CWE-134— Use of Externally-Controlled Format String
162 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-134page 1 of 4
- CVE-2010-3438CRITICALCVSS 9.8EG 9.82019-11-12
libpoe-component-irc-perl before v6.32 does not remove carriage returns and line feeds. This can be used to execute arbitrary IRC commands by passing an argument such as "some text\rQUIT" to the 'privmsg' handler, which would cause the cli…
- CVE-2011-1588HIGHCVSS 7.8EG 7.82019-11-14
Thunar before 1.3.1 could crash when copy and pasting a file name with % format characters due to a format string error.
- CVE-2012-0824CRITICALCVSS 9.8EG 9.82019-11-19
gnusound 0.7.5 has format string issue
- CVE-2014-6262HIGHCVSS 7.5EG 7.52020-02-12
Multiple format string vulnerabilities in the python module in RRDtool, as used in Zenoss Core before 4.2.5 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted…
- CVE-2015-10088MEDIUMCVSS 5.0EG 9.82023-03-05
A vulnerability, which was classified as critical, was found in ayttm up to 0.5.0.89. This affects the function http_connect in the library libproxy/proxy.c. The manipulation leads to format string. It is possible to initiate the attack re…
- CVE-2015-9238MEDIUMCVSS 5.32018-05-31
secure-compare 3.0.0 and below do not actually compare two strings properly. compare was actually comparing the first argument with itself, meaning the check passed for any two strings of the same length.
- CVE-2016-10745HIGHCVSS 8.62019-04-08
In Pallets Jinja before 2.8.1, str.format allows a sandbox escape.
- CVE-2016-10773HIGHCVSS 8.8EG 8.82019-08-05
cPanel before 60.0.25 allows format-string injection in exception-message handling (SEC-171).
- CVE-2017-16602HIGHCVSS 8.82018-01-23
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of NetGain Systems Enterprise Manager 7.2.730 build 1034. Although authentication is required to exploit this vulnerability, the existing auth…
- CVE-2017-16608CRITICALCVSS 9.82018-01-23
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Netgain Enterprise Manager. Authentication is not required to exploit this vulnerability. The specific flaw exists within exec.jsp. The iss…
- CVE-2017-17132MEDIUMCVSS 5.5EG 5.52018-03-05
Huawei VP9660 V500R002C10 has a uncontrolled format string vulnerability when the license module output the log information. An authenticated local attacker could exploit this vulnerability to cause a denial of service.
- CVE-2017-17407CRITICALCVSS 9.82018-01-23
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of NetGain Systems Enterprise Manager v7.2.699 build 1001. Authentication is not required to exploit this vulnerability. The specific flaw exi…
- CVE-2017-7519LOWCVSS 2.32018-07-27
In Ceph, a format string flaw was found in the way libradosstriper parses input from user. A user could crash an application or service using the libradosstriper library.
- CVE-2018-0175HIGHCVSS 8.0EG 9.0⚠ KEV2018-03-28
Format String vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) …
- CVE-2018-1000052HIGHCVSS 7.52018-02-09
fmtlib version prior to version 4.1.0 (before commit 0555cea5fc0bf890afe0071a558e44625a34ba85) contains a Memory corruption (SIGSEGV), CWE-134 vulnerability in fmt::print() library function that can result in Denial of Service. This attack…
- CVE-2018-10388CRITICALCVSS 9.8EG 9.82019-12-23
Format string vulnerability in the logMess function in TFTP Server SP 1.66 and earlier allows remote attackers to perform a denial of service or execute arbitrary code via format string sequences in a TFTP error packet.
- CVE-2018-10389CRITICALCVSS 9.8EG 9.82019-12-23
Format string vulnerability in the logMess function in TFTP Server MT 1.65 and earlier allows remote attackers to perform a denial of service or execute arbitrary code via format string sequences in a TFTP error packet.
- CVE-2018-12590HIGHCVSS 7.22018-06-20
Ubiquiti Networks EdgeSwitch version 1.7.3 and prior suffer from an externally controlled format-string vulnerability due to lack of protection on the admin CLI, leading to code execution and privilege escalation greater than administrator…
- CVE-2018-1352CRITICALCVSS 9.82019-02-08
A format string vulnerability in Fortinet FortiOS 5.6.0 allows attacker to execute unauthorized code or commands via the SSH username variable.
- CVE-2018-14661MEDIUMCVSS 6.52018-10-31
It was found that usage of snprintf function in feature/locks translator of glusterfs server 3.8.4, as shipped with Red Hat Gluster Storage, was vulnerable to a format string attack. A remote, authenticated attacker could use this flaw to …
- CVE-2018-14713HIGHCVSS 8.12019-05-13
Format string vulnerability in appGet.cgi on ASUS RT-AC3200 version 3.0.0.4.382.50010 allows attackers to read arbitrary sections of memory and CPU registers via the "hook" URL parameter.
- CVE-2018-14799LOWCVSS 3.72018-08-22
In Philips PageWriter TC10, TC20, TC30, TC50, TC70 Cardiographs, all versions prior to May 2018, the PageWriter device does not sanitize data entered by user. This can lead to buffer overflow or format string vulnerabilities.
- CVE-2018-1566HIGHCVSS 8.42018-07-10
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local user to execute arbitrary code due to a format string error. IBM X-Force ID: 143023.
- CVE-2018-15749MEDIUMCVSS 5.52018-09-06
The Pulse Secure Desktop (macOS) 5.3RX before 5.3R5 and 9.0R1 has a Format String Vulnerability.
- CVE-2018-16554HIGHCVSS 7.82018-09-16
The ProcessGpsInfo function of the gpsinfo.c file of jhead 3.00 may allow a remote attacker to cause a denial-of-service attack or unspecified other impact via a malicious JPEG file, because of inconsistency between float and double in a s…
- CVE-2018-17336HIGHCVSS 7.82018-09-22
UDisks 2.8.0 has a format string vulnerability in udisks_log in udiskslogging.c, allowing attackers to obtain sensitive information (stack contents), cause a denial of service (memory corruption), or possibly have unspecified other impact …
- CVE-2018-5205HIGHCVSS 7.52018-01-06
When using incomplete escape codes, Irssi before 1.0.6 may access data beyond the end of the string.
- CVE-2018-5207HIGHCVSS 7.52018-01-06
When using an incomplete variable argument, Irssi before 1.0.6 may access data beyond the end of the string.
- CVE-2018-5704CRITICALCVSS 9.62018-01-16
Open On-Chip Debugger (OpenOCD) 0.10.0 does not block attempts to use HTTP POST for sending data to 127.0.0.1 port 4444, which allows remote attackers to conduct cross-protocol scripting attacks, and consequently execute arbitrary commands…
- CVE-2018-6317CRITICALCVSS 9.12018-02-02
The remote management interface in Claymore Dual Miner 10.5 and earlier is vulnerable to an unauthenticated format string vulnerability, allowing remote attackers to read memory or cause a denial of service.
- CVE-2018-6508HIGHCVSS 8.02018-02-09
Puppet Enterprise 2017.3.x prior to 2017.3.3 are vulnerable to a remote execution bug when a specially crafted string was passed into the facter_task or puppet_conf tasks. This vulnerability only affects tasks in the affected modules, if y…
- CVE-2018-6875HIGHCVSS 7.52018-03-14
Format String vulnerability in KeepKey version 4.0.0 allows attackers to trigger information display (of information that should not be accessible), related to text containing characters that the device's font lacks.
- CVE-2018-7544CRITICALCVSS 9.12018-03-16
A cross-protocol scripting issue was discovered in the management interface in OpenVPN through 2.4.5. When this interface is enabled over TCP without a password, and when no other clients are connected to this interface, attackers can exec…
- CVE-2018-8778HIGHCVSS 7.5EG 7.52018-04-03
In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, an attacker controlling the unpacking format (similar to format string vulnerabilities) can trigger a buffer under-read in the String#un…
- CVE-2019-11287HIGHCVSS 7.5EG 7.52019-11-23
Pivotal RabbitMQ, versions 3.7.x prior to 3.7.21 and 3.8.x prior to 3.8.1, and RabbitMQ for Pivotal Platform, 1.16.x versions prior to 1.16.7 and 1.17.x versions prior to 1.17.4, contain a web management plugin that is vulnerable to a deni…
- CVE-2019-12297CRITICALCVSS 9.8EG 9.82019-05-23
An issue was discovered in scopd on Motorola routers CX2 1.01 and M2 1.01. There is a Use of an Externally Controlled Format String, reachable via TCP port 8010 or UDP port 8080.
- CVE-2019-13318MEDIUMCVSS 5.5EG 5.52019-10-04
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Reader 9.5.0.20723. User interaction is required to exploit this vulnerability in that the target must visit a malicious page o…
- CVE-2019-14410LOWCVSS 3.3EG 3.32019-07-30
Maketext in cPanel before 78.0.2 allows format-string injection in the Email store_filter UAPI (SEC-472).
- CVE-2019-14412LOWCVSS 3.3EG 3.32019-07-30
Maketext in cPanel before 78.0.2 allows format-string injection in the DCV check_domains_via_dns UAPI (SEC-474).
- CVE-2019-15546HIGHCVSS 7.5EG 7.52019-08-26
An issue was discovered in the pancurses crate through 0.16.1 for Rust. printw and mvprintw have format string vulnerabilities.
- CVE-2019-15547HIGHCVSS 7.5EG 7.52019-08-26
An issue was discovered in the ncurses crate through 5.99.0 for Rust. There are format string issues in printw functions because C format arguments are mishandled.
- CVE-2019-1579HIGHCVSS 8.1EG 9.0⚠ KEV2019-07-19
Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with GlobalProtect Portal or GlobalProtect Gateway Interface enabled may allow an unauthenticated remote attacker to execute arb…
- CVE-2019-18420MEDIUMCVSS 6.5EG 6.52019-10-31
An issue was discovered in Xen through 4.12.x allowing x86 PV guest OS users to cause a denial of service via a VCPUOP_initialise hypercall. hypercall_create_continuation() is a variadic function which uses a printf-like format string to i…
- CVE-2019-5143HIGHCVSS 8.8EG 8.82020-02-25
An exploitable format string vulnerability exists in the iw_console conio_writestr functionality of the Moxa AWK-3131A firmware version 1.13. A specially crafted time server entry can cause an overflow of the time server buffer, resulting …
- CVE-2019-6840CRITICALCVSS 9.8EG 9.82019-09-17
A Format String: CWE-134 vulnerability exists in U.motion Server (MEG6501-0001 - U.motion KNX server, MEG6501-0002 - U.motion KNX Server Plus, MEG6260-0410 - U.motion KNX Server Plus, Touch 10, MEG6260-0415 - U.motion KNX Server Plus, Touc…
- CVE-2019-7228HIGHCVSS 8.8EG 8.82019-06-27
The ABB IDAL HTTP server mishandles format strings in a username or cookie during the authentication process. Attempting to authenticate with the username %25s%25p%25x%25n will crash the server. Sending %08x.AAAA.%08x.%08x will log memory …
- CVE-2019-7230HIGHCVSS 8.8EG 8.82019-06-24
The ABB IDAL FTP server mishandles format strings in a username during the authentication process. Attempting to authenticate with the username %s%p%x%d will crash the server. Sending %08x.AAAA.%08x.%08x will log memory content from the st…
- CVE-2019-7711HIGHCVSS 7.52019-03-26
An issue was discovered in the Interpeak IPCOMShell TELNET server on Green Hills INTEGRITY RTOS 5.0.4. The undocumented shell command "prompt" sets the (user controlled) shell's prompt value, which is used as a format string input to print…
- CVE-2019-7712HIGHCVSS 7.52019-03-26
An issue was discovered in handler_ipcom_shell_pwd in the Interpeak IPCOMShell TELNET server on Green Hills INTEGRITY RTOS 5.0.4. When using the pwd command, the current working directory path is used as the first argument to printf() with…
- CVE-2019-7715HIGHCVSS 7.52019-03-26
An issue was discovered in the Interpeak IPCOMShell TELNET server on Green Hills INTEGRITY RTOS 5.0.4. The main shell handler function uses the value of the environment variable ipcom.shell.greeting as the first argument to printf(). Setti…
Map vulnerabilities like CWE-134 to your infrastructure
EchelonGraph correlates every CVE — across CWE-134 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →