CWE-134
394 CVEs • Abstraction: Base • Likelihood of Exploit: High
Use of Externally-Controlled Format String
The product uses a function that accepts a format string as an argument, but the format string originates from an external source.
CVEs (394)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Open Tftp Server Project 1Open Tftp Server Nov 21, 2024 Dec 23, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Format string vulnerability in the logMess function in TFTP Server SP 1.66 and earlier allows remote attackers to perform a denial of service or execute arbitrary code via format string sequences in a TFTP error packet. |
5Broadcom DebianFedoraproject+2 more5Debian Linux FedoraOpenstack+2 moreJun 17, 2026 Nov 23, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Pivotal RabbitMQ, versions 3.7.x prior to 3.7.21 and 3.8.x prior to 3.8.1, and RabbitMQ for Pivotal Platform, 1.16.x versions prior to 1.16.7 and 1.17.x versions prior to 1.17.4, contain a web management plugin that is v...Show more |
gnusound 0.7.5 has format string issue |
3Debian OpensuseXfce3Debian Linux OpensuseThunarNov 21, 2024 Nov 14, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Thunar before 1.3.1 could crash when copy and pasting a file name with % format characters due to a format string error. |
3Debian FedoraprojectLibpoe Component Irc Perl Project3Debian Linux FedoraLibpoe Component Irc PerlNov 21, 2024 Nov 12, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 libpoe-component-irc-perl before v6.32 does not remove carriage returns and line feeds. This can be used to execute arbitrary IRC commands by passing an argument such as "some text\rQUIT" to the 'privmsg' handler, which...Show more |
3Debian FedoraprojectXen3Debian Linux FedoraXenJun 17, 2026 Oct 31, 2019 N/A· v4 6.5 MEDIUM· v3 6.3 MEDIUM· v2 An issue was discovered in Xen through 4.12.x allowing x86 PV guest OS users to cause a denial of service via a VCPUOP_initialise hypercall. hypercall_create_continuation() is a variadic function which uses a printf-like...Show more |
1Foxitsoftware 2Phantompdf ReaderJun 17, 2026 Oct 4, 2019 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Reader 9.5.0.20723. User interaction is required to exploit this vulnerability in that the target must visit...Show more |
1Schneider Electric 4Meg6260 0410 Firmware Meg6260 0415 FirmwareMeg6501 0001 Firmware+1 moreJun 17, 2026 Sep 17, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A Format String: CWE-134 vulnerability exists in U.motion Server (MEG6501-0001 - U.motion KNX server, MEG6501-0002 - U.motion KNX Server Plus, MEG6260-0410 - U.motion KNX Server Plus, Touch 10, MEG6260-0415 - U.motion KN...Show more |
An issue was discovered in the ncurses crate through 5.99.0 for Rust. There are format string issues in printw functions because C format arguments are mishandled. |
An issue was discovered in the pancurses crate through 0.16.1 for Rust. printw and mvprintw have format string vulnerabilities. |
cPanel before 60.0.25 allows format-string injection in exception-message handling (SEC-171). |
Maketext in cPanel before 78.0.2 allows format-string injection in the DCV check_domains_via_dns UAPI (SEC-474). |
Maketext in cPanel before 78.0.2 allows format-string injection in the Email store_filter UAPI (SEC-472). |
Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with GlobalProtect Portal or GlobalProtect Gateway Interface enabled may allow an unauthenticated remote atta...Show more |
1Abb 1Pb610 Panel Builder 600 Firmware Jun 17, 2026 Jun 27, 2019 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 The ABB IDAL HTTP server mishandles format strings in a username or cookie during the authentication process. Attempting to authenticate with the username %25s%25p%25x%25n will crash the server. Sending %08x.AAAA.%08x.%0...Show more |
1Abb 1Pb610 Panel Builder 600 Firmware Jun 17, 2026 Jun 24, 2019 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 The ABB IDAL FTP server mishandles format strings in a username during the authentication process. Attempting to authenticate with the username %s%p%x%d will crash the server. Sending %08x.AAAA.%08x.%08x will log memory...Show more |
1Motorola 2Cx2 Firmware M2 FirmwareJun 17, 2026 May 23, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in scopd on Motorola routers CX2 1.01 and M2 1.01. There is a Use of an Externally Controlled Format String, reachable via TCP port 8010 or UDP port 8080. |
Format string vulnerability in appGet.cgi on ASUS RT-AC3200 version 3.0.0.4.382.50010 allows attackers to read arbitrary sections of memory and CPU registers via the "hook" URL parameter. |
In Pallets Jinja before 2.8.1, str.format allows a sandbox escape. |
An issue was discovered in the Interpeak IPCOMShell TELNET server on Green Hills INTEGRITY RTOS 5.0.4. The main shell handler function uses the value of the environment variable ipcom.shell.greeting as the first argument...Show more |