CWE-134

High likelihood

Use of Externally-Controlled Format String

Parent: CWE-668 - Exposure of Resource to Wrong Sphere

The product uses a function that accepts a format string as an argument, but the format string originates from an external source.

399 vulnerabilities with CWE-134
CVE-2018-10388 CRITICAL
Open TFTP Server < 1.66 - Remote Code Execution via Format String in TFTP Error Packet
CVSS 9.8
CVE-2018-14713 HIGH
ASUS RT-AC3200 <3.0.0.4.382.50010 - Memory Corruption
CVSS 8.1
CVE-2018-1352 CRITICAL
FortiOS 5.6.0 - Remote Code Execution via SSH Username Format String
CVSS 9.8
CVE-2018-14661 MEDIUM
GlusterFS 3.8.4 - Format String Attack
CVSS 6.5
CVE-2018-17336 HIGH
UDisks 2.8.0 - Format String Vulnerability via Filesystem Label
CVSS 7.8
CVE-2018-16554 HIGH
jhead 3.00 - Denial of Service via GPS Info Format String Mismatch
CVSS 7.8
CVE-2018-15749 MEDIUM
Pulse Secure Desktop (macOS) < 5.3R5 and 9.0R1 - Format String Vulnerability
CVSS 5.5
CVE-2018-14799 LOW
Philips PageWriter - Buffer Overflow
CVSS 3.7
CVE-2018-1566 HIGH
IBM DB2 9.7, 10.1, 10.5, 11.1 - Local Arbitrary Code Execution via Format String Error
CVSS 8.4
CVE-2018-12590 HIGH
Ubiquiti Networks EdgeSwitch <1.7.3 - Code Injection
CVSS 7.2
CVE-2018-8778 HIGH
Ruby <2.2.10-2.6.0-preview1 - Info Disclosure
CVSS 7.5
CVE-2018-0175 HIGH KEV
Cisco IOS, IOS XE, and IOS XR - Format String Vulnerability in LLDP Subsystem
CVSS 8.0
CVE-2018-7544 CRITICAL
OpenVPN < 2.4.5 - Unauthenticated Remote Code Execution via Management Interface
CVSS 9.1
CVE-2018-6875 HIGH
KeepKey Firmware 4.0.0 - Information Disclosure via Format String Vulnerability
CVSS 7.5
CVE-2018-1000052 HIGH
fmt < 4.1.0 - Memory Corruption via Invalid Format Specifier in fmt::print()
CVSS 7.5
CVE-2018-6508 HIGH
Puppet Enterprise 2017.3.0-2017.3.2 - Remote Code Execution via facter_task or puppet_conf Tasks
CVSS 8.0
CVE-2018-6317 CRITICAL
Claymore Dual Miner < 10.5 - Unauthenticated Format String Vulnerability
CVSS 9.1
CVE-2018-5704 CRITICAL
OpenOCD 0.10.0 - CSRF
CVSS 9.6
CVE-2018-5207 HIGH
irssi < 1.0.6 - Use of Externally-Controlled Format String
CVSS 7.5
CVE-2018-5205 HIGH
irssi < 1.0.6 - Use-After-Free via Incomplete Escape Codes
CVSS 7.5
CVE-2017-7519 LOW
Ceph - Denial of Service via Format String Vulnerability in libradosstriper
CVSS 2.3
CVE-2017-17132 MEDIUM
Huawei VP9660 V500R002C10 - Buffer Overflow
CVSS 5.5
CVE-2017-17407 CRITICAL
NetGain Systems Enterprise Manager v7.2.699 - RCE
CVSS 9.8
CVE-2017-16608 CRITICAL
Netgain Enterprise Manager < 7.2.766 - Unauthenticated Remote Code Execution via exec.jsp
CVSS 9.8
CVE-2017-16602 HIGH
NetGain Systems Enterprise Manager <7.2.730 build 1034 - RCE
CVSS 8.8
Details
Vulnerabilities 399
Exploit Likelihood High