id software records
27 published records for vendor id software.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 6
- With a fix record
- 18.5%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-20 Improper Input Validation2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-134 Use of Externally-Controlled Format String1
The weakness classes this vendor ships most often: where to look.
CWEAll records
27 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2007-5248Proof of concept | Multiple format string vulnerabilities in the ID Software Doom 3 engine, as used by Doom 3 1.3.1 and earlier, Quake 4 1.4.2 and earlier, andid software · doom 3 · CWE-134 | Critical9.3 | — | 7.5% | Oct 6, 2007 |
32Monitor | CVE-2006-2236Proof of concept | Buffer overflow in the Quake 3 Engine, as used by (1) ET 2.60, (2) Return to Castle Wolfenstein 1.41, and (3) Quake III Arena 1.32b allows rid software · quake 3 arena | High7.6 | — | 7.6% | May 8, 2006 |
32Monitor | CVE-2006-2875Proof of concept | Stack-based buffer overflow in the CL_ParseDownload function of Quake 3 Engine 1.32c and earlier, as used in multiple products, allows remotid software · quake 3 engine | High7.5 | — | 6.8% | Jun 6, 2006 |
32Monitor | CVE-2006-3401Proof of concept | Stack-based buffer overflow in Quake 3 Engine as used by Quake 3: Arena 1.32b and 1.32c allows remote attackers to cause a denial of serviceid software · quake 3 engine · CWE-119 | High7.5 | — | 5.7% | Jul 6, 2006 |
31Monitor | CVE-2006-3400Proof of concept | Stack-based buffer overflow in the CG_ServerCommand function in Quake 3 Engine as used by Soldier of Fortune 2 (SOF2MP) GOLD 1.03 allows remid software · quake 3 engine | High7.5 | — | 4.8% | Jul 6, 2006 |
31Monitor | CVE-2004-2593No exploit | Buffer overflow in command-packet processing of Quake II server before R1Q2, as used in multiple products, allows remote attackers to cause id software · quake ii server | High7.5 | — | 3.8% | Dec 31, 2004 |
31Monitor | CVE-2006-2082No exploit | Directory traversal vulnerability in Quake 3 engine, as used in products including Quake3 Arena, Return to Castle Wolfenstein, Wolfenstein: id software · quake 3 engine | High7.5 | — | 2.6% | May 9, 2006 |
31Monitor | CVE-1999-1505No exploit | Buffer overflow in QuakeWorld 2.10 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary commands via id software · quakeworld | High7.5 | — | 2.0% | Apr 7, 1998 |
31Monitor | CVE-1999-1502No exploit | Buffer overflows in Quake 1.9 client allows remote malicious servers to execute arbitrary commands via long (1) precache paths, (2) server nid software · quake | High7.5 | — | 1.9% | Apr 8, 1998 |
25Monitor | CVE-2000-0303No exploit | Quake3 Arena allows malicious server operators to read or modify files on a client via a dot dot (..) attack.id software · quake 3 arena | Medium6.4 | — | 1.3% | May 3, 2000 |
22Monitor | CVE-2005-0430Proof of concept | The Quake 3 engine, as used in multiple game packages, allows remote attackers to cause a denial of service (shutdown game server) and possiid software · quake 3 engine | Medium5.0 | — | 7.5% | Feb 12, 2005 |
22Monitor | CVE-2002-0770Proof of concept | Quake 2 (Q2) server 3.20 and 3.21 allows remote attackers to obtain sensitive server cvar variables, obtain directory listings, and execute id software · quake 2i server | Medium5.0 | — | 5.5% | Aug 12, 2002 |
22Monitor | CVE-2001-1289Proof of concept | Quake 3 arena 1.29f and 1.29g allows remote attackers to cause a denial of service (crash) via a malformed connection packet that begins witid software · quake 3 arena | Medium5.0 | — | 5.2% | Jul 29, 2001 |
21Monitor | CVE-2006-3325Proof of concept | client/cl_parse.c in the id3 Quake 3 Engine 1.32c and the Icculus Quake 3 Engine (ioquake3) revision 810 and earlier allows remote maliciousid software · quake 3 engine | Medium5.0 | — | 4.8% | Jun 30, 2006 |
21Monitor | CVE-2006-3324Proof of concept | The Automatic Downloading option in the id3 Quake 3 Engine and the Icculus Quake 3 Engine (ioquake3) before revision 804 allows remote attacid software · quake 3 engine | Medium5.0 | — | 4.4% | Jun 30, 2006 |
21Monitor | CVE-2004-2592Proof of concept | Quake II server before R1Q2, as used in multiple products, allows remote attackers to cause a denial of service (application crash) via a moid software · quake ii server · CWE-20 | Medium5.0 | — | 3.7% | Dec 31, 2004 |
21Monitor | CVE-1999-1569Proof of concept | Quake 1 and NetQuake servers allow remote attackers to cause a denial of service (resource exhaustion or forced disconnection) via a flood oid software · quake | Medium5.0 | — | 3.2% | Jul 17, 2001 |
21Monitor | CVE-2004-2595No exploit | Absolute path traversal vulnerability in Quake II server before R1Q2 on Linux, as used in multiple products, allows remote attackers to causid software · quake ii server linux | Medium5.0 | — | 2.8% | Dec 31, 2004 |
21Monitor | CVE-2005-0983No exploit | Quake 3 engine, as used in multiple games, allows remote attackers to cause a denial of service (client disconnect) via a long message, whicactivision · call of duty | Medium5.0 | — | 2.6% | May 2, 2005 |
21Monitor | CVE-2004-2596No exploit | Quake II server before R1Q2, as used in multiple products, allows remote attackers to cause a denial of service (exhaustion of connection slid software · quake ii server · CWE-20 | Medium5.0 | — | 1.9% | Dec 31, 2004 |
21Monitor | CVE-2004-2594No exploit | Absolute path traversal vulnerability in Quake II server before R1Q2 on Windows, as used in multiple products, allows remote attackers to reid software · quake ii server windows | Medium5.0 | — | 1.8% | Dec 31, 2004 |
21Monitor | CVE-2000-1080No exploit | Quake 1 (quake1) and ProQuake 1.01 and earlier allow remote attackers to cause a denial of service via a malformed (empty) UDP packet.id software · quake | Medium5.0 | — | 1.7% | Nov 1, 2000 |
20Monitor | CVE-2004-2597No exploit | Quake II server before R1Q2, as used in multiple products, allows remote attackers to bypass IP-based access control rules via a userinfo stid software · quake ii server | Medium5.0 | — | 1.6% | Dec 31, 2004 |
20Monitor | CVE-2004-2598No exploit | Quake II server before R1Q2, as used in multiple products, allows remote attackers to corrupt the server's client state data structure by exid software · quake ii server | Medium5.0 | — | 1.4% | Dec 31, 2004 |
20Monitor | CVE-1999-1230No exploit | Quake 2 server allows remote attackers to cause a denial of service via a spoofed UDP packet with a source address of 127.0.0.1, which causeid software · quake 2 | Medium5.0 | — | 1.3% | Dec 24, 1997 |
- CVE-2007-524839Monitor
Multiple format string vulnerabilities in the ID Software Doom 3 engine, as used by Doom 3 1.3.1 and earlier, Quake 4 1.4.2 and earlier, and
CriticalCVSS 9.3Proof of conceptEPSS 7%id software · doom 3Oct 6, 2007
- CVE-2006-223632Monitor
Buffer overflow in the Quake 3 Engine, as used by (1) ET 2.60, (2) Return to Castle Wolfenstein 1.41, and (3) Quake III Arena 1.32b allows r
HighCVSS 7.6Proof of conceptEPSS 8%id software · quake 3 arenaMay 8, 2006
- CVE-2006-287532Monitor
Stack-based buffer overflow in the CL_ParseDownload function of Quake 3 Engine 1.32c and earlier, as used in multiple products, allows remot
HighCVSS 7.5Proof of conceptEPSS 7%id software · quake 3 engineJun 6, 2006
- CVE-2006-340132Monitor
Stack-based buffer overflow in Quake 3 Engine as used by Quake 3: Arena 1.32b and 1.32c allows remote attackers to cause a denial of service
HighCVSS 7.5Proof of conceptEPSS 6%id software · quake 3 engineJul 6, 2006
- CVE-2006-340031Monitor
Stack-based buffer overflow in the CG_ServerCommand function in Quake 3 Engine as used by Soldier of Fortune 2 (SOF2MP) GOLD 1.03 allows rem
HighCVSS 7.5Proof of conceptEPSS 5%id software · quake 3 engineJul 6, 2006
- CVE-2004-259331Monitor
Buffer overflow in command-packet processing of Quake II server before R1Q2, as used in multiple products, allows remote attackers to cause
HighCVSS 7.5No exploitEPSS 4%id software · quake ii serverDec 31, 2004
- CVE-2006-208231Monitor
Directory traversal vulnerability in Quake 3 engine, as used in products including Quake3 Arena, Return to Castle Wolfenstein, Wolfenstein:
HighCVSS 7.5No exploitEPSS 3%id software · quake 3 engineMay 9, 2006
- CVE-1999-150531Monitor
Buffer overflow in QuakeWorld 2.10 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary commands via
HighCVSS 7.5No exploitEPSS 2%id software · quakeworldApr 7, 1998
- CVE-1999-150231Monitor
Buffer overflows in Quake 1.9 client allows remote malicious servers to execute arbitrary commands via long (1) precache paths, (2) server n
HighCVSS 7.5No exploitEPSS 2%id software · quakeApr 8, 1998
- CVE-2000-030325Monitor
Quake3 Arena allows malicious server operators to read or modify files on a client via a dot dot (..) attack.
MediumCVSS 6.4No exploitEPSS 1%id software · quake 3 arenaMay 3, 2000
- CVE-2005-043022Monitor
The Quake 3 engine, as used in multiple game packages, allows remote attackers to cause a denial of service (shutdown game server) and possi
MediumCVSS 5.0Proof of conceptEPSS 8%id software · quake 3 engineFeb 12, 2005
- CVE-2002-077022Monitor
Quake 2 (Q2) server 3.20 and 3.21 allows remote attackers to obtain sensitive server cvar variables, obtain directory listings, and execute
MediumCVSS 5.0Proof of conceptEPSS 6%id software · quake 2i serverAug 12, 2002
- CVE-2001-128922Monitor
Quake 3 arena 1.29f and 1.29g allows remote attackers to cause a denial of service (crash) via a malformed connection packet that begins wit
MediumCVSS 5.0Proof of conceptEPSS 5%id software · quake 3 arenaJul 29, 2001
- CVE-2006-332521Monitor
client/cl_parse.c in the id3 Quake 3 Engine 1.32c and the Icculus Quake 3 Engine (ioquake3) revision 810 and earlier allows remote malicious
MediumCVSS 5.0Proof of conceptEPSS 5%id software · quake 3 engineJun 30, 2006
- CVE-2006-332421Monitor
The Automatic Downloading option in the id3 Quake 3 Engine and the Icculus Quake 3 Engine (ioquake3) before revision 804 allows remote attac
MediumCVSS 5.0Proof of conceptEPSS 4%id software · quake 3 engineJun 30, 2006
- CVE-2004-259221Monitor
Quake II server before R1Q2, as used in multiple products, allows remote attackers to cause a denial of service (application crash) via a mo
MediumCVSS 5.0Proof of conceptEPSS 4%id software · quake ii serverDec 31, 2004
- CVE-1999-156921Monitor
Quake 1 and NetQuake servers allow remote attackers to cause a denial of service (resource exhaustion or forced disconnection) via a flood o
MediumCVSS 5.0Proof of conceptEPSS 3%id software · quakeJul 17, 2001
- CVE-2004-259521Monitor
Absolute path traversal vulnerability in Quake II server before R1Q2 on Linux, as used in multiple products, allows remote attackers to caus
MediumCVSS 5.0No exploitEPSS 3%id software · quake ii server linuxDec 31, 2004
- CVE-2005-098321Monitor
Quake 3 engine, as used in multiple games, allows remote attackers to cause a denial of service (client disconnect) via a long message, whic
MediumCVSS 5.0No exploitEPSS 3%activision · call of dutyMay 2, 2005
- CVE-2004-259621Monitor
Quake II server before R1Q2, as used in multiple products, allows remote attackers to cause a denial of service (exhaustion of connection sl
MediumCVSS 5.0No exploitEPSS 2%id software · quake ii serverDec 31, 2004
- CVE-2004-259421Monitor
Absolute path traversal vulnerability in Quake II server before R1Q2 on Windows, as used in multiple products, allows remote attackers to re
MediumCVSS 5.0No exploitEPSS 2%id software · quake ii server windowsDec 31, 2004
- CVE-2000-108021Monitor
Quake 1 (quake1) and ProQuake 1.01 and earlier allow remote attackers to cause a denial of service via a malformed (empty) UDP packet.
MediumCVSS 5.0No exploitEPSS 2%id software · quakeNov 1, 2000
- CVE-2004-259720Monitor
Quake II server before R1Q2, as used in multiple products, allows remote attackers to bypass IP-based access control rules via a userinfo st
MediumCVSS 5.0No exploitEPSS 2%id software · quake ii serverDec 31, 2004
- CVE-2004-259820Monitor
Quake II server before R1Q2, as used in multiple products, allows remote attackers to corrupt the server's client state data structure by ex
MediumCVSS 5.0No exploitEPSS 1%id software · quake ii serverDec 31, 2004
- CVE-1999-123020Monitor
Quake 2 server allows remote attackers to cause a denial of service via a spoofed UDP packet with a source address of 127.0.0.1, which cause
MediumCVSS 5.0No exploitEPSS 1%id software · quake 2Dec 24, 1997