Vulnerabilities > Use of Externally-Controlled Format String
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-09-21 | CVE-2022-40604 | Use of Externally-Controlled Format String vulnerability in Apache Airflow In Apache Airflow 2.3.0 through 2.3.4, part of a url was unnecessarily formatted, allowing for possible information extraction. | 7.5 |
2022-09-09 | CVE-2022-26392 | Use of Externally-Controlled Format String vulnerability in Baxter products The Baxter Spectrum WBM (v16, v16D38) and Baxter Spectrum WBM (v17, v17D19, v20D29 to v20D32) when in superuser mode is susceptible to format string attacks via application messaging. | 6.5 |
2022-09-09 | CVE-2022-26393 | Use of Externally-Controlled Format String vulnerability in Baxter products The Baxter Spectrum WBM is susceptible to format string attacks via application messaging. | 8.1 |
2022-09-06 | CVE-2022-34747 | Use of Externally-Controlled Format String vulnerability in Zyxel Nas326 Firmware 5.21/5.21(Aazf.7)C0 A format string vulnerability in Zyxel NAS326 firmware versions prior to V5.21(AAZF.12)C0 could allow an attacker to achieve unauthorized remote code execution via a crafted UDP packet. | 9.8 |
2022-08-05 | CVE-2022-22299 | Use of Externally-Controlled Format String vulnerability in Fortinet products A format string vulnerability [CWE-134] in the command line interpreter of FortiADC version 6.0.0 through 6.0.4, FortiADC version 6.1.0 through 6.1.5, FortiADC version 6.2.0 through 6.2.1, FortiProxy version 1.0.0 through 1.0.7, FortiProxy version 1.1.0 through 1.1.6, FortiProxy version 1.2.0 through 1.2.13, FortiProxy version 2.0.0 through 2.0.7, FortiProxy version 7.0.0 through 7.0.1, FortiOS version 6.0.0 through 6.0.14, FortiOS version 6.2.0 through 6.2.10, FortiOS version 6.4.0 through 6.4.8, FortiOS version 7.0.0 through 7.0.2, FortiMail version 6.4.0 through 6.4.5, FortiMail version 7.0.0 through 7.0.2 may allow an authenticated user to execute unauthorized code or commands via specially crafted command arguments. | 7.8 |
2022-06-13 | CVE-2022-31753 | Use of Externally-Controlled Format String vulnerability in Huawei Emui, Harmonyos and Magic UI The voice wakeup module has a vulnerability of using externally-controlled format strings. | 7.5 |
2022-06-02 | CVE-2022-1215 | Use of Externally-Controlled Format String vulnerability in Freedesktop Libinput A format string vulnerability was found in libinput | 7.8 |
2022-04-01 | CVE-2022-27177 | Use of Externally-Controlled Format String vulnerability in Netflix Consoleme A Python format string issue leading to information disclosure and potentially remote code execution in ConsoleMe for all versions prior to 1.2.2 | 9.8 |
2022-03-29 | CVE-2021-42911 | Use of Externally-Controlled Format String vulnerability in Draytek products A Format String vulnerability exists in DrayTek Vigor 2960 <= 1.5.1.3, DrayTek Vigor 3900 <= 1.5.1.3, and DrayTek Vigor 300B <= 1.5.1.3 in the mainfunction.cgi file via a crafted HTTP message containing malformed QUERY STRING, which could let a remote malicious user execute arbitrary code. | 9.8 |
2021-12-06 | CVE-2021-43041 | Use of Externally-Controlled Format String vulnerability in Kaseya Unitrends Backup An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. | 8.8 |