format string as an argument, but the format string originates from an external source.

399 vulnerabilities with CWE-134
CVE-2022-43869 MEDIUM
IBM Spectrum Scale & Elastic Storage System <5.1.2.8, <6.1.4.1 - DoS
CVSS 6.5
CVE-2022-4639 MEDIUM
sslh - Format String Vulnerability in Packet Dumping Handler
CVSS 5.6
CVE-2022-3724 MEDIUM
Wireshark 3.6.0-3.6.8 - Denial of Service via USB HID Protocol Dissector
CVSS 6.3
CVE-2022-3023 CRITICAL
GitHub pingcap/tidb <6.4.0-6.1.3. - Buffer Overflow
CVSS 9.8
CVE-2022-35887 HIGH
Abode Systems iota - Format String Injection
CVSS 8.8
CVE-2022-35886 HIGH
Abode Systems iota - Format String Injection
CVSS 8.8
CVE-2022-35885 HIGH
Abode Systems iota - Format String Injection
CVSS 8.8
CVE-2022-35884 HIGH
Abode Systems iota - Format String Injection
CVSS 8.8
CVE-2022-35881 HIGH
Abode Systems iota - Format String Injection
CVSS 8.8
CVE-2022-35880 HIGH
Abode Systems iota - Format String Injection
CVSS 8.8
CVE-2022-35879 HIGH
Abode Systems iota - Format String Injection
CVSS 8.8
CVE-2022-35878 HIGH
Abode Systems iota - Format String Injection
CVSS 8.8
CVE-2022-35877 CRITICAL
Abode Systems iota - Format String Injection
CVSS 9.8
CVE-2022-35876 CRITICAL
Abode Systems iota - Format String Injection
CVSS 9.8
CVE-2022-35875 CRITICAL
Abode Systems iota - Format String Injection
CVSS 9.8
CVE-2022-35874 CRITICAL
Abode Systems iota - Format String Injection
CVSS 9.8
CVE-2022-35244 CRITICAL
abode systems iota All-In-One Security Kit 6.9X and 6.9Z - Format String Injection via XCMD getVarHA
CVSS 9.8
CVE-2022-33938 CRITICAL
Abode Systems, Inc. iota - Format String Injection
CVSS 9.8
CVE-2022-40604 HIGH
Apache Airflow 2.3.0-2.3.4 - Information Exposure via URL Format String
CVSS 7.5
CVE-2022-26393 MEDIUM
Baxter Spectrum WBM - Format String
CVSS 5.0
CVE-2022-26392 LOW
Baxter Spectrum WBM - Format String
CVSS 3.1
CVE-2022-34747 CRITICAL
Zyxel NAS326 Firmware < 5.21(aazf.12)c0 - Remote Code Execution via UDP Packet Format String
CVSS 9.8
CVE-2022-22299 HIGH
FortiADC/FortiProxy <6.3 - Format String
CVSS 7.8
CVE-2022-2652 MEDIUM
v4l2loopback < 0.12.6 - Kernel Stack Memory Leak and Denial of Service via Card Label Format String
CVSS 6.0
CVE-2022-31753 HIGH
Huawei EMUI - Denial of Service via Voice Wakeup Format String
CVSS 7.5
Details
Vulnerabilities 399
Exploit Likelihood High