← Back
CWE-134

408 CVEs • Abstraction: Base • Likelihood of Exploit: High

Use of Externally-Controlled Format String

The product uses a function that accepts a format string as an argument, but the format string originates from an external source.

JSON object

Loading...

CVEs (408)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Debian
Yajl Ruby Project
2Debian Linux
Yajl Ruby
May 13, 2026
Nov 3, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In the yajl-ruby gem 1.3.0 for Ruby, when a crafted JSON file is supplied to Yajl::Parser.new.parse, the whole ruby process crashes with a SIGABRT in the yajl_string_decode function in yajl_encode.c. This results in the...Show more
In the yajl-ruby gem 1.3.0 for Ruby, when a crafted JSON file is supplied to Yajl::Parser.new.parse, the whole ruby process crashes with a SIGABRT in the yajl_string_decode function in yajl_encode.c. This results in the whole ruby process terminating and potentially a denial of service.Show less
2Debian
Wireshark
2Debian Linux
Wireshark
May 13, 2026
Oct 10, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Wireshark 2.4.0 to 2.4.1, 2.2.0 to 2.2.9, and 2.0.0 to 2.0.15, the DMP dissector could crash. This was addressed in epan/dissectors/packet-dmp.c by validating a string length.
1Ovirt
1Ovirt Node
May 13, 2026
Sep 26, 2017
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
ovirt_safe_delete_config in ovirtfunctions.py and other unspecified locations in ovirt-node 3.0.0-474-gb852fd7 as packaged in Red Hat Enterprise Virtualization 3 do not properly quote input strings, which allows remote a...Show more
ovirt_safe_delete_config in ovirtfunctions.py and other unspecified locations in ovirt-node 3.0.0-474-gb852fd7 as packaged in Red Hat Enterprise Virtualization 3 do not properly quote input strings, which allows remote authenticated users and physically proximate attackers to execute arbitrary commands via a ; (semicolon) in an input string.Show less
1Ruby Lang
1Ruby
May 13, 2026
Sep 15, 2017
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
Ruby before 2.4.2, 2.3.5, and 2.2.8 is vulnerable to a malicious format string which contains a precious specifier (*) with a huge minus value. Such situation can lead to a buffer overrun, resulting in a heap memory corr...Show more
Ruby before 2.4.2, 2.3.5, and 2.2.8 is vulnerable to a malicious format string which contains a precious specifier (*) with a huge minus value. Such situation can lead to a buffer overrun, resulting in a heap memory corruption or an information disclosure from the heap.Show less
1Netapp
1Data Ontap
May 13, 2026
Sep 1, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
NetApp Data ONTAP before 8.2.5 and 8.3.x before 8.3.2P12 allow remote authenticated users to cause a denial of service via vectors related to unsafe user input string handling.
1Advantech
1Webaccess
May 13, 2026
Aug 30, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An Externally Controlled Format String issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. String format specifiers based on user provided input are not properly validated, which could allow an a...Show more
An Externally Controlled Format String issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. String format specifiers based on user provided input are not properly validated, which could allow an attacker to execute arbitrary code.Show less
1Puppet
1Puppet Enterprise
May 13, 2026
Aug 9, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The console in Puppet Enterprise 2015.x and 2016.x prior to 2016.4.0 includes unsafe string reads that potentially allows for remote code execution on the console node.
1Rsyslog
1Rsyslog
May 13, 2026
Aug 6, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The zmq3 input and output modules in rsyslog before 8.28.0 interpreted description fields as format strings, possibly allowing a format string attack with unspecified impact.
2Gnu
Invisible Island
2Ncurses
Ncurses
Jul 23, 2026
Jun 29, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In ncurses 6.0, there is a format string vulnerability in the fmt_entry function. A crafted input will lead to a remote arbitrary code execution attack.
1Bavarian Motor Works
1Bluetooth Stack
May 13, 2026
May 23, 2017
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
The Bluetooth stack on the BMW 330i 2011 allows a remote crash of the CD/Multimedia software via %x or %c format string specifiers in a device name.
1Dena
1H2o
May 13, 2026
May 12, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
H2O versions 2.0.3 and earlier and 2.1.0-beta2 and earlier allows remote attackers to cause a denial-of-service (DoS) via format string specifiers in a template file via fastcgi, mruby, proxy, redirect or reproxy.
1Gnu
1A2ps
May 13, 2026
Apr 13, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Format string vulnerability in GNU a2ps 4.14 allows remote attackers to execute arbitrary code.
1Cloudviewnms
1Cloudview Nms
May 13, 2026
Apr 10, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
CloudView NMS before 2.10a has a format string issue exploitable over SNMP.
1Dell
1Integrated Remote Access Controller Firmware
May 13, 2026
Apr 10, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Dell Integrated Remote Access Controller (iDRAC) 7/8 before 2.21.21.21 has a format string issue in racadm getsystinfo.
1Apple
1Mac Os X
May 13, 2026
Apr 2, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "Printing" component. A format-string vulnerability allows remote attackers to execute arbitrary code via a craf...Show more
An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "Printing" component. A format-string vulnerability allows remote attackers to execute arbitrary code via a crafted ipp: or ipps: URL.Show less
1Plone
1Plone
May 13, 2026
Mar 23, 2017
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Plone 4.x through 4.3.11 and 5.x through 5.0.6 allow remote attackers to bypass a sandbox protection mechanism and obtain sensitive information by leveraging the Python string format method.
1Cisco
1Ios Xe
May 13, 2026
Mar 22, 2017
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
A vulnerability in the DHCP code for the Zero Touch Provisioning feature of Cisco ASR 920 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to cause an affected device to reload. The vul...Show more
A vulnerability in the DHCP code for the Zero Touch Provisioning feature of Cisco ASR 920 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability is due to a format string vulnerability when processing a crafted DHCP packet for Zero Touch Provisioning. An attacker could exploit this vulnerability by sending a specially crafted DHCP packet to an affected device. An exploit could allow the attacker to cause the device to reload, resulting in a denial of service (DoS) condition. This vulnerability affects Cisco ASR 920 Series Aggregation Services Routers that are running an affected release of Cisco IOS XE Software (3.13 through 3.18) and are listening on the DHCP server port. By default, the devices do not listen on the DHCP server port. Cisco Bug IDs: CSCuy56385.Show less
1Cpanel
2Cgiecho
Cgiemail
May 13, 2026
Mar 3, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Format string vulnerability in cgiemail and cgiecho allows remote attackers to execute arbitrary code via format string specifiers in a template file.
8Apple
HpMcafee+5 more
19Enterprise Linux Desktop
Enterprise Linux ServerEnterprise Linux Server Aus+16 more
May 6, 2026
Jun 9, 2016
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vectors.
2Fedoraproject
Latex2rtf Project
2Fedora
Latex2rtf
May 6, 2026
Apr 18, 2016
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
Format string vulnerability in the CmdKeywords function in funct1.c in latex2rtf before 2.3.10 allows remote attackers to execute arbitrary code via format string specifiers in the \keywords command in a crafted TeX file...Show more
Format string vulnerability in the CmdKeywords function in funct1.c in latex2rtf before 2.3.10 allows remote attackers to execute arbitrary code via format string specifiers in the \keywords command in a crafted TeX file.Show less