İçeriğe atla
Noroxi

CWE-134 · 392 kayıt

Use of Externally-Controlled Format String

Bu sınıftaki CVE’ler

392 kayıt

  • A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, Fo

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %62

    fortinet · fortiproxy15 Şub 2024

  • CVE-2019-1579
    76Bu hafta

    Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with GlobalProtect Portal or

    YüksekCVSS 8,1KEVSilahlaştırılmışEPSS %46

    paloaltonetworks · pan-os19 Tem 2019

  • CVE-2020-3118
    69Bu hafta

    Cisco IOS XR Software Cisco Discovery Protocol Format String Vulnerability

    YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %12

    cisco · ios xr5 Şub 2020

  • CVE-2020-13160
    63Bu hafta

    AnyDesk before 5.5.3 on Linux and FreeBSD has a format string vulnerability that can be exploited for remote code execution.

    KritikCVSS 9,8SilahlaştırılmışEPSS %81

    anydesk · anydesk9 Haz 2020

  • CVE-2012-1851
    60Bu hafta

    Format string vulnerability in the Print Spooler service in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Wi

    KritikCVSS 10,0İstismar yokEPSS %66

    microsoft · windows 714 Ağu 2012

  • CVE-2023-22374
    56Planlayın

    iControl SOAP vulnerability

    YüksekCVSS 8,5İstismar yokEPSS %73

    f5 · big-ip access policy manager1 Şub 2023

  • CVE-2012-3569
    51Planlayın

    Format string vulnerability in VMware OVF Tool 2.1 on Windows, as used in VMware Workstation 8.x before 8.0.5, VMware Player 4.x before 4.0.

    KritikCVSS 9,3SilahlaştırılmışEPSS %48

    vmware · ovf tool14 Kas 2012

  • CVE-2018-6317
    49Planlayın

    The remote management interface in Claymore Dual Miner 10.5 and earlier is vulnerable to an unauthenticated format string vulnerability, all

    KritikCVSS 9,1SilahlaştırılmışEPSS %44

    claymore dual miner project · claymore dual miner2 Şub 2018

  • CVE-2009-4769
    48Planlayın

    Multiple format string vulnerabilities in the tolog function in httpdx 1.4, 1.4.5, 1.4.6, 1.4.6b, and 1.5 allow (1) remote attackers to exec

    KritikCVSS 9,3SilahlaştırılmışEPSS %38

    jasper · httpdx20 Nis 2010

  • CVE-2012-2288
    47Planlayın

    Format string vulnerability in the nsrd RPC service in EMC NetWorker 7.6.3 and 7.6.4 before 7.6.4.1, and 8.0 before 8.0.0.1, allows remote a

    KritikCVSS 9,3SilahlaştırılmışEPSS %33

    emc · networker4 Eyl 2012

  • CVE-2015-8617
    46Planlayın

    Format string vulnerability in the zend_throw_or_error function in Zend/zend_execute_API.c in PHP 7.x before 7.0.1 allows remote attackers t

    KritikCVSS 9,8Kavram kanıtıEPSS %23

    php · php19 Oca 2016

  • CVE-2010-1039
    46Planlayın

    Format string vulnerability in the _msgout function in rpc.pcnfsd in IBM AIX 6.1, 5.3, and earlier; IBM VIOS 2.1, 1.5, and earlier; NFS/ONCp

    KritikCVSS 10,0Kavram kanıtıEPSS %20

    ibm · aix20 May 2010

  • CVE-2008-3533
    46Planlayın

    Format string vulnerability in the window_error function in yelp-window.c in yelp in Gnome after 2.19.90 and before 2.24 allows remote attac

    KritikCVSS 10,0Kavram kanıtıEPSS %19

    gnome · yelp18 Ağu 2008

  • CVE-2011-1568
    46Planlayın

    Format string vulnerability in the logText function in shmemmgr9.dll in IGSSdataServer.exe 9.00.00.11074, and 9.00.00.11063 and earlier, in

    KritikCVSS 10,0Kavram kanıtıEPSS %19

    7t · igss5 Nis 2011

  • CVE-2011-0270
    45Planlayın

    Format string vulnerability in nnmRptConfig.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execut

    KritikCVSS 10,0İstismar yokEPSS %16

    hp · openview network node manager13 Oca 2011

  • CVE-2009-3732
    45Planlayın

    Format string vulnerability in vmware-vmrc.exe build 158248 in VMware Remote Console (aka VMrc) allows remote attackers to execute arbitrary

    KritikCVSS 10,0Kavram kanıtıEPSS %16

    vmware · ace12 Nis 2010

  • CVE-2009-1210
    45Planlayın

    Format string vulnerability in the PROFINET/DCP (PN-DCP) dissector in Wireshark 1.0.6 and earlier allows remote attackers to execute arbitra

    KritikCVSS 10,0Kavram kanıtıEPSS %15

    wireshark · wireshark1 Nis 2009

  • CVE-2009-3663
    44Planlayın

    Format string vulnerability in the h_readrequest function in http.c in httpdx Web Server 1.4 allows remote attackers to cause a denial of se

    KritikCVSS 10,0Kavram kanıtıEPSS %15

    jasper · httpdx11 Eki 2009

  • CVE-2010-1550
    44Planlayın

    Format string vulnerability in ovet_demandpoll.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers

    KritikCVSS 10,0İstismar yokEPSS %12

    hp · openview network node manager13 May 2010

  • CVE-2006-0200
    43Planlayın

    Format string vulnerability in the error-reporting feature in the mysqli extension in PHP 5.1.0 and 5.1.1 might allow remote attackers to ex

    KritikCVSS 9,3İstismar yokEPSS %19

    php · php13 Oca 2006

  • CVE-2006-1615
    43Planlayın

    Multiple format string vulnerabilities in the logging code in Clam AntiVirus (ClamAV) before 0.88.1 might allow remote attackers to execute

    KritikCVSS 10,0İstismar yokEPSS %12

    clamav · clamav6 Nis 2006

  • CVE-2005-3656
    43Planlayın

    Multiple format string vulnerabilities in logging functions in mod_auth_pgsql before 2.0.3, when used for user authentication against a Post

    KritikCVSS 10,0İstismar yokEPSS %9

    guiseppe tanzilli and matthias eckermann · mod auth pgsql31 Ara 2005

  • CVE-2008-5982
    42Planlayın

    Format string vulnerability in BMC PATROL Agent before 3.7.30 allows remote attackers to execute arbitrary code via format string specifiers

    KritikCVSS 10,0İstismar yokEPSS %8

    bmc · patrol agent27 Oca 2009

  • CVE-2007-5561
    42Planlayın

    Format string vulnerability in the logging function in the Oracle OPMN daemon, as used on Oracle Enterprise Grid Console server 10.2.0.1, al

    KritikCVSS 10,0İstismar yokEPSS %8

    oracle · enterprise grid console server18 Eki 2007

  • CVE-2008-0764
    42Planlayın

    Format string vulnerability in the logging function in Larson Network Print Server (LstNPS) 9.4.2 build 105 and earlier for Windows might al

    KritikCVSS 10,0Kavram kanıtıEPSS %7

    larson software technology · network print server13 Şub 2008

Tüm zafiyet sınıfları