CWE-134
High likelihoodUse of Externally-Controlled Format String
The product uses a function that accepts a format string as an argument, but the format string originates from an external source.
399 vulnerabilities with CWE-134
CVE-2018-10388
CRITICAL
Open TFTP Server < 1.66 - Remote Code Execution via Format String in TFTP Error Packet
CVSS 9.8
CVE-2018-14713
HIGH
ASUS RT-AC3200 <3.0.0.4.382.50010 - Memory Corruption
CVSS 8.1
CVE-2018-1352
CRITICAL
FortiOS 5.6.0 - Remote Code Execution via SSH Username Format String
CVSS 9.8
CVE-2018-14661
MEDIUM
GlusterFS 3.8.4 - Format String Attack
CVSS 6.5
CVE-2018-17336
HIGH
UDisks 2.8.0 - Format String Vulnerability via Filesystem Label
CVSS 7.8
CVE-2018-16554
HIGH
jhead 3.00 - Denial of Service via GPS Info Format String Mismatch
CVSS 7.8
CVE-2018-15749
MEDIUM
Pulse Secure Desktop (macOS) < 5.3R5 and 9.0R1 - Format String Vulnerability
CVSS 5.5
CVE-2018-14799
LOW
Philips PageWriter - Buffer Overflow
CVSS 3.7
CVE-2018-1566
HIGH
IBM DB2 9.7, 10.1, 10.5, 11.1 - Local Arbitrary Code Execution via Format String Error
CVSS 8.4
CVE-2018-12590
HIGH
Ubiquiti Networks EdgeSwitch <1.7.3 - Code Injection
CVSS 7.2
CVE-2018-8778
HIGH
Ruby <2.2.10-2.6.0-preview1 - Info Disclosure
CVSS 7.5
CVE-2018-0175
HIGH
KEV
Cisco IOS, IOS XE, and IOS XR - Format String Vulnerability in LLDP Subsystem
CVSS 8.0
CVE-2018-7544
CRITICAL
OpenVPN < 2.4.5 - Unauthenticated Remote Code Execution via Management Interface
CVSS 9.1
CVE-2018-6875
HIGH
KeepKey Firmware 4.0.0 - Information Disclosure via Format String Vulnerability
CVSS 7.5
CVE-2018-1000052
HIGH
fmt < 4.1.0 - Memory Corruption via Invalid Format Specifier in fmt::print()
CVSS 7.5
CVE-2018-6508
HIGH
Puppet Enterprise 2017.3.0-2017.3.2 - Remote Code Execution via facter_task or puppet_conf Tasks
CVSS 8.0
CVE-2018-6317
CRITICAL
Claymore Dual Miner < 10.5 - Unauthenticated Format String Vulnerability
CVSS 9.1
CVE-2018-5704
CRITICAL
OpenOCD 0.10.0 - CSRF
CVSS 9.6
CVE-2018-5207
HIGH
irssi < 1.0.6 - Use of Externally-Controlled Format String
CVSS 7.5
CVE-2018-5205
HIGH
irssi < 1.0.6 - Use-After-Free via Incomplete Escape Codes
CVSS 7.5
CVE-2017-7519
LOW
Ceph - Denial of Service via Format String Vulnerability in libradosstriper
CVSS 2.3
CVE-2017-17132
MEDIUM
Huawei VP9660 V500R002C10 - Buffer Overflow
CVSS 5.5
CVE-2017-17407
CRITICAL
NetGain Systems Enterprise Manager v7.2.699 - RCE
CVSS 9.8
CVE-2017-16608
CRITICAL
Netgain Enterprise Manager < 7.2.766 - Unauthenticated Remote Code Execution via exec.jsp
CVSS 9.8
CVE-2017-16602
HIGH
NetGain Systems Enterprise Manager <7.2.730 build 1034 - RCE
CVSS 8.8
Details
Vulnerabilities
399
Exploit Likelihood
High