VulnSea

CWE-134

CVEs classified under CWE-134, newest first.

12 CVEsRSS

CVE-2026-69395Medium· 6.5
2w ago

Use of externally-controlled format string in Active Directory Certificate Services (AD CS) allows an authorized attacker to disclose information over a network.

Use of externally-controlled format string in Active Directory Certificate Services (AD CS) allows an authorized attacker to disclose information over a network.

SunlitMicrosoft · Windows 10 Version 1607EPSS 0.88%via NVD
CVE-2026-63073Critical· 9.8⚖ disputed
4w ago

Issue summary: OpenSSL CMP response validation passed an unexpected response sender distinguished name directly as the format string to `ERR_raise_data()`. Impact summary: A malicious or intercepted CMP endpoint can crash a CMP client t…

Issue summary: OpenSSL CMP response validation passed an unexpected response sender distinguished name directly as the format string to `ERR_raise_data()`. Impact summary: A malicious or intercepted CMP endpoint can crash a CMP client t…

Midnightopenssl · opensslEPSS 0.93%via NVD
CVE-2026-68553High· 7.1PoC
1mo ago

Coturn is a free open source implementation of TURN and STUN Server

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.0, an authenticated TURN user can place printf-style format specifiers in the STUN USERNAME or REALM attribute, which passes is_secure_string() validation…

Midnightcoturn · coturnEPSS 0.34%via NVD
CVE-2026-6390Medium· 6.8
2mo ago

A flaw was found in GNU nano's multi-buffer error message handling

A flaw was found in GNU nano's multi-buffer error message handling. When a user opens multiple files at startup and one triggers an ALERT-level error, a specially crafted filename containing printf format specifiers can be reinterpreted.…

SunlitEPSS 0.15%via NVD
CVE-2024-58366High· 8.5
2mo ago

SurrealDB before 1.1.1 contains a format string vulnerability in the rquickjs Exception::throw_type function when scripting is enabled

SurrealDB before 1.1.1 contains a format string vulnerability in the rquickjs Exception::throw_type function when scripting is enabled. Attackers with scripting privileges can supply format string sequences in error inputs to read arbitr…

TwilightEPSS 0.32%via NVD
CVE-2026-15809High· 7.8
2mo ago

A flaw was found in CRI-O

A flaw was found in CRI-O. The fix for a previous vulnerability (CVE-2022-4318) was incorrect, allowing it to be bypassed. An attacker capable of setting environment variables on a container can inject a newline character into the HOME e…

TwilightRed Hat · cri-oEPSS 0.18%via NVD
CVE-2026-46465Medium· 5.5
2mo ago

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an use of extern…

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an use of extern…

SunlitEPSS 0.41%via NVD
CVE-2026-6843Medium· 5.5
5mo ago

A flaw was found in nano

A flaw was found in nano. A local user could exploit a format string vulnerability in the `statusline()` function. By creating a directory with a name containing `printf` specifiers, the application attempts to display this name, leading…

Sunlitgnu · nanoEPSS 0.11%via NVD
CVE-2026-33210Critical· 9.1
6mo ago

Ruby JSON is a JSON implementation for Ruby

Ruby JSON is a JSON implementation for Ruby. From version 2.14.0 to before versions 2.15.2.1, 2.17.1.2, and 2.19.2, a format string injection vulnerability can lead to denial of service attacks or information disclosure, when the allow_d…

Midnightruby-lang · jsonEPSS 0.86%via NVD
CVE-2026-22190High· 7.5
8mo ago

The egg-mkfont utility in Panda3D versions up to and including 1.10.16 contains an uncontrolled format string vulnerability

The egg-mkfont utility in Panda3D versions up to and including 1.10.16 contains an uncontrolled format string vulnerability. The -gp (glyph pattern) command-line option is used directly as the format string for sprintf() with only a sing…

Twilightcmu · panda3dEPSS 0.36%via NVD
CVE-2019-1579High· 8.1CISA KEVPoC
7y ago

Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with GlobalProtect Portal or GlobalProtect Gateway Interface enabled may allow an unauthenticated remote attacker to execute a…

Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with GlobalProtect Portal or GlobalProtect Gateway Interface enabled may allow an unauthenticated remote attacker to execute a…

Abyssalpaloaltonetworks · pan-osEPSS 46%via NVD
CVE-2017-10685Critical· 9.8
9y ago

In ncurses 6.0, there is a format string vulnerability in the fmt_entry function

In ncurses 6.0, there is a format string vulnerability in the fmt_entry function. A crafted input will lead to a remote arbitrary code execution attack.

Midnightinvisible-island · ncursesEPSS 4.0%via NVD
CWE-134 vulnerabilities (CVEs) · VulnSea