CWE-134

High likelihood

Use of Externally-Controlled Format String

Parent: CWE-668 - Exposure of Resource to Wrong Sphere

The product uses a function that accepts a format string as an argument, but the format string originates from an external source.

379 vulnerabilities with CWE-134
CVE-2019-12297 CRITICAL
Motorola CX2/M2 <1.01 - Format String
CVSS 9.8
CVE-2019-7715 HIGH
Green Hills INTEGRITY RTOS 5.0.4 - Info Disclosure
CVSS 7.5
CVE-2019-7712 HIGH
Green Hills INTEGRITY RTOS 5.0.4 - Info Disclosure
CVSS 7.5
CVE-2019-7711 HIGH
Green Hills INTEGRITY RTOS 5.0.4 - Info Disclosure
CVSS 7.5
CVE-2018-10389 CRITICAL
TFTP Server MT <1.65 - RCE
CVSS 9.8
CVE-2018-10388 CRITICAL
TFTP Server <1.66 - RCE
CVSS 9.8
CVE-2018-14713 HIGH
ASUS RT-AC3200 <3.0.0.4.382.50010 - Memory Corruption
CVSS 8.1
CVE-2018-1352 CRITICAL
Fortinet Fortios - Format String Vulnerability
CVSS 9.8
CVE-2018-14661 MEDIUM
GlusterFS 3.8.4 - Format String Attack
CVSS 6.5
CVE-2018-17336 HIGH
UDisks 2.8.0 - Info Disclosure
CVSS 7.8
CVE-2018-16554 HIGH
Jhead - Format String Vulnerability
CVSS 7.8
CVE-2018-15749 MEDIUM
Pulsesecure Pulse Secure Desktop Client - Format String Vulnerability
CVSS 5.5
CVE-2018-14799 LOW
Philips PageWriter - Buffer Overflow
CVSS 3.7
CVE-2018-1566 HIGH
IBM Db2 - Format String Vulnerability
CVSS 8.4
CVE-2018-12590 HIGH
Ubiquiti Networks EdgeSwitch <1.7.3 - Code Injection
CVSS 7.2
CVE-2018-8778 HIGH
Ruby <2.2.10-2.6.0-preview1 - Info Disclosure
CVSS 7.5
CVE-2018-0175 HIGH KEV
Cisco Ios < 15.2\(4a\)ea5 - Format String Vulnerability
CVSS 8.0
CVE-2018-7544 CRITICAL
Openvpn < 2.4.5 - Format String Vulnerability
CVSS 9.1
CVE-2018-6875 HIGH
Shapeshift Keepkey Firmware - Format String Vulnerability
CVSS 7.5
CVE-2018-1000052 HIGH
fmtlib <4.1.0 - Memory Corruption
CVSS 7.5
CVE-2018-6508 HIGH
Puppet Enterprise < 2017.3.2 - Format String Vulnerability
CVSS 8.0
CVE-2018-6317 CRITICAL
Claymore Dual Miner < 10.5 - Format String Vulnerability
CVSS 9.1
CVE-2018-5704 CRITICAL
OpenOCD 0.10.0 - CSRF
CVSS 9.6
CVE-2018-5207 HIGH
Irssi <1.0.6 - Memory Corruption
CVSS 7.5
CVE-2018-5205 HIGH
Irssi <1.0.6 - Use After Free
CVSS 7.5
Details
Vulnerabilities 379
Exploit Likelihood High