CWE-134
394 CVEs • Abstraction: Base • Likelihood of Exploit: High
Use of Externally-Controlled Format String
The product uses a function that accepts a format string as an argument, but the format string originates from an external source.
CVEs (394)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1F5 12Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+9 moreJun 17, 2026 Feb 1, 2023 N/A· v4 8.5 HIGH· v3 N/A· v2 A format string vulnerability exists in iControl SOAP that allows an authenticated attacker to crash the iControl SOAP CGI process or, potentially execute arbitrary code. In appliance mode BIG-IP, a successful exploit o...Show more |
A vulnerability, which was classified as critical, has been found in sslh. This issue affects the function hexdump of the file probe.c of the component Packet Dumping Handler. The manipulation of the argument msg_info le...Show more |
1Multimon Ng Project 1Multimon Ng Jun 17, 2026 Dec 19, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A vulnerability was found in multimon-ng. It has been rated as critical. This issue affects the function add_ch of the file demod_flex.c. The manipulation of the argument ch leads to format string. Upgrading to version 1...Show more |
Crash in the USB HID protocol dissector in Wireshark 3.6.0 to 3.6.8 allows denial of service via packet injection or crafted capture file on Windows |
Use of Externally-Controlled Format String in GitHub repository pingcap/tidb prior to 6.4.0, 6.1.3. |
1Goabode 1Iota All In One Security Kit Firmware Jun 17, 2026 Oct 25, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 Four format string injection vulnerabilities exist in the web interface /action/wirelessConnect functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z and 6.9X. A specially-crafted HTTP request can lead t...Show more |
1Goabode 1Iota All In One Security Kit Firmware Jun 17, 2026 Oct 25, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 Four format string injection vulnerabilities exist in the web interface /action/wirelessConnect functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z and 6.9X. A specially-crafted HTTP request can lead t...Show more |
1Goabode 1Iota All In One Security Kit Firmware Jun 17, 2026 Oct 25, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 Four format string injection vulnerabilities exist in the web interface /action/wirelessConnect functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z and 6.9X. A specially-crafted HTTP request can lead t...Show more |
1Goabode 1Iota All In One Security Kit Firmware Jun 17, 2026 Oct 25, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 Four format string injection vulnerabilities exist in the web interface /action/wirelessConnect functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z and 6.9X. A specially-crafted HTTP request can lead t...Show more |
1Goabode 1Iota All In One Security Kit Firmware Jun 17, 2026 Oct 25, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 Four format string injection vulnerabilities exist in the UPnP logging functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z and 6.9X. A specially-crafted UPnP negotiation can lead to memory corruption,...Show more |
1Goabode 1Iota All In One Security Kit Firmware Jun 17, 2026 Oct 25, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 Four format string injection vulnerabilities exist in the UPnP logging functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z and 6.9X. A specially-crafted UPnP negotiation can lead to memory corruption,...Show more |
1Goabode 1Iota All In One Security Kit Firmware Jun 17, 2026 Oct 25, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 Four format string injection vulnerabilities exist in the UPnP logging functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z and 6.9X. A specially-crafted UPnP negotiation can lead to memory corruption,...Show more |
1Goabode 1Iota All In One Security Kit Firmware Jun 17, 2026 Oct 25, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 Four format string injection vulnerabilities exist in the UPnP logging functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z and 6.9X. A specially-crafted UPnP negotiation can lead to memory corruption,...Show more |
1Goabode 1Iota All In One Security Kit Firmware Jun 17, 2026 Oct 25, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Four format string injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. Specially-crafted configuration values can lead to memory corrupt...Show more |
1Goabode 1Iota All In One Security Kit Firmware Jun 17, 2026 Oct 25, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Four format string injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. Specially-crafted configuration values can lead to memory corrupt...Show more |
1Goabode 1Iota All In One Security Kit Firmware Jun 17, 2026 Oct 25, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Four format string injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. Specially-crafted configuration values can lead to memory corrupt...Show more |
1Goabode 1Iota All In One Security Kit Firmware Jun 17, 2026 Oct 25, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Four format string injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. Specially-crafted configuration values can lead to memory corrupt...Show more |
1Goabode 1Iota All In One Security Kit Firmware Jun 17, 2026 Oct 25, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A format string injection vulnerability exists in the XCMD getVarHA functionality of abode systems, inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted XCMD can lead to memory corruption, information dis...Show more |
1Goabode 1Iota All In One Security Kit Firmware Jun 17, 2026 Oct 25, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A format string injection vulnerability exists in the ghome_process_control_packet functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z and 6.9X. A specially-crafted XCMD can lead to memory corruption,...Show more |
In Apache Airflow 2.3.0 through 2.3.4, part of a url was unnecessarily formatted, allowing for possible information extraction. |