The product uses a function that accepts a format string as an argument, but the format string originates from an external source.
Volume of CVEs assigned to CWE-134 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
395 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-23113CRITICAL A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, FortiProxy versions 7.4.0 through 7.4.2, 7 | Feb 15, 2024 | 9.8 | 92 | YES | NO |
CVE-2020-13160CRITICAL AnyDesk before 5.5.3 on Linux and FreeBSD has a format string vulnerability that can be exploited for remote code execution. | Jun 9, 2020 | 9.8 | 84 | NO | YES |
CVE-2019-1579HIGH Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with GlobalProtect Portal or GlobalProtect Gateway Interface enabled | Jul 19, 2019 | 8.1 | 83 | YES | NO |
CVE-2012-3569HIGH Format string vulnerability in VMware OVF Tool 2.1 on Windows, as used in VMware Workstation 8.x before 8.0.5, VMware Player 4.x before 4.0.5, and other products, allows user-assis | Nov 14, 2012 | 9.3 | 74 | NO | YES |
CVE-2020-3118HIGH A vulnerability in the Cisco Discovery Protocol implementation for Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to execute arbitrary code or cause a relo | Feb 5, 2020 | 8.8 | 71 | YES | NO |
CVE-2018-6317CRITICAL The remote management interface in Claymore Dual Miner 10.5 and earlier is vulnerable to an unauthenticated format string vulnerability, allowing remote attackers to read memory or | Feb 2, 2018 | 9.1 | 70 | NO | YES |
CVE-2012-1851HIGH Format string vulnerability in the Print Spooler service in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, a | Aug 15, 2012 | 10.0 | 68 | NO | NO |
CVE-2023-22374HIGH
A format string vulnerability exists in iControl SOAP that allows an authenticated attacker to crash the iControl SOAP CGI process or, potentially execute arbitrary code. In appli | Feb 1, 2023 | 8.5 | 67 | NO | NO |
CVE-2012-2288HIGH Format string vulnerability in the nsrd RPC service in EMC NetWorker 7.6.3 and 7.6.4 before 7.6.4.1, and 8.0 before 8.0.0.1, allows remote attackers to execute arbitrary code via f | Sep 4, 2012 | 9.3 | 66 | NO | YES |
CVE-2018-0175HIGH Format String vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthentic | Mar 28, 2018 | 8.0 | 64 | YES | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.