CWE-134

High likelihood

Use of Externally-Controlled Format String

Parent: CWE-668 - Exposure of Resource to Wrong Sphere

The product uses a function that accepts a format string as an argument, but the format string originates from an external source.

399 vulnerabilities with CWE-134
CVE-2017-16516 HIGH
yajl-ruby 1.3.0 - Memory Corruption
CVSS 7.5
CVE-2017-15191 HIGH
Wireshark 2.0.0-2.0.15 - Denial of Service in DMP Dissector
CVSS 7.5
CVE-2017-0898 CRITICAL
Ruby <2.4.2, 2.3.5, 2.2.8 - Buffer Overflow/Info Disclosure
CVSS 9.1
CVE-2017-12702 HIGH
Advantech WebAccess < 8.2 - Remote Code Execution via Format String Vulnerability
CVSS 8.8
CVE-2017-12588 CRITICAL
rsyslog < 8.27.0 - Format String Vulnerability in ZMQ3 Input/Output Modules
CVSS 9.8
CVE-2017-10685 CRITICAL
ncurses 6.0 - Remote Code Execution via Format String in fmt_entry Function
CVSS 9.8
CVE-2017-9212 HIGH
BMW 330i 2011 Bluetooth Stack - Denial of Service via Format String in Device Name
CVSS 7.5
CVE-2017-2403 HIGH
macOS < 10.12.4 - Remote Code Execution via Printing Component Format String
CVSS 8.8
CVE-2017-5524 MEDIUM
Plone 4.x-4.3.11 and 5.x-5.0.6 - Sandbox Protection Bypass via Python String Format Method
CVSS 4.3
CVE-2017-3859 HIGH
Cisco IOS XE 3.13-3.18 - Unauthenticated Denial of Service via DHCP Zero Touch Provisioning Format String
CVSS 7.5
CVE-2017-5613 HIGH
cPanel cgiecho and cgiemail - Remote Code Execution via Format String Specifiers in Template File
CVSS 7.8
CVE-2016-10773 HIGH
cPanel 59.9999.58-60.0.24 - Format String Injection in Exception Message Handling
CVSS 8.8
CVE-2016-10745 HIGH
Jinja < 2.8.1 - Sandbox Escape via str.format
CVSS 8.6
CVE-2016-1895 MEDIUM
NetApp Data ONTAP <8.2.5, <8.3.2P12 - DoS
CVSS 6.5
CVE-2016-5716 HIGH
Puppet Enterprise 2015.x-2016.x < 2016.4.0 - Remote Code Execution via Unsafe String Reads
CVSS 8.8
CVE-2016-4864 HIGH
Dena H2o < 2.0.3 - Format String Vulnerability
CVSS 7.5
CVE-2016-5074 CRITICAL
CloudView NMS < 2.10a - Format String Vulnerability via SNMP
CVSS 9.8
CVE-2016-4448 CRITICAL
HP Icewall Federation Agent < 2.2.1 - Format String Vulnerability
CVSS 9.8
CVE-2015-10088 MEDIUM
ayttm < 0.5.0-89 - Format String Vulnerability in http_connect Function
CVSS 5.0
CVE-2015-9238 MEDIUM
secure-compare < 3.0.1 - Incorrect String Comparison
CVSS 5.3
CVE-2015-8107 HIGH
GNU a2ps 4.14 - Remote Code Execution via Format String Vulnerability
CVSS 7.8
CVE-2015-7271 CRITICAL
Dell Integrated Remote Access Controller Firmware < 2.21.21.21 - Format String Vulnerability via racadm getsystinfo
CVSS 9.8
CVE-2015-8106 HIGH
latex2rtf - Remote Code Execution via Format String Specifiers in \keywords Command
CVSS 7.8
CVE-2015-8617 CRITICAL
PHP 7.x < 7.0.1 - Remote Code Execution via Format String Specifiers in Class Name
CVSS 9.8
CVE-2015-2894 MEDIUM
Idera Uptime Infrastructure Monitor <7.2 - DoS
CVSS 5.3
Details
Vulnerabilities 399
Exploit Likelihood High