Vulnerabilities > Use of Externally-Controlled Format String

DATE CVE VULNERABILITY TITLE RISK
2006-07-21 CVE-2006-3469 USE of Externally-Controlled Format String vulnerability in multiple products
Format string vulnerability in time.cc in MySQL Server 4.1 before 4.1.21 and 5.0 before 1 April 2006 allows remote authenticated users to cause a denial of service (crash) via a format string instead of a date as the first parameter to the date_format function, which is later used in a formatted print call to display the error message.
network
low complexity
mysql oracle CWE-134
4.0
2006-07-13 CVE-2006-3573 USE of Externally-Controlled Format String vulnerability in Milan Mimica Sparklet
Format string vulnerability in the WriteText function in agl_text.cpp in Milan Mimica Sparklet 0.9.4 and earlier allows remote attackers to execute arbitrary code via format string specifiers in a player nickname.
network
low complexity
milan-mimica CWE-134
critical
10.0
2006-06-27 CVE-2006-1471 USE of Externally-Controlled Format String vulnerability in Apple mac OS X and mac OS X Server
Format string vulnerability in the CF_syslog function launchd in Apple Mac OS X 10.4 up to 10.4.6 allows local users to execute arbitrary code via format string specifiers that are not properly handled in a syslog call in the logging facility, as demonstrated by using a crafted plist file.
local
low complexity
apple CWE-134
4.6
2006-05-28 CVE-2006-2453 USE of Externally-Controlled Format String vulnerability in DIA
Multiple unspecified format string vulnerabilities in Dia have unspecified impact and attack vectors, a different set of issues than CVE-2006-2480.
network
low complexity
dia CWE-134
7.5
2006-05-19 CVE-2006-2480 USE of Externally-Controlled Format String vulnerability in DIA 0.94
Format string vulnerability in Dia 0.94 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code by triggering errors or warnings, as demonstrated via format string specifiers in a .bmp filename.
network
high complexity
dia CWE-134
5.1
2006-05-16 CVE-2006-2409 USE of Externally-Controlled Format String vulnerability in Raydium
Format string vulnerability in the raydium_log function in console.c in Raydium before SVN revision 310 allows local users to execute arbitrary code via format string specifiers in the format parameter, which are not properly handled in a call to raydium_console_line_add.
local
low complexity
raydium CWE-134
4.6
2006-04-19 CVE-2006-1840 USE of Externally-Controlled Format String vulnerability in Empire Server Empire Server
Multiple format string vulnerabilities in Empire Server before 4.3.1 allow attackers to cause a denial of service (crash) via the (1) load, (2) spy and (3) bomb functions.
network
low complexity
empire-server CWE-134
6.4
2006-04-06 CVE-2006-1615 USE of Externally-Controlled Format String vulnerability in Clamav
Multiple format string vulnerabilities in the logging code in Clam AntiVirus (ClamAV) before 0.88.1 might allow remote attackers to execute arbitrary code.
network
low complexity
clamav CWE-134
critical
10.0
2006-03-09 CVE-2006-0743 USE of Externally-Controlled Format String vulnerability in Apache Log4Net 1.2.9Beta
Format string vulnerability in LocalSyslogAppender in Apache log4net 1.2.9 might allow remote attackers to cause a denial of service (memory corruption and termination) via unknown vectors.
network
low complexity
apache CWE-134
5.0
2006-02-18 CVE-2006-0771 USE of Externally-Controlled Format String vulnerability in Even Balance Punkbuster
Format string vulnerability in PunkBuster 1.180 and earlier, as used by Soldier of Fortune II and possibly other games, allows remote attackers to cause a denial of service (server crash) and possibly execute arbitrary code via format string specifiers in invalid cvar values, which are not properly handled when the server kicks the player and records the reason.
network
low complexity
even-balance CWE-134
6.4