CWE-134— Use of Externally-Controlled Format String
The product uses a function that accepts a format string as an argument, but the format string originates from an external source.— MITRE CWE catalog
391 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-134page 4 of 8
- CVE-2012-2369HIGHCVSS v2 7.5EG 7.52012-05-23
Format string vulnerability in the log_message_cb function in otr-plugin.c in the Off-the-Record Messaging (OTR) pidgin-otr plugin before 3.2.1 for Pidgin might allow remote attackers to execute arbitrary code via format string specifiers …
- CVE-2012-3569HIGHCVSS v2 9.3EG 9.32012-11-14
Format string vulnerability in VMware OVF Tool 2.1 on Windows, as used in VMware Workstation 8.x before 8.0.5, VMware Player 4.x before 4.0.5, and other products, allows user-assisted remote attackers to execute arbitrary code via a crafte…
- CVE-2012-4426MEDIUMCVSS v2 6.8EG 6.82012-11-21
Multiple format string vulnerabilities in mcrypt 2.6.8 and earlier might allow user-assisted remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via vectors involving (1) errors.c or (2) mcrypt.c.
- CVE-2013-0929HIGHCVSS v2 7.6EG 7.62013-01-21
Format string vulnerability in the _vsnsprintf function in rrobotd.exe in the Device Manager in EMC AlphaStor 4.0 before build 800 allows remote attackers to execute arbitrary code via format string specifiers in a command.
- CVE-2013-1886HIGHCVSS v2 7.5EG 7.52014-01-24
Format string vulnerability in the token processing system (pki-tps) in Red Hat Certificate System (RHCS) 8.1 and possibly Dogtag Certificate System 9 and 10 allows remote authenticated users to cause a denial of service (crash) and possib…
- CVE-2013-2131MEDIUMCVSS v2 5.0EG 5.02015-01-04
Format string vulnerability in the rrdtool module 1.4.7 for Python, as used in Zenoss, allows context-dependent attackers to cause a denial of service (crash) via format string specifiers to the rrdtool.graph function.
- CVE-2013-2851MEDIUMCVSS v2 6.0EG 6.02013-06-07
Format string vulnerability in the register_disk function in block/genhd.c in the Linux kernel through 3.9.4 allows local users to gain privileges by leveraging root access and writing format string specifiers to /sys/module/md_mod/paramet…
- CVE-2013-2852MEDIUMCVSS v2 6.9EG 6.92013-06-07
Format string vulnerability in the b43_request_firmware function in drivers/net/wireless/b43/main.c in the Broadcom B43 wireless driver in the Linux kernel through 3.9.4 allows local users to gain privileges by leveraging root access and i…
- CVE-2013-3560MEDIUMCVSS v2 5.0EG 5.02013-05-25
The dissect_dsmcc_un_download function in epan/dissectors/packet-mpeg-dsmcc.c in the MPEG DSM-CC dissector in Wireshark 1.8.x before 1.8.7 uses an incorrect format string, which allows remote attackers to cause a denial of service (applica…
- CVE-2013-4147HIGHCVSS v2 7.5EG 7.52013-08-09
Multiple format string vulnerabilities in Yet Another Radius Daemon (YARD RADIUS) 1.1.2 allow context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via format string specifiers in a request in …
- CVE-2013-4258HIGHCVSS v2 7.5EG 7.52013-10-09
Format string vulnerability in the osLogMsg function in server/os/aulog.c in Network Audio System (NAS) 1.9.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in …
- CVE-2013-5135HIGHCVSS v2 7.5EG 7.52013-10-24
Format string vulnerability in Screen Sharing Server in Apple Mac OS X before 10.9 and Apple Remote Desktop before 3.5.4 allows remote attackers to execute arbitrary code via format string specifiers in a VNC username.
- CVE-2013-6809MEDIUMCVSS v2 5.0EG 5.02013-12-13
Format string vulnerability in the client in Tftpd32 before 4.50 allows remote servers to cause a denial of service (crash) or possibly execute arbitrary code via format string specifiers in the Remote File field.
- CVE-2013-7386MEDIUMCVSS v2 5.0EG 5.02014-06-02
Format string vulnerability in the PROJECT::write_account_file function in client/cs_account.cpp in BOINC, possibly 7.2.33, allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via format string s…
- CVE-2014-1315MEDIUMCVSS v2 6.8EG 6.82014-04-23
Format string vulnerability in CoreServicesUIAgent in Apple OS X 10.9.x through 10.9.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via format string specifiers in a URL.
- CVE-2014-1683MEDIUMCVSS v2 6.8EG 6.82014-01-29
The bashMail function in cms/data/skins/techjunkie/fragments/contacts/functions.php in SkyBlueCanvas CMS before 1.1 r248-04, when the pid parameter is 4, allows remote attackers to execute arbitrary commands via shell metacharacters in the…
- CVE-2014-6262HIGHCVSS 7.5EG 7.52020-02-12
Multiple format string vulnerabilities in the python module in RRDtool, as used in Zenoss Core before 4.2.5 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted…
- CVE-2014-8170HIGHCVSS 8.8EG 8.82017-09-26
ovirt_safe_delete_config in ovirtfunctions.py and other unspecified locations in ovirt-node 3.0.0-474-gb852fd7 as packaged in Red Hat Enterprise Virtualization 3 do not properly quote input strings, which allows remote authenticated users …
- CVE-2014-8625MEDIUMCVSS v2 6.8EG 6.82015-01-20
Multiple format string vulnerabilities in the parse_error_msg function in parsehelp.c in dpkg before 1.17.22 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in th…
- CVE-2014-9157HIGHCVSS v2 7.5EG 7.52014-12-03
Format string vulnerability in the yyerror function in lib/cgraph/scan.l in Graphviz allows remote attackers to have unspecified impact via format string specifiers in unknown vectors, which are not properly handled in an error string.
- CVE-2015-10088CRITICALCVSS 5.0EG 9.82023-03-05
A vulnerability, which was classified as critical, was found in ayttm up to 0.5.0.89. This affects the function http_connect in the library libproxy/proxy.c. The manipulation leads to format string. It is possible to initiate the attack re…
- CVE-2015-7271CRITICALCVSS 9.8EG 9.82017-04-10
Dell Integrated Remote Access Controller (iDRAC) 7/8 before 2.21.21.21 has a format string issue in racadm getsystinfo.
- CVE-2015-8106HIGHCVSS 7.8EG 7.82016-04-18
Format string vulnerability in the CmdKeywords function in funct1.c in latex2rtf before 2.3.10 allows remote attackers to execute arbitrary code via format string specifiers in the \keywords command in a crafted TeX file.
- CVE-2015-8107HIGHCVSS 7.8EG 7.82017-04-13
Format string vulnerability in GNU a2ps 4.14 allows remote attackers to execute arbitrary code.
- CVE-2015-8617CRITICALCVSS 9.8EG 9.82016-01-19
Format string vulnerability in the zend_throw_or_error function in Zend/zend_execute_API.c in PHP 7.x before 7.0.1 allows remote attackers to execute arbitrary code via format string specifiers in a string that is misused as a class name, …
- CVE-2015-9238MEDIUMCVSS 5.3EG 5.32018-05-31
secure-compare 3.0.0 and below do not actually compare two strings properly. compare was actually comparing the first argument with itself, meaning the check passed for any two strings of the same length.
- CVE-2016-10745HIGHCVSS 8.6EG 8.62019-04-08
In Pallets Jinja before 2.8.1, str.format allows a sandbox escape.
- CVE-2016-10773HIGHCVSS 8.8EG 8.82019-08-05
cPanel before 60.0.25 allows format-string injection in exception-message handling (SEC-171).
- CVE-2016-1895MEDIUMCVSS 6.5EG 6.52017-09-01
NetApp Data ONTAP before 8.2.5 and 8.3.x before 8.3.2P12 allow remote authenticated users to cause a denial of service via vectors related to unsafe user input string handling.
- CVE-2016-4448CRITICALCVSS 9.8EG 9.82016-06-09
Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vectors.
- CVE-2016-4864HIGHCVSS 7.5EG 7.52017-05-12
H2O versions 2.0.3 and earlier and 2.1.0-beta2 and earlier allows remote attackers to cause a denial-of-service (DoS) via format string specifiers in a template file via fastcgi, mruby, proxy, redirect or reproxy.
- CVE-2016-5074CRITICALCVSS 9.8EG 9.82017-04-10
CloudView NMS before 2.10a has a format string issue exploitable over SNMP.
- CVE-2016-5716HIGHCVSS 8.8EG 8.82017-08-09
The console in Puppet Enterprise 2015.x and 2016.x prior to 2016.4.0 includes unsafe string reads that potentially allows for remote code execution on the console node.
- CVE-2017-0898CRITICALCVSS 9.1EG 9.12017-09-15
Ruby before 2.4.2, 2.3.5, and 2.2.8 is vulnerable to a malicious format string which contains a precious specifier (*) with a huge minus value. Such situation can lead to a buffer overrun, resulting in a heap memory corruption or an inform…
- CVE-2017-10685CRITICALCVSS 9.8EG 9.82017-06-29
In ncurses 6.0, there is a format string vulnerability in the fmt_entry function. A crafted input will lead to a remote arbitrary code execution attack.
- CVE-2017-12588CRITICALCVSS 9.8EG 9.82017-08-06
The zmq3 input and output modules in rsyslog before 8.28.0 interpreted description fields as format strings, possibly allowing a format string attack with unspecified impact.
- CVE-2017-12702HIGHCVSS 8.8EG 8.82017-08-30
An Externally Controlled Format String issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. String format specifiers based on user provided input are not properly validated, which could allow an attacker to execute …
- CVE-2017-15191HIGHCVSS 7.5EG 7.52017-10-10
In Wireshark 2.4.0 to 2.4.1, 2.2.0 to 2.2.9, and 2.0.0 to 2.0.15, the DMP dissector could crash. This was addressed in epan/dissectors/packet-dmp.c by validating a string length.
- CVE-2017-16516HIGHCVSS 7.5EG 7.52017-11-03
In the yajl-ruby gem 1.3.0 for Ruby, when a crafted JSON file is supplied to Yajl::Parser.new.parse, the whole ruby process crashes with a SIGABRT in the yajl_string_decode function in yajl_encode.c. This results in the whole ruby process …
- CVE-2017-16602HIGHCVSS 8.8EG 8.82018-01-23
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of NetGain Systems Enterprise Manager 7.2.730 build 1034. Although authentication is required to exploit this vulnerability, the existing auth…
- CVE-2017-16608CRITICALCVSS 9.8EG 9.82018-01-23
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Netgain Enterprise Manager. Authentication is not required to exploit this vulnerability. The specific flaw exists within exec.jsp. The iss…
- CVE-2017-17132MEDIUMCVSS 5.5EG 5.52018-03-05
Huawei VP9660 V500R002C10 has a uncontrolled format string vulnerability when the license module output the log information. An authenticated local attacker could exploit this vulnerability to cause a denial of service.
- CVE-2017-17407CRITICALCVSS 9.8EG 9.82018-01-23
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of NetGain Systems Enterprise Manager v7.2.699 build 1001. Authentication is not required to exploit this vulnerability. The specific flaw exi…
- CVE-2017-2403HIGHCVSS 8.8EG 8.82017-04-02
An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "Printing" component. A format-string vulnerability allows remote attackers to execute arbitrary code via a crafted ipp: or ipps: U…
- CVE-2017-3859HIGHCVSS 7.5EG 7.52017-03-22
A vulnerability in the DHCP code for the Zero Touch Provisioning feature of Cisco ASR 920 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability is due t…
- CVE-2017-5524MEDIUMCVSS 4.3EG 4.32017-03-23
Plone 4.x through 4.3.11 and 5.x through 5.0.6 allow remote attackers to bypass a sandbox protection mechanism and obtain sensitive information by leveraging the Python string format method.
- CVE-2017-5613HIGHCVSS 7.8EG 7.82017-03-03
Format string vulnerability in cgiemail and cgiecho allows remote attackers to execute arbitrary code via format string specifiers in a template file.
- CVE-2017-7519MEDIUMCVSS 2.3EG 4.42018-07-27
In Ceph, a format string flaw was found in the way libradosstriper parses input from user. A user could crash an application or service using the libradosstriper library.
- CVE-2017-9212HIGHCVSS 7.5EG 7.52017-05-23
The Bluetooth stack on the BMW 330i 2011 allows a remote crash of the CD/Multimedia software via %x or %c format string specifiers in a device name.
- CVE-2018-0175CRITICALCVSS 8.0EG 9.0⚠ KEV2018-03-28
Format String vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) …
Map vulnerabilities like CWE-134 to your infrastructure
EchelonGraph correlates every CVE — across CWE-134 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →