Cyber Posture

CWE · MITRE source

CWE-134Use of Externally-Controlled Format String

Abstraction: Base · CVEs in our corpus: 380

The product uses a function that accepts a format string as an argument, but the format string originates from an external source.

Last updated: 09 May 2026 03:25 UTC

NIST 800-53 r5 controls that address this weakness (0)AI

Control Title Family Why it addresses this CWE
No NIST controls proposed yet.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2019-1579 KEV9.28.10.93012019-07-19
CVE-2024-23113 KEV7.29.80.54382024-02-15
CVE-2020-131606.99.80.82422020-06-09
CVE-2018-63176.29.10.72662018-02-02
CVE-2023-350865.97.20.75072023-07-21
CVE-2012-35694.80.00.80642012-11-14
CVE-2014-16834.70.00.77842014-01-29
CVE-2012-18514.30.00.72452012-08-15
CVE-2008-37344.20.00.69432008-08-20
CVE-2012-22884.20.00.69932012-09-04
CVE-2018-0175 KEV3.88.00.02922018-03-28
CVE-2020-3118 KEV3.88.80.00182020-02-05
CVE-2009-47693.70.00.62142010-04-20
CVE-2012-100553.50.00.58952025-08-13
CVE-2015-86173.39.80.21882016-01-19
CVE-2006-34693.20.00.54102006-07-21
CVE-2007-00173.10.00.51212007-01-03
CVE-2005-36563.00.00.49582005-12-31
CVE-2018-103883.09.80.18152019-12-23
CVE-2011-100292.90.00.48842025-08-20
CVE-2017-166082.89.80.13502018-01-23
CVE-2011-15682.70.00.44212011-04-05
CVE-2012-08092.70.00.44752012-02-01
CVE-2014-62622.77.50.19692020-02-12
CVE-2021-25489 KEV2.73.30.00362021-10-06