Cyber Posture

CWE · MITRE source

CWE-134Use of Externally-Controlled Format String

Abstraction: Base · CVEs in our corpus: 381

The product uses a function that accepts a format string as an argument, but the format string originates from an external source.

Last updated: 19 May 2026 14:18 UTC

NIST 800-53 r5 controls that address this weakness (0)AI

Control Title Family Why it addresses this CWE
No NIST controls proposed yet.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2019-1579 KEV9.28.10.92882019-07-19
CVE-2020-131607.39.80.88832020-06-09
CVE-2024-23113 KEV7.29.80.54382024-02-15
CVE-2018-63176.29.10.72662018-02-02
CVE-2023-350866.07.20.75892023-07-21
CVE-2012-3569 UPD4.80.00.80642012-11-14
CVE-2014-16834.70.00.77842014-01-29
CVE-2012-1851 UPD4.30.00.72452012-08-15
CVE-2008-3734 UPD4.20.00.69432008-08-20
CVE-2012-2288 UPD4.20.00.69932012-09-04
CVE-2018-0175 KEV3.88.00.02922018-03-28
CVE-2020-3118 KEV3.88.80.00202020-02-05
CVE-2009-47693.70.00.62142010-04-20
CVE-2012-100553.50.00.58952025-08-13
CVE-2015-8617 UPD3.39.80.21882016-01-19
CVE-2007-0017 UPD3.10.00.51212007-01-03
CVE-2005-36563.00.00.49582005-12-31
CVE-2018-103883.09.80.18152019-12-23
CVE-2011-100292.90.00.48842025-08-20
CVE-2017-166082.89.80.13502018-01-23
CVE-2011-15682.70.00.44212011-04-05
CVE-2012-08092.70.00.44752012-02-01
CVE-2014-62622.77.50.19692020-02-12
CVE-2021-25489 KEV2.73.30.00362021-10-06
CVE-2017-166022.48.80.11342018-01-23