Skip to main content

CVE-2008-3734

9.3
CVSS v2.0 Base Score
69.43%
MEDIUM RiskEPSS (99th percentile)

Format string vulnerability in Ipswitch WS_FTP Home 2007.0.0.2 and WS_FTP Professional 2007.1.0.0 allows remote FTP servers to cause a denial of service (application crash) or possibly execute arbitrary code via format string specifiers in a connection greeting (response).

Published: 8/20/2008
Modified: 4/23/2026
Back to CVE Lookup

Vulnerability Summary

CVSS v2 Score

9.3

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS Score (Exploitation Probability)

69.43%MEDIUM Exploitation Risk
99th percentile

This vulnerability has a 69.43% probability of being exploited in the next 30 days, ranking higher than 99% of all scored CVEs.

CWE Classification

Related Vulnerabilities

Same Weakness Type(CWE-134)

CVE-2024-4641MEDIUM 6.3

OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due to accepting a format string from an external source as an argument. An attacker could modify an externally controlled format string to cause a memory leak and denial of service.

6/25/2024
CVE-2024-23113CRITICAL 9.8

A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, FortiPAM versions 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiSwitchManager versions 7.2.0 through 7.2.3, 7.0.0 through 7.0.3 allows attacker to execute unauthorized code or commands via specially crafted packets.

2/15/2024
CVE-2023-5746CRITICAL 9.8

A vulnerability regarding use of externally-controlled format string is found in the cgi component. This allows remote attackers to execute arbitrary code via unspecified vectors. The following models with Synology Camera Firmware versions before 1.0.5-0185 may be affected: BC500 and TC500.

10/25/2023
CVE-2022-35244CRITICAL 9.8

A format string injection vulnerability exists in the XCMD getVarHA functionality of abode systems, inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted XCMD can lead to memory corruption, information disclosure, and denial of service. An attacker can send a malicious XML payload to trigger this vulnerability.

10/25/2022
CVE-2022-27177CRITICAL 9.8

A Python format string issue leading to information disclosure and potentially remote code execution in ConsoleMe for all versions prior to 1.2.2

4/1/2022