Записи valvesoftware
29 опубликованных записей вендора valvesoftware.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 4
- С записью об исправлении
- 3,4 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')4
- CWE-787 Out-of-bounds Write4
- CWE-20 Improper Input Validation2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-732 Incorrect Permission Assignment for Critical Resource2
- CWE-116 Improper Encoding or Escaping of Output1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEОхват bug bounty
Вендор продукта присутствует в публичной программе. Сопоставление по имени; проверьте текст scope в программе.
Все записи
29 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
41В плане | CVE-2020-6016Эксплойта нет | Valve's Game Networking Sockets prior to version v1.2.0 improperly handles unreliable segments with negative offsets in function SNP_Receivevalvesoftware · game networking sockets · CWE-590 | Критическая9,8 | — | 6,0 % | 18 нояб. 2020 г. |
40В плане | CVE-2017-17877Эксплойта нет | An issue was discovered in Valve Steam Link build 643.valvesoftware · steam link firmware | Критическая9,8 | — | 4,1 % | 27 дек. 2017 г. |
40В плане | CVE-2020-6018Эксплойта нет | Valve's Game Networking Sockets prior to version v1.2.0 improperly handles long encrypted messages in function AES_GCM_DecryptContext::Decryvalvesoftware · game networking sockets · CWE-120 | Критическая9,8 | — | 3,2 % | 1 дек. 2020 г. |
40В плане | CVE-2020-6017Эксплойта нет | Valve's Game Networking Sockets prior to version v1.2.0 improperly handles long unreliable segments in function SNP_ReceiveUnreliableSegmentvalvesoftware · game networking sockets · CWE-120 | Критическая9,8 | — | 3,2 % | 3 дек. 2020 г. |
39Наблюдать | CVE-2017-17878Эксплойта нет | An issue was discovered in Valve Steam Link build 643.valvesoftware · steam link firmware · CWE-327 | Критическая9,8 | — | 1,6 % | 27 дек. 2017 г. |
39Наблюдать | CVE-2023-35855Эксплойта нет | A buffer overflow in Counter-Strike through 8684 allows a game server to execute arbitrary code on a remote client's machine by modifying thvalvesoftware · counter-strike · CWE-120 | Критическая9,8 | — | 1,1 % | 19 июн. 2023 г. |
38Наблюдать | CVE-2019-15943Proof of concept | vphysics.dll in Counter-Strike: Global Offensive before 1.37.1.1 allows remote attackers to achieve code execution or denial of service by cvalvesoftware · counter-strike\ · CWE-787 | Высокая8,8 | — | 8,7 % | 19 сент. 2019 г. |
37Наблюдать | CVE-2021-30481Proof of concept | Valve Steam before 2021-04-17, when a Source engine game is installed, allows remote authenticated users to execute arbitrary code because ovalvesoftware · steam client · CWE-120 | Критическая9,0 | — | 3,5 % | 10 апр. 2021 г. |
32Наблюдать | CVE-2020-7949Proof of concept | schemasystem.dll in Valve Dota 2 before 7.23f allows remote attackers to achieve code execution or denial of service by creating a gaming sevalvesoftware · dota 2 | Высокая7,8 | — | 4,2 % | 27 янв. 2020 г. |
32Наблюдать | CVE-2020-9005Эксплойта нет | meshsystem.dll in Valve Dota 2 through 2020-02-17 allows remote attackers to achieve code execution or denial of service by creating a gaminvalvesoftware · dota 2 · CWE-787 | Высокая7,8 | — | 2,2 % | 17 февр. 2020 г. |
32Наблюдать | CVE-2020-7950Эксплойта нет | meshsystem.dll in Valve Dota 2 before 7.23f allows remote attackers to achieve code execution or denial of service by creating a gaming servvalvesoftware · dota 2 | Высокая7,8 | — | 1,9 % | 27 янв. 2020 г. |
32Наблюдать | CVE-2020-7951Эксплойта нет | meshsystem.dll in Valve Dota 2 before 7.23e allows remote attackers to achieve code execution or denial of service by creating a gaming servvalvesoftware · dota 2 · CWE-787 | Высокая7,8 | — | 1,9 % | 27 янв. 2020 г. |
32Наблюдать | CVE-2020-7952Эксплойта нет | rendersystemdx9.dll in Valve Dota 2 before 7.23f allows remote attackers to achieve code execution or denial of service by creating a gamingvalvesoftware · dota 2 | Высокая7,8 | — | 1,9 % | 27 янв. 2020 г. |
31Наблюдать | CVE-2020-6019Эксплойта нет | Valve's Game Networking Sockets prior to version v1.2.0 improperly handles inlined statistics messages in function CConnectionTransportUDPBavalvesoftware · game networking sockets · CWE-248 | Высокая7,5 | — | 2,8 % | 13 нояб. 2020 г. |
31Наблюдать | CVE-2020-12242Proof of concept | Valve Source allows local users to gain privileges by writing to the /tmp/hl2_relaunch file, which is later executed in the context of a difvalvesoftware · source · CWE-78 | Высокая7,8 | — | 1,1 % | 27 апр. 2020 г. |
31Наблюдать | CVE-2019-17180Эксплойта нет | Valve Steam Client before 2019-09-12 allows placing or appending partially controlled filesystem content, as demonstrated by file modificativalvesoftware · steam client · CWE-22 | Высокая7,8 | — | 0,7 % | 4 окт. 2019 г. |
31Наблюдать | CVE-2020-15530Эксплойта нет | An issue was discovered in Valve Steam Client 2.10.91.91.valvesoftware · steam client · CWE-362 | Высокая7,8 | — | 0,5 % | 4 июл. 2020 г. |
31Наблюдать | CVE-2019-15315Эксплойта нет | Valve Steam Client for Windows through 2019-08-16 allows privilege escalation (to NT AUTHORITY\SYSTEM) because local users can replace the cvalvesoftware · steam client · CWE-732 | Высокая7,8 | — | 0,4 % | 21 авг. 2019 г. |
30Наблюдать | CVE-2023-38312Эксплойта нет | A directory traversal vulnerability in Valve Counter-Strike 8684 allows a client (with remote control access to a game server) to read arbitvalvesoftware · counter-strike · CWE-22 | Высокая7,5 | — | 0,8 % | 15 окт. 2023 г. |
29Наблюдать | CVE-2023-30382Эксплойта нет | A buffer overflow in the component hl.exe of Valve Half-Life up to 5433873 allows attackers to execute arbitrary code and escalate privilegevalvesoftware · half-life · CWE-787 | Высокая7,3 | — | 0,2 % | 23 мая 2023 г. |
28Наблюдать | CVE-2015-7985Proof of concept | Valve Steam 2.10.91.91 uses weak permissions (Users: read and write) for the Install folder, which allows local users to gain privileges viavalvesoftware · steam client · CWE-276 | Высокая7,2 | — | 1,0 % | 24 нояб. 2015 г. |
28Наблюдать | CVE-2019-15316Эксплойта нет | Valve Steam Client for Windows through 2019-08-20 has weak folder permissions, leading to privilege escalation (to NT AUTHORITY\SYSTEM) via valvesoftware · steam client · CWE-367 | Высокая7,0 | — | 0,4 % | 21 авг. 2019 г. |
26Наблюдать | CVE-2019-14743Эксплойта нет | In Valve Steam Client for Windows through 2019-08-07, HKLM\SOFTWARE\Wow6432Node\Valve\Steam has explicit "Full control" for the Users group,valvesoftware · steam client · CWE-732 | Средняя6,6 | — | 0,6 % | 7 авг. 2019 г. |
21Наблюдать | CVE-2015-4016Эксплойта нет | The client detection protocol in Valve Steam allows remote attackers to cause a denial of service (process crash) via a crafted response to valvesoftware · steam client · CWE-20 | Средняя5,0 | — | 3,0 % | 20 мая 2015 г. |
21Наблюдать | CVE-2008-7203Proof of concept | Valve Software Half-Life Counter-Strike 1.6 allows remote attackers to cause a denial of service (crash) via multiple crafted login packets.valvesoftware · counter-strike · CWE-399 | Средняя5,0 | — | 2,6 % | 11 сент. 2009 г. |
- CVE-2020-601641В плане
Valve's Game Networking Sockets prior to version v1.2.0 improperly handles unreliable segments with negative offsets in function SNP_Receive
КритическаяCVSS 9,8Эксплойта нетEPSS 6 %valvesoftware · game networking sockets18 нояб. 2020 г.
- CVE-2017-1787740В плане
An issue was discovered in Valve Steam Link build 643.
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %valvesoftware · steam link firmware27 дек. 2017 г.
- CVE-2020-601840В плане
Valve's Game Networking Sockets prior to version v1.2.0 improperly handles long encrypted messages in function AES_GCM_DecryptContext::Decry
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %valvesoftware · game networking sockets1 дек. 2020 г.
- CVE-2020-601740В плане
Valve's Game Networking Sockets prior to version v1.2.0 improperly handles long unreliable segments in function SNP_ReceiveUnreliableSegment
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %valvesoftware · game networking sockets3 дек. 2020 г.
- CVE-2017-1787839Наблюдать
An issue was discovered in Valve Steam Link build 643.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %valvesoftware · steam link firmware27 дек. 2017 г.
- CVE-2023-3585539Наблюдать
A buffer overflow in Counter-Strike through 8684 allows a game server to execute arbitrary code on a remote client's machine by modifying th
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %valvesoftware · counter-strike19 июн. 2023 г.
- CVE-2019-1594338Наблюдать
vphysics.dll in Counter-Strike: Global Offensive before 1.37.1.1 allows remote attackers to achieve code execution or denial of service by c
ВысокаяCVSS 8,8Proof of conceptEPSS 9 %valvesoftware · counter-strike\19 сент. 2019 г.
- CVE-2021-3048137Наблюдать
Valve Steam before 2021-04-17, when a Source engine game is installed, allows remote authenticated users to execute arbitrary code because o
КритическаяCVSS 9,0Proof of conceptEPSS 4 %valvesoftware · steam client10 апр. 2021 г.
- CVE-2020-794932Наблюдать
schemasystem.dll in Valve Dota 2 before 7.23f allows remote attackers to achieve code execution or denial of service by creating a gaming se
ВысокаяCVSS 7,8Proof of conceptEPSS 4 %valvesoftware · dota 227 янв. 2020 г.
- CVE-2020-900532Наблюдать
meshsystem.dll in Valve Dota 2 through 2020-02-17 allows remote attackers to achieve code execution or denial of service by creating a gamin
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %valvesoftware · dota 217 февр. 2020 г.
- CVE-2020-795032Наблюдать
meshsystem.dll in Valve Dota 2 before 7.23f allows remote attackers to achieve code execution or denial of service by creating a gaming serv
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %valvesoftware · dota 227 янв. 2020 г.
- CVE-2020-795132Наблюдать
meshsystem.dll in Valve Dota 2 before 7.23e allows remote attackers to achieve code execution or denial of service by creating a gaming serv
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %valvesoftware · dota 227 янв. 2020 г.
- CVE-2020-795232Наблюдать
rendersystemdx9.dll in Valve Dota 2 before 7.23f allows remote attackers to achieve code execution or denial of service by creating a gaming
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %valvesoftware · dota 227 янв. 2020 г.
- CVE-2020-601931Наблюдать
Valve's Game Networking Sockets prior to version v1.2.0 improperly handles inlined statistics messages in function CConnectionTransportUDPBa
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %valvesoftware · game networking sockets13 нояб. 2020 г.
- CVE-2020-1224231Наблюдать
Valve Source allows local users to gain privileges by writing to the /tmp/hl2_relaunch file, which is later executed in the context of a dif
ВысокаяCVSS 7,8Proof of conceptEPSS 1 %valvesoftware · source27 апр. 2020 г.
- CVE-2019-1718031Наблюдать
Valve Steam Client before 2019-09-12 allows placing or appending partially controlled filesystem content, as demonstrated by file modificati
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %valvesoftware · steam client4 окт. 2019 г.
- CVE-2020-1553031Наблюдать
An issue was discovered in Valve Steam Client 2.10.91.91.
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %valvesoftware · steam client4 июл. 2020 г.
- CVE-2019-1531531Наблюдать
Valve Steam Client for Windows through 2019-08-16 allows privilege escalation (to NT AUTHORITY\SYSTEM) because local users can replace the c
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %valvesoftware · steam client21 авг. 2019 г.
- CVE-2023-3831230Наблюдать
A directory traversal vulnerability in Valve Counter-Strike 8684 allows a client (with remote control access to a game server) to read arbit
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %valvesoftware · counter-strike15 окт. 2023 г.
- CVE-2023-3038229Наблюдать
A buffer overflow in the component hl.exe of Valve Half-Life up to 5433873 allows attackers to execute arbitrary code and escalate privilege
ВысокаяCVSS 7,3Эксплойта нетEPSS 0 %valvesoftware · half-life23 мая 2023 г.
- CVE-2015-798528Наблюдать
Valve Steam 2.10.91.91 uses weak permissions (Users: read and write) for the Install folder, which allows local users to gain privileges via
ВысокаяCVSS 7,2Proof of conceptEPSS 1 %valvesoftware · steam client24 нояб. 2015 г.
- CVE-2019-1531628Наблюдать
Valve Steam Client for Windows through 2019-08-20 has weak folder permissions, leading to privilege escalation (to NT AUTHORITY\SYSTEM) via
ВысокаяCVSS 7,0Эксплойта нетEPSS 0 %valvesoftware · steam client21 авг. 2019 г.
- CVE-2019-1474326Наблюдать
In Valve Steam Client for Windows through 2019-08-07, HKLM\SOFTWARE\Wow6432Node\Valve\Steam has explicit "Full control" for the Users group,
СредняяCVSS 6,6Эксплойта нетEPSS 1 %valvesoftware · steam client7 авг. 2019 г.
- CVE-2015-401621Наблюдать
The client detection protocol in Valve Steam allows remote attackers to cause a denial of service (process crash) via a crafted response to
СредняяCVSS 5,0Эксплойта нетEPSS 3 %valvesoftware · steam client20 мая 2015 г.
- CVE-2008-720321Наблюдать
Valve Software Half-Life Counter-Strike 1.6 allows remote attackers to cause a denial of service (crash) via multiple crafted login packets.
СредняяCVSS 5,0Proof of conceptEPSS 3 %valvesoftware · counter-strike11 сент. 2009 г.