Vulnerabilities > Use of Externally-Controlled Format String

DATE CVE VULNERABILITY TITLE RISK
2017-04-02 CVE-2017-2403 Use of Externally-Controlled Format String vulnerability in Apple mac OS X
An issue was discovered in certain Apple products.
network
low complexity
apple CWE-134
8.8
2017-03-23 CVE-2017-5524 Use of Externally-Controlled Format String vulnerability in Plone
Plone 4.x through 4.3.11 and 5.x through 5.0.6 allow remote attackers to bypass a sandbox protection mechanism and obtain sensitive information by leveraging the Python string format method.
network
low complexity
plone CWE-134
4.3
2017-03-22 CVE-2017-3859 Use of Externally-Controlled Format String vulnerability in Cisco IOS XE
A vulnerability in the DHCP code for the Zero Touch Provisioning feature of Cisco ASR 920 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to cause an affected device to reload.
network
low complexity
cisco CWE-134
7.5
2017-03-03 CVE-2017-5613 Use of Externally-Controlled Format String vulnerability in Cpanel Cgiecho and Cgiemail
Format string vulnerability in cgiemail and cgiecho allows remote attackers to execute arbitrary code via format string specifiers in a template file.
local
low complexity
cpanel CWE-134
7.8
2016-06-09 CVE-2016-4448 Use of Externally-Controlled Format String vulnerability in multiple products
Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vectors.
network
low complexity
hp apple xmlsoft redhat slackware oracle tenable mcafee CWE-134
critical
9.8
2016-04-18 CVE-2015-8106 Use of Externally-Controlled Format String vulnerability in multiple products
Format string vulnerability in the CmdKeywords function in funct1.c in latex2rtf before 2.3.10 allows remote attackers to execute arbitrary code via format string specifiers in the \keywords command in a crafted TeX file.
local
low complexity
latex2rtf-project fedoraproject CWE-134
7.8
2016-01-19 CVE-2015-8617 Use of Externally-Controlled Format String vulnerability in PHP 7.0.1
Format string vulnerability in the zend_throw_or_error function in Zend/zend_execute_API.c in PHP 7.x before 7.0.1 allows remote attackers to execute arbitrary code via format string specifiers in a string that is misused as a class name, leading to incorrect error handling.
network
low complexity
php CWE-134
critical
9.8
2015-12-31 CVE-2015-2894 Use of Externally-Controlled Format String vulnerability in Idera Uptime Infrastructure Monitor 6.0/7.2
Format string vulnerability in the up.time client in Idera Uptime Infrastructure Monitor 6.0 and 7.2 allows remote attackers to cause a denial of service (application crash) via format string specifiers.
network
low complexity
idera CWE-134
5.3