Skip to main content

CWE archive

CWE-134 CVEs

Programmatic archive

395 CVEs tagged with CWE-13497 Critical, 155 High, 120 Medium, 23 Low, 0 Unrated.

CVE-2022-2652

Published Aug 4, 2022

Depending on the way the format strings in the card label are crafted it's possible to leak kernel stack memory. There is also the possibility for DoS due to the v4l2loopback kern…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-26674

Published Apr 22, 2022

ASUS RT-AX88U has a Format String vulnerability, which allows an unauthenticated remote attacker to write to arbitrary memory address and perform remote arbitrary code execution,…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-27177

Published Apr 1, 2022

A Python format string issue leading to information disclosure and potentially remote code execution in ConsoleMe for all versions prior to 1.2.2

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-41193

Published Mar 1, 2022

wire-avs is the audio visual signaling (AVS) component of Wire, an open-source messenger. A remote format string vulnerability in versions prior to 7.1.12 allows an attacker to ca…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-24051

Published Feb 18, 2022

MariaDB CONNECT Storage Engine Format String Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Mari…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-43041

Published Dec 6, 2021

An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. A crafted HTTP request could induce a format string vulnerability in the privileged vaultServer applica…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-25489

Published Oct 6, 2021

Assuming radio permission is gained, missing input validation in modem interface driver prior to SMR Oct-2021 Release 1 results in format string bug leading to kernel panic.

CVSS 3.3 · Low
evidence mentions
2
Buzz score
42.5
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2021-36161

Published Sep 9, 2021

Some component in Dubbo will try to print the formated string of the input arguments, which will possibly cause RCE for a maliciously customized bean with special toString method.…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-35331

Published Jul 5, 2021

In Tcl 8.6.11, a format string vulnerability in nmakehlp.c might allow code execution via a crafted file. NOTE: multiple third parties dispute the significance of this finding

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-29740

Published Jun 1, 2021

IBM Spectrum Scale 5.0.0 through 5.0.5.6 and 5.1.0 through 5.1.0.3 system core component is affected by a format string security vulnerability. An attacker could execute arbitrary…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-30145

Published May 18, 2021

A format string vulnerability in mpv through 0.33.0 allows user-assisted remote attackers to achieve code execution via a crafted m3u playlist file.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-36323

Published Apr 14, 2021

In the standard library in Rust before 1.52.0, there is an optimization for joining strings that can cause uninitialized bytes to be exposed (or the program to crash) if the borro…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2020-29018

Published Jan 14, 2021

A format string vulnerability in FortiWeb 6.3.0 through 6.3.5 may allow an authenticated, remote attacker to read the content of memory and retrieve sensitive data via the redir p…

CVSS 8.8 · High
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2020-35869

Published Dec 31, 2020

An issue was discovered in the rusqlite crate before 0.23.0 for Rust. Memory safety can be violated because rusqlite::trace::log mishandles format strings.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-27524

Published Nov 11, 2020

On Audi A7 MMI 2014 vehicles, the Bluetooth stack in Audi A7 MMI Multiplayer with version (N+R_CN_AU_P0395) mishandles %x and %s format string specifiers in a device name. This ma…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort
Showing 126-150 of 395 CVEsPage 6 of 16