CWE-134
High likelihoodUse of Externally-Controlled Format String
The product uses a function that accepts a format string as an argument, but the format string originates from an external source.
399 vulnerabilities with CWE-134
CVE-2020-27853
CRITICAL
Wire < 3.21.2936/3.21.3932/3.21.3959, 5.3-6.3, < 3.49.918, < 3.61 - RCE via SDP Media Attribute Format String
CVSS 9.8
CVE-2020-15203
HIGH
Tensorflow <2.3.1 - Memory Corruption
CVSS 7.5
CVE-2020-16142
LOW
Mercedes-Benz COMAND - Format String Injection via Bluetooth Device Name
CVSS 3.5
CVE-2020-15634
MEDIUM
NETGEAR R6700 Firmware < 1.0.4.98 - Unauthenticated Remote Code Execution via String Table File Upload
CVSS 6.3
CVE-2020-13160
CRITICAL
AnyDesk < 5.5.3 - Remote Code Execution via Format String Vulnerability
CVSS 9.8
CVE-2020-1992
HIGH
PAN-OS 9.0.0-9.0.6 - Use-After-Free in Varrcvr Daemon via WildFire Log Forwarding
CVSS 8.1
CVE-2020-1979
HIGH
PAN-OS < 8.1.13 - Remote Code Execution via Format String in Log Daemon
CVSS 8.1
CVE-2020-3118
HIGH
KEV
Cisco IOS XR >=6.6.0 <6.6.12 - Unauthenticated Remote Code Execution via Cisco Discovery Protocol Format String
CVSS 8.8
CVE-2019-5143
HIGH
Moxa AWK-3131A Firmware 1.13 - Authenticated Remote Code Execution via Format String in iw_console conio_writestr
CVSS 8.8
CVE-2019-11287
HIGH
RabbitMQ 3.7.0-3.7.20 and 3.8.0 - Denial of Service via X-Reason HTTP Header Format String
CVSS 7.5
CVE-2019-18420
MEDIUM
Xen < 4.12.1 - Denial of Service via VCPUOP_initialise Hypercall Format String
CVSS 6.5
CVE-2019-13318
MEDIUM
Foxit Reader < 9.5.0.20723 and PhantomPDF < 8.3.10.42705 - Information Disclosure via util.printf Format String
CVSS 5.5
CVE-2019-6840
CRITICAL
Schneider Electric U.motion Server - Format String
CVSS 9.8
CVE-2019-15547
HIGH
ncurses < 5.99.0 - Use of Externally-Controlled Format String in printw Functions
CVSS 7.5
CVE-2019-15546
HIGH
pancurses < 0.16.1 - Use of Externally-Controlled Format String via printw and mvprintw
CVSS 7.5
CVE-2019-14412
LOW
cPanel < 78.0.2 - Format String Injection via DCV check_domains_via_dns UAPI
CVSS 3.3
CVE-2019-14410
LOW
cPanel < 78.0.2 - Format String Injection via Email Store Filter UAPI
CVSS 3.3
CVE-2019-1579
HIGH
KEV
PAN-OS < 7.1.19 - Unauthenticated Remote Code Execution via GlobalProtect Portal/Gateway Interface
CVSS 8.1
CVE-2019-7228
HIGH
ABB IDAL HTTP Server - Buffer Overflow
CVSS 8.8
CVE-2019-7230
HIGH
ABB IDAL FTP Server - Buffer Overflow
CVSS 8.8
CVE-2019-12297
CRITICAL
Motorola CX2/M2 <1.01 - Format String
CVSS 9.8
CVE-2019-7715
HIGH
Green Hills INTEGRITY RTOS 5.0.4 - Info Disclosure
CVSS 7.5
CVE-2019-7712
HIGH
Green Hills INTEGRITY RTOS 5.0.4 - Info Disclosure
CVSS 7.5
CVE-2019-7711
HIGH
Green Hills INTEGRITY RTOS 5.0.4 - Info Disclosure
CVSS 7.5
CVE-2018-10389
CRITICAL
Open TFTP Server < 1.65 - Remote Code Execution via Format String in TFTP Error Packet
CVSS 9.8
Details
Vulnerabilities
399
Exploit Likelihood
High