CWE-134
High likelihoodUse of Externally-Controlled Format String
The product uses a function that accepts a format string as an argument, but the format string originates from an external source.
399 vulnerabilities with CWE-134
CVE-2022-1215
HIGH
libinput 1.10.0-1.18.1 - Use of Externally-Controlled Format String
CVSS 7.8
CVE-2022-26674
CRITICAL
ASUS RT-AX88U Firmware < 3.0.0.4.386.46065 - Unauthenticated Remote Code Execution via Format String Vulnerability
CVSS 9.8
CVE-2022-27177
CRITICAL
ConsoleMe < 1.2.2 - Use of Externally-Controlled Format String
CVSS 9.8
CVE-2022-24051
HIGH
MariaDB CONNECT - Privilege Escalation
CVSS 7.8
CVE-2021-34970
MEDIUM
Foxit PDF Editor and Reader - Information Disclosure via Print Method Format String
CVSS 5.5
CVE-2021-42911
CRITICAL
DrayTek Vigor 2960, 3900, and 300B <= 1.5.1.3 - Remote Code Execution via Format String in mainfunction.cgi
CVSS 9.8
CVE-2021-41193
CRITICAL
wire-avs < 7.1.12 - Remote Format String Vulnerability
CVSS 9.8
CVE-2021-43041
HIGH
Kaseya Unitrends Backup <10.5.5 - Format String
CVSS 8.8
CVE-2021-37735
MEDIUM
Aruba Instant - Denial of Service via Format String Vulnerability
CVSS 5.3
CVE-2021-25489
LOW
KEV
Modem Interface Driver <SMR Oct-2021 Release 1 - Buffer Overflow
CVSS 3.3
CVE-2021-36161
CRITICAL
Apache Dubbo < 2.7.13 - Remote Code Execution via Format String Injection in toString Call
CVSS 9.8
CVE-2021-33886
HIGH
B. Braun SpaceCom2 < 012U000062 - Unauthenticated Remote Code Execution via Format String Injection
CVSS 8.1
CVE-2021-28846
MEDIUM
TRENDnet TEW-755AP/755AP2KAC/821DAP2KAC/825DAP 1.11B03 - Denial of Service via Format String in apply_cgi
CVSS 6.5
CVE-2021-32785
MEDIUM
Apache 2.x <2.4.9 - Command Injection
CVSS 5.3
CVE-2021-35331
HIGH
Tcl 8.6.11 - Use-After-Free in nmakehlp.c
CVSS 7.8
CVE-2021-33535
HIGH
Weidmueller Industrial WLAN Devices < 1.16.18 - Authenticated Remote Code Execution via Time Server Buffer Overflow
CVSS 8.8
CVE-2021-29740
HIGH
IBM Spectrum Scale 5.0.0-5.0.5.6 and 5.1.0-5.1.0.3 - Format String Vulnerability
CVSS 7.8
CVE-2021-30145
HIGH
mpv <=0.33.0 - Code Execution via Crafted m3u Playlist
CVSS 7.8
CVE-2021-20307
CRITICAL
libpano13 < 2.9.19 - Format String Vulnerability in panoFileOutputNamesCreate()
CVSS 9.8
CVE-2020-36619
MEDIUM
multimon-ng < 1.2.0 - Format String Vulnerability in demod_flex.c add_ch Function
CVSS 5.5
CVE-2020-36323
HIGH
Rust < 1.52.0 - Use-After-Free via String Join Optimization
CVSS 8.2
CVE-2020-29018
HIGH
FortiWeb 6.3.0-6.3.5 - Authenticated Format String Injection via Redir Parameter
CVSS 8.8
CVE-2020-35869
CRITICAL
rusqlite < 0.23.0 - Use of Externally-Controlled Format String in Trace Log
CVSS 9.8
CVE-2020-27524
HIGH
Audi A7 MMI <N+R_CN_AU_P0395 - Info Disclosure
CVSS 7.1
CVE-2020-27523
HIGH
Solstice-Pod < 5.0.2 - Unauthenticated Denial of Service via Format String in WEBRTC Parameters
CVSS 7.5
Details
Vulnerabilities
399
Exploit Likelihood
High