VYPR

CWE-134

Use of Externally-Controlled Format String

BaseDraftLikelihood: High

Description

The product uses a function that accepts a format string as an argument, but the format string originates from an external source.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-135 · CAPEC-67

CVEs mapped to this weakness (400)

page 6 of 20
  • CVE-2021-29740HigJun 1, 2021
    risk 0.51cvss 7.8epss 0.00

    IBM Spectrum Scale 5.0.0 through 5.0.5.6 and 5.1.0 through 5.1.0.3 system core component is affected by a format string security vulnerability. An attacker could execute arbitrary code in the context of process memory, potentially escalating their system privileges and taking…

  • CVE-2018-17336HigSep 22, 2018
    risk 0.51cvss 7.8epss 0.01

    UDisks 2.8.0 has a format string vulnerability in udisks_log in udiskslogging.c, allowing attackers to obtain sensitive information (stack contents), cause a denial of service (memory corruption), or possibly have unspecified other impact via a malformed filesystem label, as…

  • CVE-2018-16554HigSep 16, 2018
    risk 0.51cvss 7.8epss 0.02

    The ProcessGpsInfo function of the gpsinfo.c file of jhead 3.00 may allow a remote attacker to cause a denial-of-service attack or unspecified other impact via a malicious JPEG file, because of inconsistency between float and double in a sprintf format string during TAG_GPS_ALT…

  • CVE-2015-8107HigApr 13, 2017
    risk 0.51cvss 7.8epss 0.03

    Format string vulnerability in GNU a2ps 4.14 allows remote attackers to execute arbitrary code.

  • CVE-2017-5613HigMar 3, 2017
    risk 0.51cvss 7.8epss 0.03

    Format string vulnerability in cgiemail and cgiecho allows remote attackers to execute arbitrary code via format string specifiers in a template file.

  • CVE-2015-8106HigApr 18, 2016
    risk 0.51cvss 7.8epss 0.04

    Format string vulnerability in the CmdKeywords function in funct1.c in latex2rtf before 2.3.10 allows remote attackers to execute arbitrary code via format string specifiers in the \keywords command in a crafted TeX file.

  • CVE-2023-35086HigJul 21, 2023
    risk 0.50cvss 7.2epss 0.39

    It is identified a format string vulnerability in ASUS RT-AX56U V2 & RT-AC86U. This vulnerability is caused by directly using input as a format string when calling syslog in logmessage_normal function, in the do_detwan_cgi module of httpd. A remote attacker with administrator…

  • CVE-2026-3509HigMar 24, 2026
    risk 0.49cvss 7.5epss 0.00

    An unauthenticated remote attacker may be able to control the format string of messages processed by the Audit Log of the CODESYS Control runtime system, potentially resulting in a denial‑of‑service (DoS) condition.

  • CVE-2026-22190HigJan 7, 2026
    risk 0.49cvss 7.5epss 0.00

    The egg-mkfont utility in Panda3D versions up to and including 1.10.16 contains an uncontrolled format string vulnerability. The -gp (glyph pattern) command-line option is used directly as the format string for sprintf() with only a single argument supplied. If an attacker…

  • CVE-2025-36202HigSep 22, 2025
    risk 0.49cvss 7.5epss 0.00

    IBM webMethods Integration 10.15 and 11.1 could allow an authenticated user with required execute Services to execute commands on the system due to the improper validation of format string strings passed as an argument from an external source.

  • CVE-2024-39529HigJul 11, 2024
    risk 0.49cvss 7.5epss 0.00

    A Use of Externally-Controlled Format String vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). If DNS Domain Generation Algorithm (DGA)…

  • CVE-2023-24590HigDec 18, 2023
    risk 0.49cvss 7.5epss 0.01

    A format string issue in the Controller 6000's optional diagnostic web interface can be used to write/read from memory, and in some instances crash the Controller 6000 leading to a Denial of Service. This issue affects: Gallagher Controller 6000 8.60 prior to vCR8.60.231116a…

  • CVE-2022-31753HigJun 13, 2022
    risk 0.49cvss 7.5epss 0.01

    The voice wakeup module has a vulnerability of using externally-controlled format strings. Successful exploitation of this vulnerability may affect system availability.

  • CVE-2020-27523HigNov 11, 2020
    risk 0.49cvss 7.5epss 0.02

    Solstice-Pod up to 5.0.2 WEBRTC server mishandles the format-string specifiers %x; %p; %c and %s in the screen_key, display_name, browser_name, and operation_system parameter during the authentication process. This may crash the server and force Solstice-Pod to reboot, which…

  • CVE-2019-11287HigNov 23, 2019
    risk 0.49cvss 7.5epss 0.05

    Pivotal RabbitMQ, versions 3.7.x prior to 3.7.21 and 3.8.x prior to 3.8.1, and RabbitMQ for Pivotal Platform, 1.16.x versions prior to 1.16.7 and 1.17.x versions prior to 1.17.4, contain a web management plugin that is vulnerable to a denial of service attack. The "X-Reason"…

  • CVE-2019-15547HigAug 26, 2019
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in the ncurses crate through 5.99.0 for Rust. There are format string issues in printw functions because C format arguments are mishandled.

  • CVE-2019-15546HigAug 26, 2019
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in the pancurses crate through 0.16.1 for Rust. printw and mvprintw have format string vulnerabilities.

  • CVE-2016-10745HigApr 8, 2019
    risk 0.49cvss 8.6epss 0.03

    In Pallets Jinja before 2.8.1, str.format allows a sandbox escape.

  • CVE-2019-7715HigMar 26, 2019
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in the Interpeak IPCOMShell TELNET server on Green Hills INTEGRITY RTOS 5.0.4. The main shell handler function uses the value of the environment variable ipcom.shell.greeting as the first argument to printf(). Setting this variable using the sysvar…

  • CVE-2019-7712HigMar 26, 2019
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in handler_ipcom_shell_pwd in the Interpeak IPCOMShell TELNET server on Green Hills INTEGRITY RTOS 5.0.4. When using the pwd command, the current working directory path is used as the first argument to printf() without a proper check. An attacker may thus…