VYPR

CWE-134

Use of Externally-Controlled Format String

BaseDraftLikelihood: High

Description

The product uses a function that accepts a format string as an argument, but the format string originates from an external source.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-135 · CAPEC-67

CVEs mapped to this weakness (408)

page 16 of 21
  • CVE-2025-48388MedMay 29, 2025
    risk 0.00cvss 6.5epss 0.00

    FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.178, the application performs insufficient validation of user-supplied data, which is used as arguments to string formatting functions. As a result, an attacker can pass a string containing…

  • CVE-2023-48221HigNov 20, 2023
    risk 0.00cvss 7.3epss 0.01

    wire-avs provides Audio, Visual, and Signaling (AVS) functionality sure the secure messaging software Wire. Prior to versions 9.2.22 and 9.3.5, a remote format string vulnerability could potentially allow an attacker to cause a denial of service or possibly execute arbitrary…

  • CVE-2023-25815LowApr 25, 2023
    risk 0.00cvss 3.3epss 0.01

    In Git for Windows, the Windows port of Git, no localized messages are shipped with the installer. As a consequence, Git is expected not to localize messages at all, and skips the gettext initialization. However, due to a change in MINGW-packages, the `gettext()` function's…

  • CVE-2022-4639MedDec 21, 2022
    risk 0.00cvss 5.6epss 0.01

    A vulnerability, which was classified as critical, has been found in sslh. This issue affects the function hexdump of the file probe.c of the component Packet Dumping Handler. The manipulation of the argument msg_info leads to format string. The attack may be initiated remotely.…

  • CVE-2022-2652MedAug 4, 2022
    risk 0.00cvss 6.0epss 0.00

    Depending on the way the format strings in the card label are crafted it's possible to leak kernel stack memory. There is also the possibility for DoS due to the v4l2loopback kernel module crashing when providing the card label on request (reproduce e.g. with many %s modifiers…

  • CVE-2021-32785MedJul 22, 2021
    risk 0.00cvss 5.3epss 0.03

    mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Relying Party, authenticating users against an OpenID Connect Provider. When mod_auth_openidc versions prior to 2.4.9 are configured to use an…

  • CVE-2021-35331HigJul 5, 2021
    risk 0.00cvss 7.8epss 0.02

    In Tcl 8.6.11, a format string vulnerability in nmakehlp.c might allow code execution via a crafted file. NOTE: multiple third parties dispute the significance of this finding

  • CVE-2021-30145HigMay 18, 2021
    risk 0.00cvss 7.8epss 0.02

    A format string vulnerability in mpv through 0.33.0 allows user-assisted remote attackers to achieve code execution via a crafted m3u playlist file.

  • CVE-2018-1000052HigFeb 9, 2018
    risk 0.00cvss 7.5epss 0.01

    fmtlib version prior to version 4.1.0 (before commit 0555cea5fc0bf890afe0071a558e44625a34ba85) contains a Memory corruption (SIGSEGV), CWE-134 vulnerability in fmt::print() library function that can result in Denial of Service. This attack appear to be exploitable via Specifying…

  • CVE-2015-6285Sep 14, 2015
    risk 0.00cvss —epss 0.01

    Format string vulnerability in Cisco Email Security Appliance (ESA) 7.6.0 and 8.0.0 allows remote attackers to cause a denial of service (memory overwrite or service outage) via format string specifiers in an HTTP request, aka Bug ID CSCug21497.

  • CVE-2014-8625Jan 20, 2015
    risk 0.00cvss —epss 0.03

    Multiple format string vulnerabilities in the parse_error_msg function in parsehelp.c in dpkg before 1.17.22 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in the (1) package or (2) architecture name.

  • CVE-2013-2131Jan 4, 2015
    risk 0.00cvss —epss 0.11

    Format string vulnerability in the rrdtool module 1.4.7 for Python, as used in Zenoss, allows context-dependent attackers to cause a denial of service (crash) via format string specifiers to the rrdtool.graph function.

  • CVE-2014-9157Dec 3, 2014
    risk 0.00cvss —epss 0.06

    Format string vulnerability in the yyerror function in lib/cgraph/scan.l in Graphviz allows remote attackers to have unspecified impact via format string specifiers in unknown vectors, which are not properly handled in an error string.

  • CVE-2013-7386Jun 2, 2014
    risk 0.00cvss —epss 0.04

    Format string vulnerability in the PROJECT::write_account_file function in client/cs_account.cpp in BOINC, possibly 7.2.33, allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via format string specifiers in the gui_urls item in an…

  • CVE-2014-1315Apr 23, 2014
    risk 0.00cvss —epss 0.02

    Format string vulnerability in CoreServicesUIAgent in Apple OS X 10.9.x through 10.9.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via format string specifiers in a URL.

  • CVE-2011-4930Feb 10, 2014
    risk 0.00cvss —epss 0.01

    Multiple format string vulnerabilities in Condor 7.2.0 through 7.6.4, and possibly certain 7.7.x versions, as used in Red Hat MRG Grid and possibly other products, allow local users to cause a denial of service (condor_schedd daemon and failure to launch jobs) and possibly…

  • CVE-2013-1886Jan 24, 2014
    risk 0.00cvss —epss 0.02

    Format string vulnerability in the token processing system (pki-tps) in Red Hat Certificate System (RHCS) 8.1 and possibly Dogtag Certificate System 9 and 10 allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via format…

  • CVE-2013-6809Dec 13, 2013
    risk 0.00cvss —epss 0.03

    Format string vulnerability in the client in Tftpd32 before 4.50 allows remote servers to cause a denial of service (crash) or possibly execute arbitrary code via format string specifiers in the Remote File field.

  • CVE-2013-4389Oct 17, 2013
    risk 0.00cvss —epss 0.03

    Multiple format string vulnerabilities in log_subscriber.rb files in the log subscriber component in Action Mailer in Ruby on Rails 3.x before 3.2.15 allow remote attackers to cause a denial of service via a crafted e-mail address that is improperly handled during construction…

  • CVE-2013-4258Oct 9, 2013
    risk 0.00cvss —epss 0.04

    Format string vulnerability in the osLogMsg function in server/os/aulog.c in Network Audio System (NAS) 1.9.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in unspecified vectors, related to syslog.