VYPR

CWE-134

Use of Externally-Controlled Format String

BaseDraftLikelihood: High

Description

The product uses a function that accepts a format string as an argument, but the format string originates from an external source.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-135 · CAPEC-67

CVEs mapped to this weakness (400)

page 4 of 20
  • CVE-2023-33011HigJul 17, 2023
    risk 0.57cvss 8.8epss 0.00

    A format string vulnerability in the Zyxel ATP series firmware versions 5.10 through 5.36 Patch 2, USG FLEX series firmware versions 5.00 through 5.36 Patch 2, USG FLEX 50(W) series firmware versions 5.10 through 5.36 Patch 2, USG20(W)-VPN series firmware versions 5.10 through…

  • CVE-2022-3023CriNov 4, 2022
    risk 0.57cvss 9.8epss 0.01

    Use of Externally-Controlled Format String in GitHub repository pingcap/tidb prior to 6.4.0, 6.1.3.

  • CVE-2022-35887HigOct 25, 2022
    risk 0.57cvss 8.8epss 0.01

    Four format string injection vulnerabilities exist in the web interface /action/wirelessConnect functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z and 6.9X. A specially-crafted HTTP request can lead to memory corruption, information disclosure and denial of…

  • CVE-2022-35886HigOct 25, 2022
    risk 0.57cvss 8.8epss 0.01

    Four format string injection vulnerabilities exist in the web interface /action/wirelessConnect functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z and 6.9X. A specially-crafted HTTP request can lead to memory corruption, information disclosure and denial of…

  • CVE-2022-35885HigOct 25, 2022
    risk 0.57cvss 8.8epss 0.01

    Four format string injection vulnerabilities exist in the web interface /action/wirelessConnect functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z and 6.9X. A specially-crafted HTTP request can lead to memory corruption, information disclosure and denial of…

  • CVE-2022-35884HigOct 25, 2022
    risk 0.57cvss 8.8epss 0.01

    Four format string injection vulnerabilities exist in the web interface /action/wirelessConnect functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z and 6.9X. A specially-crafted HTTP request can lead to memory corruption, information disclosure and denial of…

  • CVE-2022-35881HigOct 25, 2022
    risk 0.57cvss 8.8epss 0.01

    Four format string injection vulnerabilities exist in the UPnP logging functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z and 6.9X. A specially-crafted UPnP negotiation can lead to memory corruption, information disclosure, and denial of service. An attacker…

  • CVE-2022-35880HigOct 25, 2022
    risk 0.57cvss 8.8epss 0.01

    Four format string injection vulnerabilities exist in the UPnP logging functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z and 6.9X. A specially-crafted UPnP negotiation can lead to memory corruption, information disclosure, and denial of service. An attacker…

  • CVE-2022-35879HigOct 25, 2022
    risk 0.57cvss 8.8epss 0.01

    Four format string injection vulnerabilities exist in the UPnP logging functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z and 6.9X. A specially-crafted UPnP negotiation can lead to memory corruption, information disclosure, and denial of service. An attacker…

  • CVE-2022-35878HigOct 25, 2022
    risk 0.57cvss 8.8epss 0.01

    Four format string injection vulnerabilities exist in the UPnP logging functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z and 6.9X. A specially-crafted UPnP negotiation can lead to memory corruption, information disclosure, and denial of service. An attacker…

  • CVE-2022-27177CriApr 1, 2022
    risk 0.57cvss 9.8epss 0.02

    A Python format string issue leading to information disclosure and potentially remote code execution in ConsoleMe for all versions prior to 1.2.2

  • CVE-2021-41193CriMar 1, 2022
    risk 0.57cvss 9.8epss 0.02

    wire-avs is the audio visual signaling (AVS) component of Wire, an open-source messenger. A remote format string vulnerability in versions prior to 7.1.12 allows an attacker to cause a denial of service or possibly execute arbitrary code. The issue has been fixed in wire-avs…

  • CVE-2021-43041HigDec 6, 2021
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. A crafted HTTP request could induce a format string vulnerability in the privileged vaultServer application.

  • CVE-2021-33535HigJun 25, 2021
    risk 0.57cvss 8.8epss 0.02

    In Weidmueller Industrial WLAN devices in multiple versions an exploitable format string vulnerability exists in the iw_console conio_writestr functionality. A specially crafted time server entry can cause an overflow of the time server buffer, resulting in remote code…

  • CVE-2020-29018HigJan 14, 2021
    risk 0.57cvss 8.8epss 0.02

    A format string vulnerability in FortiWeb 6.3.0 through 6.3.5 may allow an authenticated, remote attacker to read the content of memory and retrieve sensitive data via the redir parameter.

  • CVE-2020-35869CriDec 31, 2020
    risk 0.57cvss 9.8epss 0.02

    An issue was discovered in the rusqlite crate before 0.23.0 for Rust. Memory safety can be violated because rusqlite::trace::log mishandles format strings.

  • CVE-2016-10773HigAug 5, 2019
    risk 0.57cvss 8.8epss 0.01

    cPanel before 60.0.25 allows format-string injection in exception-message handling (SEC-171).

  • CVE-2019-7228HigJun 27, 2019
    risk 0.57cvss 8.8epss 0.04

    The ABB IDAL HTTP server mishandles format strings in a username or cookie during the authentication process. Attempting to authenticate with the username %25s%25p%25x%25n will crash the server. Sending %08x.AAAA.%08x.%08x will log memory content from the stack.

  • CVE-2019-7230HigJun 24, 2019
    risk 0.57cvss 8.8epss 0.04

    The ABB IDAL FTP server mishandles format strings in a username during the authentication process. Attempting to authenticate with the username %s%p%x%d will crash the server. Sending %08x.AAAA.%08x.%08x will log memory content from the stack.

  • CVE-2017-16602HigJan 23, 2018
    risk 0.57cvss 8.8epss 0.03

    This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of NetGain Systems Enterprise Manager 7.2.730 build 1034. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed.…