Skip to main content

CWE archive

CWE-134 CVEs

Programmatic archive

394 CVEs tagged with CWE-13497 Critical, 155 High, 119 Medium, 23 Low, 0 Unrated.

CVE-2008-1206

Published Mar 8, 2008

Format string vulnerability in the log_message function in lks.c in Linux Kiss Server 1.2, when background (daemon) mode is disabled, allows remote attackers to cause a denial of…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0072

Published Mar 6, 2008

Format string vulnerability in the emf_multipart_encrypted function in mail/em-format.c in Evolution 2.12.3 and earlier allows remote attackers to execute arbitrary code via a cra…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1127

Published Mar 3, 2008

Format string vulnerability in the cryactio function in Crysis 1.1.1.5879 allows remote authenticated users to execute arbitrary code via format string specifiers in the user name…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1120

Published Mar 3, 2008

Format string vulnerability in the embedded Internet Explorer component for Mirabilis ICQ 6 build 6043 allows remote servers to execute arbitrary code or cause a denial of service…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-1055

Published Feb 27, 2008

Format string vulnerability in webmail.exe in NetWin SurgeMail 38k4 and earlier and beta 39a, and WebMail 3.1s and earlier, allows remote attackers to cause a denial of service (d…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-6625

Published Jan 4, 2008

The Platform Service Process (asampsp) in Fan-Out Driver Platform Services for Novell Identity Manager (IDM) 3.5.1 allows remote attackers to cause a denial of service (daemon cra…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4708

Published Dec 19, 2007

Format string vulnerability in Address Book in Apple Mac OS X 10.4.11 allows remote attackers to execute arbitrary code via the URL handler.

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-6273

Published Dec 7, 2007

Multiple format string vulnerabilities in the configuration file in SonicWALL GLobal VPN Client 3.1.556 and 4.0.0.810 allow user-assisted remote attackers to execute arbitrary cod…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-6183

Published Nov 30, 2007

Format string vulnerability in the mdiag_initialize function in gtk/src/rbgtkmessagedialog.c in Ruby-GNOME 2 (aka Ruby/Gnome2) 0.16.0, and SVN versions before 20071127, allows con…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-3880

Published Nov 14, 2007

Format string vulnerability in srsexec in Sun Remote Services (SRS) Net Connect 3.2.3 and 3.2.4, as distributed in the SRS Proxy Core (SUNWsrspx) package, allows local users to ga…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2007-5396

Published Nov 10, 2007

Format string vulnerability in the ext_yahoo_contact_added function in yahoo.c in Miranda IM 0.7.1 allows remote attackers to execute arbitrary code via a Y7 Buddy Authorization p…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5825

Published Nov 5, 2007

Format string vulnerability in the ws_addarg function in webserver.c in mt-dappd in Firefly Media Server 0.2.4 and earlier allows remote attackers to execute arbitrary code via a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-5740

Published Oct 31, 2007

The format string protection mechanism in IMAPD for Perdition Mail Retrieval Proxy 1.17 and earlier allows remote attackers to execute arbitrary code via an IMAP tag with a null b…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-5545

Published Oct 18, 2007

Format string vulnerability in TIBCO SmartPGM FX allows remote attackers to execute arbitrary code via format string specifiers in unspecified vectors. NOTE: as of 20071016, the…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-3675

Published Oct 12, 2007

Multiple format string vulnerabilities in the kavwebscan.CKAVWebScan ActiveX control (kavwebscan.dll) in Kaspersky Online Scanner before 5.0.98 allow remote attackers to execute a…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-3917

Published Oct 11, 2007

The multiplayer engine in Wesnoth 1.2.x before 1.2.7 and 1.3.x before 1.3.9 allows remote servers to cause a denial of service (crash) via a long message with multibyte characters…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2007-5262

Published Oct 8, 2007

Multiple format string vulnerabilities in Battlefront Dropteam 1.3.3 and earlier allow remote attackers to execute arbitrary code via format string specifiers in the (1) username,…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-5265

Published Oct 8, 2007

Multiple format string vulnerabilities in websrv.cpp in Dawn of Time 1.69s beta4 and earlier allow remote attackers to execute arbitrary code via format string specifiers in the (…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 326-350 of 394 CVEsPage 14 of 16