CVE-2021-41193
wire-avs is the audio visual signaling (AVS) component of Wire, an open-source messenger. A remote format string vulnerability in versions prior to 7.1.12 allows an attacker to cause a denial of service or possibly execute arbitrary code. The issue has been fixed in wire-avs 7.1.12. There are currently no known workarounds.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 1.14%
- CWE
- CWE-134
- Published
- 2022-03-01
- Last modified
- 2026-03-13
Affected products
- wireapp wire-avs
Weakness type
Related vulnerabilities
- CVE-2024-23113 — A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.
- CVE-2012-10055 — ComSndFTP v1.3.7 Beta USER Format String RCE
- CVE-2023-35086 — ASUS RT-AX56U V2 & RT-AC86U - Format String -1
- CVE-2020-3118 — Cisco IOS XR Software Cisco Discovery Protocol Format String Vulnerability
- CVE-2011-10029 — Solar FTP Server <= 2.1.1 Malformed USER Denial of Service
- CVE-2022-26674 — ASUS RT-AX88U - Format String
- CVE-2022-34747 — A format string vulnerability in Zyxel NAS326 firmware versions prior to V5.21(AAZF.12)C0 could allow an attacker to ach
- CVE-2023-35087 — ASUS RT-AX56U V2 & RT-AC86U - Format String - 2