CWE-134 · 392 записей
Use of Externally-Controlled Format String
CVE этого класса
393 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
88Срочно | CVE-2024-23113Готовый эксплойт | A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, Fofortinet · fortiproxy · CWE-134 | Критическая9,8 | KEV | 61,7 % | 15 февр. 2024 г. |
76На этой неделе | CVE-2019-1579Готовый эксплойт | Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with GlobalProtect Portal or paloaltonetworks · pan-os · CWE-134 | Высокая8,1 | KEV | 46,2 % | 19 июл. 2019 г. |
69На этой неделе | CVE-2020-3118Готовый эксплойт | Cisco IOS XR Software Cisco Discovery Protocol Format String Vulnerabilitycisco · ios xr · CWE-134 | Высокая8,8 | KEV | 11,7 % | 5 февр. 2020 г. |
63На этой неделе | CVE-2020-13160Готовый эксплойт | AnyDesk before 5.5.3 on Linux and FreeBSD has a format string vulnerability that can be exploited for remote code execution.anydesk · anydesk · CWE-134 | Критическая9,8 | — | 80,6 % | 9 июн. 2020 г. |
60На этой неделе | CVE-2012-1851Эксплойта нет | Format string vulnerability in the Print Spooler service in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Wimicrosoft · windows 7 · CWE-134 | Критическая10,0 | — | 65,6 % | 14 авг. 2012 г. |
56В плане | CVE-2023-22374Эксплойта нет | iControl SOAP vulnerabilityf5 · big-ip access policy manager · CWE-134 | Высокая8,5 | — | 72,6 % | 1 февр. 2023 г. |
51В плане | CVE-2012-3569Готовый эксплойт | Format string vulnerability in VMware OVF Tool 2.1 on Windows, as used in VMware Workstation 8.x before 8.0.5, VMware Player 4.x before 4.0.vmware · ovf tool · CWE-134 | Критическая9,3 | — | 47,7 % | 14 нояб. 2012 г. |
49В плане | CVE-2018-6317Готовый эксплойт | The remote management interface in Claymore Dual Miner 10.5 and earlier is vulnerable to an unauthenticated format string vulnerability, allclaymore dual miner project · claymore dual miner · CWE-134 | Критическая9,1 | — | 43,7 % | 2 февр. 2018 г. |
48В плане | CVE-2009-4769Готовый эксплойт | Multiple format string vulnerabilities in the tolog function in httpdx 1.4, 1.4.5, 1.4.6, 1.4.6b, and 1.5 allow (1) remote attackers to execjasper · httpdx · CWE-134 | Критическая9,3 | — | 37,9 % | 20 апр. 2010 г. |
47В плане | CVE-2012-2288Готовый эксплойт | Format string vulnerability in the nsrd RPC service in EMC NetWorker 7.6.3 and 7.6.4 before 7.6.4.1, and 8.0 before 8.0.0.1, allows remote aemc · networker · CWE-134 | Критическая9,3 | — | 33,1 % | 4 сент. 2012 г. |
46В плане | CVE-2015-8617Proof of concept | Format string vulnerability in the zend_throw_or_error function in Zend/zend_execute_API.c in PHP 7.x before 7.0.1 allows remote attackers tphp · php · CWE-134 | Критическая9,8 | — | 22,8 % | 19 янв. 2016 г. |
46В плане | CVE-2010-1039Proof of concept | Format string vulnerability in the _msgout function in rpc.pcnfsd in IBM AIX 6.1, 5.3, and earlier; IBM VIOS 2.1, 1.5, and earlier; NFS/ONCpibm · aix · CWE-134 | Критическая10,0 | — | 20,2 % | 20 мая 2010 г. |
46В плане | CVE-2008-3533Proof of concept | Format string vulnerability in the window_error function in yelp-window.c in yelp in Gnome after 2.19.90 and before 2.24 allows remote attacgnome · yelp · CWE-134 | Критическая10,0 | — | 19,4 % | 18 авг. 2008 г. |
46В плане | CVE-2011-1568Proof of concept | Format string vulnerability in the logText function in shmemmgr9.dll in IGSSdataServer.exe 9.00.00.11074, and 9.00.00.11063 and earlier, in 7t · igss · CWE-134 | Критическая10,0 | — | 19,4 % | 5 апр. 2011 г. |
45В плане | CVE-2011-0270Эксплойта нет | Format string vulnerability in nnmRptConfig.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to executhp · openview network node manager · CWE-134 | Критическая10,0 | — | 16,3 % | 13 янв. 2011 г. |
45В плане | CVE-2009-3732Proof of concept | Format string vulnerability in vmware-vmrc.exe build 158248 in VMware Remote Console (aka VMrc) allows remote attackers to execute arbitraryvmware · ace · CWE-134 | Критическая10,0 | — | 16,2 % | 12 апр. 2010 г. |
45В плане | CVE-2009-1210Proof of concept | Format string vulnerability in the PROFINET/DCP (PN-DCP) dissector in Wireshark 1.0.6 and earlier allows remote attackers to execute arbitrawireshark · wireshark · CWE-134 | Критическая10,0 | — | 15,2 % | 1 апр. 2009 г. |
44В плане | CVE-2009-3663Proof of concept | Format string vulnerability in the h_readrequest function in http.c in httpdx Web Server 1.4 allows remote attackers to cause a denial of sejasper · httpdx · CWE-134 | Критическая10,0 | — | 14,6 % | 11 окт. 2009 г. |
44В плане | CVE-2010-1550Эксплойта нет | Format string vulnerability in ovet_demandpoll.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackershp · openview network node manager · CWE-134 | Критическая10,0 | — | 11,8 % | 13 мая 2010 г. |
43В плане | CVE-2006-0200Эксплойта нет | Format string vulnerability in the error-reporting feature in the mysqli extension in PHP 5.1.0 and 5.1.1 might allow remote attackers to exphp · php · CWE-134 | Критическая9,3 | — | 19,4 % | 13 янв. 2006 г. |
43В плане | CVE-2006-1615Эксплойта нет | Multiple format string vulnerabilities in the logging code in Clam AntiVirus (ClamAV) before 0.88.1 might allow remote attackers to execute clamav · clamav · CWE-134 | Критическая10,0 | — | 11,6 % | 6 апр. 2006 г. |
43В плане | CVE-2005-3656Эксплойта нет | Multiple format string vulnerabilities in logging functions in mod_auth_pgsql before 2.0.3, when used for user authentication against a Postguiseppe tanzilli and matthias eckermann · mod auth pgsql · CWE-134 | Критическая10,0 | — | 8,9 % | 31 дек. 2005 г. |
42В плане | CVE-2008-5982Эксплойта нет | Format string vulnerability in BMC PATROL Agent before 3.7.30 allows remote attackers to execute arbitrary code via format string specifiersbmc · patrol agent · CWE-134 | Критическая10,0 | — | 7,8 % | 27 янв. 2009 г. |
42В плане | CVE-2007-5561Эксплойта нет | Format string vulnerability in the logging function in the Oracle OPMN daemon, as used on Oracle Enterprise Grid Console server 10.2.0.1, aloracle · enterprise grid console server · CWE-134 | Критическая10,0 | — | 7,7 % | 18 окт. 2007 г. |
42В плане | CVE-2008-0764Proof of concept | Format string vulnerability in the logging function in Larson Network Print Server (LstNPS) 9.4.2 build 105 and earlier for Windows might allarson software technology · network print server · CWE-134 | Критическая10,0 | — | 7,4 % | 13 февр. 2008 г. |
- CVE-2024-2311388Срочно
A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, Fo
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 62 %fortinet · fortiproxy15 февр. 2024 г.
- CVE-2019-157976На этой неделе
Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with GlobalProtect Portal or
ВысокаяCVSS 8,1KEVГотовый эксплойтEPSS 46 %paloaltonetworks · pan-os19 июл. 2019 г.
- CVE-2020-311869На этой неделе
Cisco IOS XR Software Cisco Discovery Protocol Format String Vulnerability
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 12 %cisco · ios xr5 февр. 2020 г.
- CVE-2020-1316063На этой неделе
AnyDesk before 5.5.3 on Linux and FreeBSD has a format string vulnerability that can be exploited for remote code execution.
КритическаяCVSS 9,8Готовый эксплойтEPSS 81 %anydesk · anydesk9 июн. 2020 г.
- CVE-2012-185160На этой неделе
Format string vulnerability in the Print Spooler service in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Wi
КритическаяCVSS 10,0Эксплойта нетEPSS 66 %microsoft · windows 714 авг. 2012 г.
- CVE-2023-2237456В плане
iControl SOAP vulnerability
ВысокаяCVSS 8,5Эксплойта нетEPSS 73 %f5 · big-ip access policy manager1 февр. 2023 г.
- CVE-2012-356951В плане
Format string vulnerability in VMware OVF Tool 2.1 on Windows, as used in VMware Workstation 8.x before 8.0.5, VMware Player 4.x before 4.0.
КритическаяCVSS 9,3Готовый эксплойтEPSS 48 %vmware · ovf tool14 нояб. 2012 г.
- CVE-2018-631749В плане
The remote management interface in Claymore Dual Miner 10.5 and earlier is vulnerable to an unauthenticated format string vulnerability, all
КритическаяCVSS 9,1Готовый эксплойтEPSS 44 %claymore dual miner project · claymore dual miner2 февр. 2018 г.
- CVE-2009-476948В плане
Multiple format string vulnerabilities in the tolog function in httpdx 1.4, 1.4.5, 1.4.6, 1.4.6b, and 1.5 allow (1) remote attackers to exec
КритическаяCVSS 9,3Готовый эксплойтEPSS 38 %jasper · httpdx20 апр. 2010 г.
- CVE-2012-228847В плане
Format string vulnerability in the nsrd RPC service in EMC NetWorker 7.6.3 and 7.6.4 before 7.6.4.1, and 8.0 before 8.0.0.1, allows remote a
КритическаяCVSS 9,3Готовый эксплойтEPSS 33 %emc · networker4 сент. 2012 г.
- CVE-2015-861746В плане
Format string vulnerability in the zend_throw_or_error function in Zend/zend_execute_API.c in PHP 7.x before 7.0.1 allows remote attackers t
КритическаяCVSS 9,8Proof of conceptEPSS 23 %php · php19 янв. 2016 г.
- CVE-2010-103946В плане
Format string vulnerability in the _msgout function in rpc.pcnfsd in IBM AIX 6.1, 5.3, and earlier; IBM VIOS 2.1, 1.5, and earlier; NFS/ONCp
КритическаяCVSS 10,0Proof of conceptEPSS 20 %ibm · aix20 мая 2010 г.
- CVE-2008-353346В плане
Format string vulnerability in the window_error function in yelp-window.c in yelp in Gnome after 2.19.90 and before 2.24 allows remote attac
КритическаяCVSS 10,0Proof of conceptEPSS 19 %gnome · yelp18 авг. 2008 г.
- CVE-2011-156846В плане
Format string vulnerability in the logText function in shmemmgr9.dll in IGSSdataServer.exe 9.00.00.11074, and 9.00.00.11063 and earlier, in
КритическаяCVSS 10,0Proof of conceptEPSS 19 %7t · igss5 апр. 2011 г.
- CVE-2011-027045В плане
Format string vulnerability in nnmRptConfig.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execut
КритическаяCVSS 10,0Эксплойта нетEPSS 16 %hp · openview network node manager13 янв. 2011 г.
- CVE-2009-373245В плане
Format string vulnerability in vmware-vmrc.exe build 158248 in VMware Remote Console (aka VMrc) allows remote attackers to execute arbitrary
КритическаяCVSS 10,0Proof of conceptEPSS 16 %vmware · ace12 апр. 2010 г.
- CVE-2009-121045В плане
Format string vulnerability in the PROFINET/DCP (PN-DCP) dissector in Wireshark 1.0.6 and earlier allows remote attackers to execute arbitra
КритическаяCVSS 10,0Proof of conceptEPSS 15 %wireshark · wireshark1 апр. 2009 г.
- CVE-2009-366344В плане
Format string vulnerability in the h_readrequest function in http.c in httpdx Web Server 1.4 allows remote attackers to cause a denial of se
КритическаяCVSS 10,0Proof of conceptEPSS 15 %jasper · httpdx11 окт. 2009 г.
- CVE-2010-155044В плане
Format string vulnerability in ovet_demandpoll.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers
КритическаяCVSS 10,0Эксплойта нетEPSS 12 %hp · openview network node manager13 мая 2010 г.
- CVE-2006-020043В плане
Format string vulnerability in the error-reporting feature in the mysqli extension in PHP 5.1.0 and 5.1.1 might allow remote attackers to ex
КритическаяCVSS 9,3Эксплойта нетEPSS 19 %php · php13 янв. 2006 г.
- CVE-2006-161543В плане
Multiple format string vulnerabilities in the logging code in Clam AntiVirus (ClamAV) before 0.88.1 might allow remote attackers to execute
КритическаяCVSS 10,0Эксплойта нетEPSS 12 %clamav · clamav6 апр. 2006 г.
- CVE-2005-365643В плане
Multiple format string vulnerabilities in logging functions in mod_auth_pgsql before 2.0.3, when used for user authentication against a Post
КритическаяCVSS 10,0Эксплойта нетEPSS 9 %guiseppe tanzilli and matthias eckermann · mod auth pgsql31 дек. 2005 г.
- CVE-2008-598242В плане
Format string vulnerability in BMC PATROL Agent before 3.7.30 allows remote attackers to execute arbitrary code via format string specifiers
КритическаяCVSS 10,0Эксплойта нетEPSS 8 %bmc · patrol agent27 янв. 2009 г.
- CVE-2007-556142В плане
Format string vulnerability in the logging function in the Oracle OPMN daemon, as used on Oracle Enterprise Grid Console server 10.2.0.1, al
КритическаяCVSS 10,0Эксплойта нетEPSS 8 %oracle · enterprise grid console server18 окт. 2007 г.
- CVE-2008-076442В плане
Format string vulnerability in the logging function in Larson Network Print Server (LstNPS) 9.4.2 build 105 and earlier for Windows might al
КритическаяCVSS 10,0Proof of conceptEPSS 7 %larson software technology · network print server13 февр. 2008 г.