← Back
CWE-134

394 CVEs • Abstraction: Base • Likelihood of Exploit: High

Use of Externally-Controlled Format String

The product uses a function that accepts a format string as an argument, but the format string originates from an external source.

JSON object

Loading...

CVEs (394)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Open Tftp Server Project
1Open Tftp Server
Nov 21, 2024
Dec 23, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Format string vulnerability in the logMess function in TFTP Server SP 1.66 and earlier allows remote attackers to perform a denial of service or execute arbitrary code via format string sequences in a TFTP error packet.
5Broadcom
DebianFedoraproject+2 more
5Debian Linux
FedoraOpenstack+2 more
Jun 17, 2026
Nov 23, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Pivotal RabbitMQ, versions 3.7.x prior to 3.7.21 and 3.8.x prior to 3.8.1, and RabbitMQ for Pivotal Platform, 1.16.x versions prior to 1.16.7 and 1.17.x versions prior to 1.17.4, contain a web management plugin that is v...Show more
Pivotal RabbitMQ, versions 3.7.x prior to 3.7.21 and 3.8.x prior to 3.8.1, and RabbitMQ for Pivotal Platform, 1.16.x versions prior to 1.16.7 and 1.17.x versions prior to 1.17.4, contain a web management plugin that is vulnerable to a denial of service attack. The "X-Reason" HTTP Header can be leveraged to insert a malicious Erlang format string that will expand and consume the heap, resulting in the server crashing.Show less
1Gnu
1Gnusound
Nov 21, 2024
Nov 19, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
gnusound 0.7.5 has format string issue
3Debian
OpensuseXfce
3Debian Linux
OpensuseThunar
Nov 21, 2024
Nov 14, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Thunar before 1.3.1 could crash when copy and pasting a file name with % format characters due to a format string error.
3Debian
FedoraprojectLibpoe Component Irc Perl Project
3Debian Linux
FedoraLibpoe Component Irc Perl
Nov 21, 2024
Nov 12, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
libpoe-component-irc-perl before v6.32 does not remove carriage returns and line feeds. This can be used to execute arbitrary IRC commands by passing an argument such as "some text\rQUIT" to the 'privmsg' handler, which...Show more
libpoe-component-irc-perl before v6.32 does not remove carriage returns and line feeds. This can be used to execute arbitrary IRC commands by passing an argument such as "some text\rQUIT" to the 'privmsg' handler, which would cause the client to disconnect from the server.Show less
3Debian
FedoraprojectXen
3Debian Linux
FedoraXen
Jun 17, 2026
Oct 31, 2019
N/A· v4
6.5 MEDIUM· v3
6.3 MEDIUM· v2
An issue was discovered in Xen through 4.12.x allowing x86 PV guest OS users to cause a denial of service via a VCPUOP_initialise hypercall. hypercall_create_continuation() is a variadic function which uses a printf-like...Show more
An issue was discovered in Xen through 4.12.x allowing x86 PV guest OS users to cause a denial of service via a VCPUOP_initialise hypercall. hypercall_create_continuation() is a variadic function which uses a printf-like format string to interpret its parameters. Error handling for a bad format character was done using BUG(), which crashes Xen. One path, via the VCPUOP_initialise hypercall, has a bad format character. The BUG() can be hit if VCPUOP_initialise executes for a sufficiently long period of time for a continuation to be created. Malicious guests may cause a hypervisor crash, resulting in a Denial of Service (DoS). Xen versions 4.6 and newer are vulnerable. Xen versions 4.5 and earlier are not vulnerable. Only x86 PV guests can exploit the vulnerability. HVM and PVH guests, and guests on ARM systems, cannot exploit the vulnerability.Show less
1Foxitsoftware
2Phantompdf
Reader
Jun 17, 2026
Oct 4, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Reader 9.5.0.20723. User interaction is required to exploit this vulnerability in that the target must visit...Show more
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Reader 9.5.0.20723. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of the util.printf Javascript method. The application processes the %p parameter in the format string, allowing heap addresses to be returned to the script. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-8544.Show less
1Schneider Electric
4Meg6260 0410 Firmware
Meg6260 0415 FirmwareMeg6501 0001 Firmware+1 more
Jun 17, 2026
Sep 17, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A Format String: CWE-134 vulnerability exists in U.motion Server (MEG6501-0001 - U.motion KNX server, MEG6501-0002 - U.motion KNX Server Plus, MEG6260-0410 - U.motion KNX Server Plus, Touch 10, MEG6260-0415 - U.motion KN...Show more
A Format String: CWE-134 vulnerability exists in U.motion Server (MEG6501-0001 - U.motion KNX server, MEG6501-0002 - U.motion KNX Server Plus, MEG6260-0410 - U.motion KNX Server Plus, Touch 10, MEG6260-0415 - U.motion KNX Server Plus, Touch 15), which could allow an attacker to send a crafted message to the target server, thereby causing arbitrary commands to be executed.Show less
1Ncurses Project
1Ncurses
Jun 17, 2026
Aug 26, 2019
N/A· v4
7.5 HIGH· v3
6.4 MEDIUM· v2
An issue was discovered in the ncurses crate through 5.99.0 for Rust. There are format string issues in printw functions because C format arguments are mishandled.
1Pancurses Project
1Pancurses
Jun 17, 2026
Aug 26, 2019
N/A· v4
7.5 HIGH· v3
6.4 MEDIUM· v2
An issue was discovered in the pancurses crate through 0.16.1 for Rust. printw and mvprintw have format string vulnerabilities.
1Cpanel
1Cpanel
Nov 21, 2024
Aug 5, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
cPanel before 60.0.25 allows format-string injection in exception-message handling (SEC-171).
1Cpanel
1Cpanel
Jun 17, 2026
Jul 30, 2019
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
Maketext in cPanel before 78.0.2 allows format-string injection in the DCV check_domains_via_dns UAPI (SEC-474).
1Cpanel
1Cpanel
Jun 17, 2026
Jul 30, 2019
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
Maketext in cPanel before 78.0.2 allows format-string injection in the Email store_filter UAPI (SEC-472).
1Paloaltonetworks
1Pan Os
Jun 17, 2026
Jul 19, 2019
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with GlobalProtect Portal or GlobalProtect Gateway Interface enabled may allow an unauthenticated remote atta...Show more
Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with GlobalProtect Portal or GlobalProtect Gateway Interface enabled may allow an unauthenticated remote attacker to execute arbitrary code.Show less
1Abb
1Pb610 Panel Builder 600 Firmware
Jun 17, 2026
Jun 27, 2019
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
The ABB IDAL HTTP server mishandles format strings in a username or cookie during the authentication process. Attempting to authenticate with the username %25s%25p%25x%25n will crash the server. Sending %08x.AAAA.%08x.%0...Show more
The ABB IDAL HTTP server mishandles format strings in a username or cookie during the authentication process. Attempting to authenticate with the username %25s%25p%25x%25n will crash the server. Sending %08x.AAAA.%08x.%08x will log memory content from the stack.Show less
1Abb
1Pb610 Panel Builder 600 Firmware
Jun 17, 2026
Jun 24, 2019
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
The ABB IDAL FTP server mishandles format strings in a username during the authentication process. Attempting to authenticate with the username %s%p%x%d will crash the server. Sending %08x.AAAA.%08x.%08x will log memory...Show more
The ABB IDAL FTP server mishandles format strings in a username during the authentication process. Attempting to authenticate with the username %s%p%x%d will crash the server. Sending %08x.AAAA.%08x.%08x will log memory content from the stack.Show less
1Motorola
2Cx2 Firmware
M2 Firmware
Jun 17, 2026
May 23, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in scopd on Motorola routers CX2 1.01 and M2 1.01. There is a Use of an Externally Controlled Format String, reachable via TCP port 8010 or UDP port 8080.
1Asus
1Rt Ac3200 Firmware
Nov 21, 2024
May 13, 2019
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
Format string vulnerability in appGet.cgi on ASUS RT-AC3200 version 3.0.0.4.382.50010 allows attackers to read arbitrary sections of memory and CPU registers via the "hook" URL parameter.
1Palletsprojects
1Jinja
Nov 21, 2024
Apr 8, 2019
N/A· v4
8.6 HIGH· v3
5.0 MEDIUM· v2
In Pallets Jinja before 2.8.1, str.format allows a sandbox escape.
1Ghs
1Integrity Rtos
Jun 17, 2026
Mar 26, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in the Interpeak IPCOMShell TELNET server on Green Hills INTEGRITY RTOS 5.0.4. The main shell handler function uses the value of the environment variable ipcom.shell.greeting as the first argument...Show more
An issue was discovered in the Interpeak IPCOMShell TELNET server on Green Hills INTEGRITY RTOS 5.0.4. The main shell handler function uses the value of the environment variable ipcom.shell.greeting as the first argument to printf(). Setting this variable using the sysvar command results in a user-controlled format string during login, resulting in an information leak of memory addresses.Show less