Vulnerabilities > Use of Externally-Controlled Format String

DATE CVE VULNERABILITY TITLE RISK
2022-09-21 CVE-2022-40604 Use of Externally-Controlled Format String vulnerability in Apache Airflow
In Apache Airflow 2.3.0 through 2.3.4, part of a url was unnecessarily formatted, allowing for possible information extraction.
network
low complexity
apache CWE-134
7.5
2022-09-09 CVE-2022-26392 Use of Externally-Controlled Format String vulnerability in Baxter products
The Baxter Spectrum WBM (v16, v16D38) and Baxter Spectrum WBM (v17, v17D19, v20D29 to v20D32) when in superuser mode is susceptible to format string attacks via application messaging.
network
low complexity
baxter CWE-134
6.5
2022-09-09 CVE-2022-26393 Use of Externally-Controlled Format String vulnerability in Baxter products
The Baxter Spectrum WBM is susceptible to format string attacks via application messaging.
network
low complexity
baxter CWE-134
8.1
2022-09-06 CVE-2022-34747 Use of Externally-Controlled Format String vulnerability in Zyxel Nas326 Firmware 5.21/5.21(Aazf.7)C0
A format string vulnerability in Zyxel NAS326 firmware versions prior to V5.21(AAZF.12)C0 could allow an attacker to achieve unauthorized remote code execution via a crafted UDP packet.
network
low complexity
zyxel CWE-134
critical
9.8
2022-08-05 CVE-2022-22299 Use of Externally-Controlled Format String vulnerability in Fortinet products
A format string vulnerability [CWE-134] in the command line interpreter of FortiADC version 6.0.0 through 6.0.4, FortiADC version 6.1.0 through 6.1.5, FortiADC version 6.2.0 through 6.2.1, FortiProxy version 1.0.0 through 1.0.7, FortiProxy version 1.1.0 through 1.1.6, FortiProxy version 1.2.0 through 1.2.13, FortiProxy version 2.0.0 through 2.0.7, FortiProxy version 7.0.0 through 7.0.1, FortiOS version 6.0.0 through 6.0.14, FortiOS version 6.2.0 through 6.2.10, FortiOS version 6.4.0 through 6.4.8, FortiOS version 7.0.0 through 7.0.2, FortiMail version 6.4.0 through 6.4.5, FortiMail version 7.0.0 through 7.0.2 may allow an authenticated user to execute unauthorized code or commands via specially crafted command arguments.
local
low complexity
fortinet CWE-134
7.8
2022-06-13 CVE-2022-31753 Use of Externally-Controlled Format String vulnerability in Huawei Emui, Harmonyos and Magic UI
The voice wakeup module has a vulnerability of using externally-controlled format strings.
network
low complexity
huawei CWE-134
7.5
2022-06-02 CVE-2022-1215 Use of Externally-Controlled Format String vulnerability in Freedesktop Libinput
A format string vulnerability was found in libinput
local
low complexity
freedesktop CWE-134
7.8
2022-04-01 CVE-2022-27177 Use of Externally-Controlled Format String vulnerability in Netflix Consoleme
A Python format string issue leading to information disclosure and potentially remote code execution in ConsoleMe for all versions prior to 1.2.2
network
low complexity
netflix CWE-134
critical
9.8
2022-03-29 CVE-2021-42911 Use of Externally-Controlled Format String vulnerability in Draytek products
A Format String vulnerability exists in DrayTek Vigor 2960 <= 1.5.1.3, DrayTek Vigor 3900 <= 1.5.1.3, and DrayTek Vigor 300B <= 1.5.1.3 in the mainfunction.cgi file via a crafted HTTP message containing malformed QUERY STRING, which could let a remote malicious user execute arbitrary code.
network
low complexity
draytek CWE-134
critical
9.8
2021-12-06 CVE-2021-43041 Use of Externally-Controlled Format String vulnerability in Kaseya Unitrends Backup
An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5.
network
low complexity
kaseya CWE-134
8.8