CWE-134 · 392 kayıt
Use of Externally-Controlled Format String
Bu sınıftaki CVE’ler
392 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
88Hemen | CVE-2024-23113Silahlaştırılmış | A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, Fofortinet · fortiproxy · CWE-134 | Kritik9,8 | KEV | %61,7 | 15 Şub 2024 |
76Bu hafta | CVE-2019-1579Silahlaştırılmış | Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with GlobalProtect Portal or paloaltonetworks · pan-os · CWE-134 | Yüksek8,1 | KEV | %46,2 | 19 Tem 2019 |
69Bu hafta | CVE-2020-3118Silahlaştırılmış | Cisco IOS XR Software Cisco Discovery Protocol Format String Vulnerabilitycisco · ios xr · CWE-134 | Yüksek8,8 | KEV | %11,7 | 5 Şub 2020 |
63Bu hafta | CVE-2020-13160Silahlaştırılmış | AnyDesk before 5.5.3 on Linux and FreeBSD has a format string vulnerability that can be exploited for remote code execution.anydesk · anydesk · CWE-134 | Kritik9,8 | — | %80,6 | 9 Haz 2020 |
60Bu hafta | CVE-2012-1851İstismar yok | Format string vulnerability in the Print Spooler service in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Wimicrosoft · windows 7 · CWE-134 | Kritik10,0 | — | %65,6 | 14 Ağu 2012 |
56Planlayın | CVE-2023-22374İstismar yok | iControl SOAP vulnerabilityf5 · big-ip access policy manager · CWE-134 | Yüksek8,5 | — | %72,6 | 1 Şub 2023 |
51Planlayın | CVE-2012-3569Silahlaştırılmış | Format string vulnerability in VMware OVF Tool 2.1 on Windows, as used in VMware Workstation 8.x before 8.0.5, VMware Player 4.x before 4.0.vmware · ovf tool · CWE-134 | Kritik9,3 | — | %47,7 | 14 Kas 2012 |
49Planlayın | CVE-2018-6317Silahlaştırılmış | The remote management interface in Claymore Dual Miner 10.5 and earlier is vulnerable to an unauthenticated format string vulnerability, allclaymore dual miner project · claymore dual miner · CWE-134 | Kritik9,1 | — | %43,7 | 2 Şub 2018 |
48Planlayın | CVE-2009-4769Silahlaştırılmış | Multiple format string vulnerabilities in the tolog function in httpdx 1.4, 1.4.5, 1.4.6, 1.4.6b, and 1.5 allow (1) remote attackers to execjasper · httpdx · CWE-134 | Kritik9,3 | — | %37,9 | 20 Nis 2010 |
47Planlayın | CVE-2012-2288Silahlaştırılmış | Format string vulnerability in the nsrd RPC service in EMC NetWorker 7.6.3 and 7.6.4 before 7.6.4.1, and 8.0 before 8.0.0.1, allows remote aemc · networker · CWE-134 | Kritik9,3 | — | %33,1 | 4 Eyl 2012 |
46Planlayın | CVE-2015-8617Kavram kanıtı | Format string vulnerability in the zend_throw_or_error function in Zend/zend_execute_API.c in PHP 7.x before 7.0.1 allows remote attackers tphp · php · CWE-134 | Kritik9,8 | — | %22,8 | 19 Oca 2016 |
46Planlayın | CVE-2010-1039Kavram kanıtı | Format string vulnerability in the _msgout function in rpc.pcnfsd in IBM AIX 6.1, 5.3, and earlier; IBM VIOS 2.1, 1.5, and earlier; NFS/ONCpibm · aix · CWE-134 | Kritik10,0 | — | %20,2 | 20 May 2010 |
46Planlayın | CVE-2008-3533Kavram kanıtı | Format string vulnerability in the window_error function in yelp-window.c in yelp in Gnome after 2.19.90 and before 2.24 allows remote attacgnome · yelp · CWE-134 | Kritik10,0 | — | %19,4 | 18 Ağu 2008 |
46Planlayın | CVE-2011-1568Kavram kanıtı | Format string vulnerability in the logText function in shmemmgr9.dll in IGSSdataServer.exe 9.00.00.11074, and 9.00.00.11063 and earlier, in 7t · igss · CWE-134 | Kritik10,0 | — | %19,4 | 5 Nis 2011 |
45Planlayın | CVE-2011-0270İstismar yok | Format string vulnerability in nnmRptConfig.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to executhp · openview network node manager · CWE-134 | Kritik10,0 | — | %16,3 | 13 Oca 2011 |
45Planlayın | CVE-2009-3732Kavram kanıtı | Format string vulnerability in vmware-vmrc.exe build 158248 in VMware Remote Console (aka VMrc) allows remote attackers to execute arbitraryvmware · ace · CWE-134 | Kritik10,0 | — | %16,2 | 12 Nis 2010 |
45Planlayın | CVE-2009-1210Kavram kanıtı | Format string vulnerability in the PROFINET/DCP (PN-DCP) dissector in Wireshark 1.0.6 and earlier allows remote attackers to execute arbitrawireshark · wireshark · CWE-134 | Kritik10,0 | — | %15,2 | 1 Nis 2009 |
44Planlayın | CVE-2009-3663Kavram kanıtı | Format string vulnerability in the h_readrequest function in http.c in httpdx Web Server 1.4 allows remote attackers to cause a denial of sejasper · httpdx · CWE-134 | Kritik10,0 | — | %14,6 | 11 Eki 2009 |
44Planlayın | CVE-2010-1550İstismar yok | Format string vulnerability in ovet_demandpoll.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackershp · openview network node manager · CWE-134 | Kritik10,0 | — | %11,8 | 13 May 2010 |
43Planlayın | CVE-2006-0200İstismar yok | Format string vulnerability in the error-reporting feature in the mysqli extension in PHP 5.1.0 and 5.1.1 might allow remote attackers to exphp · php · CWE-134 | Kritik9,3 | — | %19,4 | 13 Oca 2006 |
43Planlayın | CVE-2006-1615İstismar yok | Multiple format string vulnerabilities in the logging code in Clam AntiVirus (ClamAV) before 0.88.1 might allow remote attackers to execute clamav · clamav · CWE-134 | Kritik10,0 | — | %11,6 | 6 Nis 2006 |
43Planlayın | CVE-2005-3656İstismar yok | Multiple format string vulnerabilities in logging functions in mod_auth_pgsql before 2.0.3, when used for user authentication against a Postguiseppe tanzilli and matthias eckermann · mod auth pgsql · CWE-134 | Kritik10,0 | — | %8,9 | 31 Ara 2005 |
42Planlayın | CVE-2008-5982İstismar yok | Format string vulnerability in BMC PATROL Agent before 3.7.30 allows remote attackers to execute arbitrary code via format string specifiersbmc · patrol agent · CWE-134 | Kritik10,0 | — | %7,8 | 27 Oca 2009 |
42Planlayın | CVE-2007-5561İstismar yok | Format string vulnerability in the logging function in the Oracle OPMN daemon, as used on Oracle Enterprise Grid Console server 10.2.0.1, aloracle · enterprise grid console server · CWE-134 | Kritik10,0 | — | %7,7 | 18 Eki 2007 |
42Planlayın | CVE-2008-0764Kavram kanıtı | Format string vulnerability in the logging function in Larson Network Print Server (LstNPS) 9.4.2 build 105 and earlier for Windows might allarson software technology · network print server · CWE-134 | Kritik10,0 | — | %7,4 | 13 Şub 2008 |
- CVE-2024-2311388Hemen
A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, Fo
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %62fortinet · fortiproxy15 Şub 2024
- CVE-2019-157976Bu hafta
Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with GlobalProtect Portal or
YüksekCVSS 8,1KEVSilahlaştırılmışEPSS %46paloaltonetworks · pan-os19 Tem 2019
- CVE-2020-311869Bu hafta
Cisco IOS XR Software Cisco Discovery Protocol Format String Vulnerability
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %12cisco · ios xr5 Şub 2020
- CVE-2020-1316063Bu hafta
AnyDesk before 5.5.3 on Linux and FreeBSD has a format string vulnerability that can be exploited for remote code execution.
KritikCVSS 9,8SilahlaştırılmışEPSS %81anydesk · anydesk9 Haz 2020
- CVE-2012-185160Bu hafta
Format string vulnerability in the Print Spooler service in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Wi
KritikCVSS 10,0İstismar yokEPSS %66microsoft · windows 714 Ağu 2012
- CVE-2023-2237456Planlayın
iControl SOAP vulnerability
YüksekCVSS 8,5İstismar yokEPSS %73f5 · big-ip access policy manager1 Şub 2023
- CVE-2012-356951Planlayın
Format string vulnerability in VMware OVF Tool 2.1 on Windows, as used in VMware Workstation 8.x before 8.0.5, VMware Player 4.x before 4.0.
KritikCVSS 9,3SilahlaştırılmışEPSS %48vmware · ovf tool14 Kas 2012
- CVE-2018-631749Planlayın
The remote management interface in Claymore Dual Miner 10.5 and earlier is vulnerable to an unauthenticated format string vulnerability, all
KritikCVSS 9,1SilahlaştırılmışEPSS %44claymore dual miner project · claymore dual miner2 Şub 2018
- CVE-2009-476948Planlayın
Multiple format string vulnerabilities in the tolog function in httpdx 1.4, 1.4.5, 1.4.6, 1.4.6b, and 1.5 allow (1) remote attackers to exec
KritikCVSS 9,3SilahlaştırılmışEPSS %38jasper · httpdx20 Nis 2010
- CVE-2012-228847Planlayın
Format string vulnerability in the nsrd RPC service in EMC NetWorker 7.6.3 and 7.6.4 before 7.6.4.1, and 8.0 before 8.0.0.1, allows remote a
KritikCVSS 9,3SilahlaştırılmışEPSS %33emc · networker4 Eyl 2012
- CVE-2015-861746Planlayın
Format string vulnerability in the zend_throw_or_error function in Zend/zend_execute_API.c in PHP 7.x before 7.0.1 allows remote attackers t
KritikCVSS 9,8Kavram kanıtıEPSS %23php · php19 Oca 2016
- CVE-2010-103946Planlayın
Format string vulnerability in the _msgout function in rpc.pcnfsd in IBM AIX 6.1, 5.3, and earlier; IBM VIOS 2.1, 1.5, and earlier; NFS/ONCp
KritikCVSS 10,0Kavram kanıtıEPSS %20ibm · aix20 May 2010
- CVE-2008-353346Planlayın
Format string vulnerability in the window_error function in yelp-window.c in yelp in Gnome after 2.19.90 and before 2.24 allows remote attac
KritikCVSS 10,0Kavram kanıtıEPSS %19gnome · yelp18 Ağu 2008
- CVE-2011-156846Planlayın
Format string vulnerability in the logText function in shmemmgr9.dll in IGSSdataServer.exe 9.00.00.11074, and 9.00.00.11063 and earlier, in
KritikCVSS 10,0Kavram kanıtıEPSS %197t · igss5 Nis 2011
- CVE-2011-027045Planlayın
Format string vulnerability in nnmRptConfig.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execut
KritikCVSS 10,0İstismar yokEPSS %16hp · openview network node manager13 Oca 2011
- CVE-2009-373245Planlayın
Format string vulnerability in vmware-vmrc.exe build 158248 in VMware Remote Console (aka VMrc) allows remote attackers to execute arbitrary
KritikCVSS 10,0Kavram kanıtıEPSS %16vmware · ace12 Nis 2010
- CVE-2009-121045Planlayın
Format string vulnerability in the PROFINET/DCP (PN-DCP) dissector in Wireshark 1.0.6 and earlier allows remote attackers to execute arbitra
KritikCVSS 10,0Kavram kanıtıEPSS %15wireshark · wireshark1 Nis 2009
- CVE-2009-366344Planlayın
Format string vulnerability in the h_readrequest function in http.c in httpdx Web Server 1.4 allows remote attackers to cause a denial of se
KritikCVSS 10,0Kavram kanıtıEPSS %15jasper · httpdx11 Eki 2009
- CVE-2010-155044Planlayın
Format string vulnerability in ovet_demandpoll.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers
KritikCVSS 10,0İstismar yokEPSS %12hp · openview network node manager13 May 2010
- CVE-2006-020043Planlayın
Format string vulnerability in the error-reporting feature in the mysqli extension in PHP 5.1.0 and 5.1.1 might allow remote attackers to ex
KritikCVSS 9,3İstismar yokEPSS %19php · php13 Oca 2006
- CVE-2006-161543Planlayın
Multiple format string vulnerabilities in the logging code in Clam AntiVirus (ClamAV) before 0.88.1 might allow remote attackers to execute
KritikCVSS 10,0İstismar yokEPSS %12clamav · clamav6 Nis 2006
- CVE-2005-365643Planlayın
Multiple format string vulnerabilities in logging functions in mod_auth_pgsql before 2.0.3, when used for user authentication against a Post
KritikCVSS 10,0İstismar yokEPSS %9guiseppe tanzilli and matthias eckermann · mod auth pgsql31 Ara 2005
- CVE-2008-598242Planlayın
Format string vulnerability in BMC PATROL Agent before 3.7.30 allows remote attackers to execute arbitrary code via format string specifiers
KritikCVSS 10,0İstismar yokEPSS %8bmc · patrol agent27 Oca 2009
- CVE-2007-556142Planlayın
Format string vulnerability in the logging function in the Oracle OPMN daemon, as used on Oracle Enterprise Grid Console server 10.2.0.1, al
KritikCVSS 10,0İstismar yokEPSS %8oracle · enterprise grid console server18 Eki 2007
- CVE-2008-076442Planlayın
Format string vulnerability in the logging function in Larson Network Print Server (LstNPS) 9.4.2 build 105 and earlier for Windows might al
KritikCVSS 10,0Kavram kanıtıEPSS %7larson software technology · network print server13 Şub 2008