CWE-134
408 CVEs • Abstraction: Base • Likelihood of Exploit: High
Use of Externally-Controlled Format String
The product uses a function that accepts a format string as an argument, but the format string originates from an external source.
CVEs (408)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An issue was discovered in the rusqlite crate before 0.23.0 for Rust. Memory safety can be violated because rusqlite::trace::log mishandles format strings. |
On Audi A7 MMI 2014 vehicles, the Bluetooth stack in Audi A7 MMI Multiplayer with version (N+R_CN_AU_P0395) mishandles %x and %s format string specifiers in a device name. This may lead to memory content leaks and potent...Show more |
1Mersive 1Solstice Pod Firmware Jun 17, 2026 Nov 11, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Solstice-Pod up to 5.0.2 WEBRTC server mishandles the format-string specifiers %x; %p; %c and %s in the screen_key, display_name, browser_name, and operation_system parameter during the authentication process. This may c...Show more |
1Wire 3Wire Wire Audio, Video, And SignalingWire Secure MessengerJun 17, 2026 Oct 27, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Wire before 2020-10-16 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a format string. This affects Wire AVS (Audio, Video, and Signaling) 5.3 through 6.x...Show more |
2Google Opensuse2Leap TensorflowJun 17, 2026 Sep 25, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, by controlling the `fill` argument of tf.strings.as_string, a malicious attacker is able to trigger a format string vulnerability due to the way the in...Show more |
On Mercedes-Benz C Class AMG Premium Plus c220 BlueTec vehicles, the Bluetooth stack mishandles %x and %c format-string specifiers in a device name in the COMAND infotainment software. |
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700 routers with firmware 1.0.4.84_10.0.58. Authentication is not required to exploit this vulnerabili...Show more |
AnyDesk before 5.5.3 on Linux and FreeBSD has a format string vulnerability that can be exploited for remote code execution. |
A format string vulnerability in the Varrcvr daemon of PAN-OS on PA-7000 Series devices with a Log Forwarding Card (LFC) allows remote attackers to crash the daemon creating a denial of service condition or potentially e...Show more |
A format string vulnerability in the PAN-OS log daemon (logd) on Panorama allows a network based attacker with knowledge of registered firewall devices and access to Panorama management interfaces to execute arbitrary co...Show more |
An exploitable format string vulnerability exists in the iw_console conio_writestr functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted time server entry can cause an overflow of the time server...Show more |
2Debian Zenoss2Debian Linux Zenoss CoreNov 21, 2024 Feb 12, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Multiple format string vulnerabilities in the python module in RRDtool, as used in Zenoss Core before 4.2.5 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (application c...Show more |
A vulnerability in the Cisco Discovery Protocol implementation for Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to execute arbitrary code or cause a reload on an affected device. The vulnerabil...Show more |
1Open Tftp Server Project 1Open Tftp Server Nov 21, 2024 Dec 23, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Format string vulnerability in the logMess function in TFTP Server MT 1.65 and earlier allows remote attackers to perform a denial of service or execute arbitrary code via format string sequences in a TFTP error packet. |
1Open Tftp Server Project 1Open Tftp Server Nov 21, 2024 Dec 23, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Format string vulnerability in the logMess function in TFTP Server SP 1.66 and earlier allows remote attackers to perform a denial of service or execute arbitrary code via format string sequences in a TFTP error packet. |
5Broadcom DebianFedoraproject+2 more5Debian Linux FedoraOpenstack+2 moreJun 17, 2026 Nov 23, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Pivotal RabbitMQ, versions 3.7.x prior to 3.7.21 and 3.8.x prior to 3.8.1, and RabbitMQ for Pivotal Platform, 1.16.x versions prior to 1.16.7 and 1.17.x versions prior to 1.17.4, contain a web management plugin that is v...Show more |
gnusound 0.7.5 has format string issue |
3Debian OpensuseXfce3Debian Linux OpensuseThunarNov 21, 2024 Nov 14, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Thunar before 1.3.1 could crash when copy and pasting a file name with % format characters due to a format string error. |
3Debian FedoraprojectLibpoe Component Irc Perl Project3Debian Linux FedoraLibpoe Component Irc PerlNov 21, 2024 Nov 12, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 libpoe-component-irc-perl before v6.32 does not remove carriage returns and line feeds. This can be used to execute arbitrary IRC commands by passing an argument such as "some text\rQUIT" to the 'privmsg' handler, which...Show more |
3Debian FedoraprojectXen3Debian Linux FedoraXenJun 17, 2026 Oct 31, 2019 N/A· v4 6.5 MEDIUM· v3 6.3 MEDIUM· v2 An issue was discovered in Xen through 4.12.x allowing x86 PV guest OS users to cause a denial of service via a VCPUOP_initialise hypercall. hypercall_create_continuation() is a variadic function which uses a printf-like...Show more |