CWE-134
394 CVEs • Abstraction: Base • Likelihood of Exploit: High
Use of Externally-Controlled Format String
The product uses a function that accepts a format string as an argument, but the format string originates from an external source.
CVEs (394)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Netgain Systems 1Enterprise Manager Nov 21, 2024 Jan 23, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of NetGain Systems Enterprise Manager v7.2.699 build 1001. Authentication is not required to exploit this vulnerability. Th...Show more |
1Netgain Systems 1Enterprise Manager Nov 21, 2024 Jan 23, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Netgain Enterprise Manager. Authentication is not required to exploit this vulnerability. The specific flaw exists withi...Show more |
1Netgain Systems 1Enterprise Manager Nov 21, 2024 Jan 23, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of NetGain Systems Enterprise Manager 7.2.730 build 1034. Although authentication is required to exploit this vulnerability...Show more |
2Debian Openocd2Debian Linux Open On Chip DebuggerJun 17, 2026 Jan 16, 2018 N/A· v4 9.6 CRITICAL· v3 9.3 HIGH· v2 Open On-Chip Debugger (OpenOCD) 0.10.0 does not block attempts to use HTTP POST for sending data to 127.0.0.1 port 4444, which allows remote attackers to conduct cross-protocol scripting attacks, and consequently execute...Show more |
When using an incomplete variable argument, Irssi before 1.0.6 may access data beyond the end of the string. |
3Canonical DebianIrssi3Debian Linux IrssiUbuntu LinuxNov 21, 2024 Jan 6, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 When using incomplete escape codes, Irssi before 1.0.6 may access data beyond the end of the string. |
2Debian Yajl Ruby Project2Debian Linux Yajl RubyMay 13, 2026 Nov 3, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In the yajl-ruby gem 1.3.0 for Ruby, when a crafted JSON file is supplied to Yajl::Parser.new.parse, the whole ruby process crashes with a SIGABRT in the yajl_string_decode function in yajl_encode.c. This results in the...Show more |
2Debian Wireshark2Debian Linux WiresharkMay 13, 2026 Oct 10, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Wireshark 2.4.0 to 2.4.1, 2.2.0 to 2.2.9, and 2.0.0 to 2.0.15, the DMP dissector could crash. This was addressed in epan/dissectors/packet-dmp.c by validating a string length. |
ovirt_safe_delete_config in ovirtfunctions.py and other unspecified locations in ovirt-node 3.0.0-474-gb852fd7 as packaged in Red Hat Enterprise Virtualization 3 do not properly quote input strings, which allows remote a...Show more |
Ruby before 2.4.2, 2.3.5, and 2.2.8 is vulnerable to a malicious format string which contains a precious specifier (*) with a huge minus value. Such situation can lead to a buffer overrun, resulting in a heap memory corr...Show more |
NetApp Data ONTAP before 8.2.5 and 8.3.x before 8.3.2P12 allow remote authenticated users to cause a denial of service via vectors related to unsafe user input string handling. |
An Externally Controlled Format String issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. String format specifiers based on user provided input are not properly validated, which could allow an a...Show more |
The console in Puppet Enterprise 2015.x and 2016.x prior to 2016.4.0 includes unsafe string reads that potentially allows for remote code execution on the console node. |
The zmq3 input and output modules in rsyslog before 8.28.0 interpreted description fields as format strings, possibly allowing a format string attack with unspecified impact. |
2Gnu Invisible Island2Ncurses NcursesJul 23, 2026 Jun 29, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In ncurses 6.0, there is a format string vulnerability in the fmt_entry function. A crafted input will lead to a remote arbitrary code execution attack. |
1Bavarian Motor Works 1Bluetooth Stack May 13, 2026 May 23, 2017 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 The Bluetooth stack on the BMW 330i 2011 allows a remote crash of the CD/Multimedia software via %x or %c format string specifiers in a device name. |
H2O versions 2.0.3 and earlier and 2.1.0-beta2 and earlier allows remote attackers to cause a denial-of-service (DoS) via format string specifiers in a template file via fastcgi, mruby, proxy, redirect or reproxy. |
Format string vulnerability in GNU a2ps 4.14 allows remote attackers to execute arbitrary code. |
CloudView NMS before 2.10a has a format string issue exploitable over SNMP. |
1Dell 1Integrated Remote Access Controller Firmware May 13, 2026 Apr 10, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Dell Integrated Remote Access Controller (iDRAC) 7/8 before 2.21.21.21 has a format string issue in racadm getsystinfo. |