Vulnerabilities > Use of Externally-Controlled Format String

DATE CVE VULNERABILITY TITLE RISK
2007-03-03 CVE-2007-1251 USE of Externally-Controlled Format String vulnerability in Netrek Vanilla Server 2.12.0
Format string vulnerability in the new_warning function in ntserv/warning.c for Netrek Vanilla Server 2.12.0, when EVENTLOG is enabled, allows remote attackers to cause a denial of service (crash) or execute arbitrary code via format string specifiers in the message handling.
network
netrek CWE-134
critical
9.3
2007-02-20 CVE-2007-1006 USE of Externally-Controlled Format String vulnerability in Ekiga
Multiple format string vulnerabilities in the gm_main_window_flash_message function in Ekiga before 2.0.5 allow attackers to cause a denial of service and possibly execute arbitrary code via a crafted Q.931 SETUP packet.
network
low complexity
ekiga CWE-134
critical
10.0
2007-02-06 CVE-2007-0454 USE of Externally-Controlled Format String vulnerability in multiple products
Format string vulnerability in the afsacl.so VFS module in Samba 3.0.6 through 3.0.23d allows context-dependent attackers to execute arbitrary code via format string specifiers in a filename on an AFS file system, which is not properly handled during Windows ACL mapping.
network
low complexity
samba debian mandrakesoft CWE-134
7.5
2007-02-01 CVE-2007-0646 USE of Externally-Controlled Format String vulnerability in Apple Imovie, mac OS X and Safari
Format string vulnerability in iMovie HD 6.0.3, and Safari in Apple Mac OS X 10.4 through 10.4.10, allows remote user-assisted attackers to cause a denial of service (crash) via format string specifiers in a filename, which is not properly handled when calling the NSRunCriticalAlertPanel Apple AppKit function.
network
apple CWE-134
7.1
2007-01-18 CVE-2007-0344 USE of Externally-Controlled Format String vulnerability in Colloquy
Multiple format string vulnerabilities in (1) _invitedToRoom: and (2) _invitedToDirectChat: in Colloquy 2.1 and earlier allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via format string specifiers in the channel name of an INVITE request, related to the implementation of AlertSheet and AlertPanel in Apple AppKit.
network
low complexity
colloquy CWE-134
7.5
2007-01-03 CVE-2007-0017 USE of Externally-Controlled Format String vulnerability in Videolan VLC Media Player
Multiple format string vulnerabilities in (1) the cdio_log_handler function in modules/access/cdda/access.c in the CDDA (libcdda_plugin) plugin, and the (2) cdio_log_handler and (3) vcd_log_handler functions in modules/access/vcdx/access.c in the VCDX (libvcdx_plugin) plugin, in VideoLAN VLC 0.7.0 through 0.8.6 allow user-assisted remote attackers to execute arbitrary code via format string specifiers in an invalid URI, as demonstrated by a udp://-- URI in an M3U file.
network
videolan CWE-134
6.8
2006-12-27 CVE-2006-6751 USE of Externally-Controlled Format String vulnerability in Dxmsoft XM Easy Personal FTP Server 5.2.1/5.3
Format string vulnerability in XM Easy Personal FTP Server 5.2.1 allows remote attackers to cause a denial of service (application crash) via format string specifiers in the USER command or certain other available or nonexistent commands.
network
low complexity
dxmsoft CWE-134
5.0
2006-07-21 CVE-2006-3628 USE of Externally-Controlled Format String vulnerability in multiple products
Multiple format string vulnerabilities in Wireshark (aka Ethereal) 0.10.x to 0.99.0 allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) ANSI MAP, (2) Checkpoint FW-1, (3) MQ, (4) XML, and (5) NTP dissectors.
network
low complexity
ethereal-group wireshark CWE-134
critical
10.0
2006-07-21 CVE-2006-3469 USE of Externally-Controlled Format String vulnerability in multiple products
Format string vulnerability in time.cc in MySQL Server 4.1 before 4.1.21 and 5.0 before 1 April 2006 allows remote authenticated users to cause a denial of service (crash) via a format string instead of a date as the first parameter to the date_format function, which is later used in a formatted print call to display the error message.
network
low complexity
mysql oracle CWE-134
4.0
2006-07-13 CVE-2006-3573 USE of Externally-Controlled Format String vulnerability in Milan Mimica Sparklet
Format string vulnerability in the WriteText function in agl_text.cpp in Milan Mimica Sparklet 0.9.4 and earlier allows remote attackers to execute arbitrary code via format string specifiers in a player nickname.
network
low complexity
milan-mimica CWE-134
critical
10.0