CWE-134
High likelihoodUse of Externally-Controlled Format String
The product uses a function that accepts a format string as an argument, but the format string originates from an external source.
399 vulnerabilities with CWE-134
CVE-2017-16516
HIGH
yajl-ruby 1.3.0 - Memory Corruption
CVSS 7.5
CVE-2017-15191
HIGH
Wireshark 2.0.0-2.0.15 - Denial of Service in DMP Dissector
CVSS 7.5
CVE-2017-0898
CRITICAL
Ruby <2.4.2, 2.3.5, 2.2.8 - Buffer Overflow/Info Disclosure
CVSS 9.1
CVE-2017-12702
HIGH
Advantech WebAccess < 8.2 - Remote Code Execution via Format String Vulnerability
CVSS 8.8
CVE-2017-12588
CRITICAL
rsyslog < 8.27.0 - Format String Vulnerability in ZMQ3 Input/Output Modules
CVSS 9.8
CVE-2017-10685
CRITICAL
ncurses 6.0 - Remote Code Execution via Format String in fmt_entry Function
CVSS 9.8
CVE-2017-9212
HIGH
BMW 330i 2011 Bluetooth Stack - Denial of Service via Format String in Device Name
CVSS 7.5
CVE-2017-2403
HIGH
macOS < 10.12.4 - Remote Code Execution via Printing Component Format String
CVSS 8.8
CVE-2017-5524
MEDIUM
Plone 4.x-4.3.11 and 5.x-5.0.6 - Sandbox Protection Bypass via Python String Format Method
CVSS 4.3
CVE-2017-3859
HIGH
Cisco IOS XE 3.13-3.18 - Unauthenticated Denial of Service via DHCP Zero Touch Provisioning Format String
CVSS 7.5
CVE-2017-5613
HIGH
cPanel cgiecho and cgiemail - Remote Code Execution via Format String Specifiers in Template File
CVSS 7.8
CVE-2016-10773
HIGH
cPanel 59.9999.58-60.0.24 - Format String Injection in Exception Message Handling
CVSS 8.8
CVE-2016-10745
HIGH
Jinja < 2.8.1 - Sandbox Escape via str.format
CVSS 8.6
CVE-2016-1895
MEDIUM
NetApp Data ONTAP <8.2.5, <8.3.2P12 - DoS
CVSS 6.5
CVE-2016-5716
HIGH
Puppet Enterprise 2015.x-2016.x < 2016.4.0 - Remote Code Execution via Unsafe String Reads
CVSS 8.8
CVE-2016-4864
HIGH
Dena H2o < 2.0.3 - Format String Vulnerability
CVSS 7.5
CVE-2016-5074
CRITICAL
CloudView NMS < 2.10a - Format String Vulnerability via SNMP
CVSS 9.8
CVE-2016-4448
CRITICAL
HP Icewall Federation Agent < 2.2.1 - Format String Vulnerability
CVSS 9.8
CVE-2015-10088
MEDIUM
ayttm < 0.5.0-89 - Format String Vulnerability in http_connect Function
CVSS 5.0
CVE-2015-9238
MEDIUM
secure-compare < 3.0.1 - Incorrect String Comparison
CVSS 5.3
CVE-2015-8107
HIGH
GNU a2ps 4.14 - Remote Code Execution via Format String Vulnerability
CVSS 7.8
CVE-2015-7271
CRITICAL
Dell Integrated Remote Access Controller Firmware < 2.21.21.21 - Format String Vulnerability via racadm getsystinfo
CVSS 9.8
CVE-2015-8106
HIGH
latex2rtf - Remote Code Execution via Format String Specifiers in \keywords Command
CVSS 7.8
CVE-2015-8617
CRITICAL
PHP 7.x < 7.0.1 - Remote Code Execution via Format String Specifiers in Class Name
CVSS 9.8
CVE-2015-2894
MEDIUM
Idera Uptime Infrastructure Monitor <7.2 - DoS
CVSS 5.3
Details
Vulnerabilities
399
Exploit Likelihood
High