activision records
8 published records for vendor activision.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 3
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-20 Improper Input Validation2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')1
- CWE-787 Out-of-bounds Write1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
8 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
49Plan | CVE-2018-10718Proof of concept | Stack-based buffer overflow in Activision Infinity Ward Call of Duty Modern Warfare 2 before 2018-04-26 allows remote attackers to execute aactivision · call of duty modern warfare 2 · CWE-787 | Critical10.0 | — | 30.2% | May 3, 2018 |
40Plan | CVE-2018-20817No exploit | SV_SteamAuthClient in various Activision Infinity Ward Call of Duty games before 2015-08-11 is missing a size check when reading authBlob daactivision · call of duty\ · CWE-119 | Critical9.8 | — | 3.6% | Apr 19, 2019 |
40Plan | CVE-2019-20893No exploit | An issue was discovered in Activision Infinity Ward Call of Duty Modern Warfare 2 through 2019-12-11.activision · call of duty modern warfare 2 · CWE-120 | Critical9.8 | — | 2.2% | Jun 30, 2020 |
33Monitor | CVE-2006-5058Proof of concept | Buffer overflow in (1) Call of Duty 1.5b and earlier, (2) Call of Duty United Offensive 1.51b and earlier, and (3) Call of Duty 2 1.3 and eaactivision · call of duty | High7.5 | — | 10.1% | Sep 27, 2006 |
29Monitor | CVE-2008-2106Proof of concept | Call of Duty 4 (CoD4) 1.5 and earlier allows remote authenticated users to cause a denial of service (crash) via a type 7 stats packet, whicactivision · call of duty 4 · CWE-20 | Medium6.8 | — | 7.7% | May 7, 2008 |
23Monitor | CVE-2012-4918No exploit | Call of Duty Elite for iOS 2.0.1 does not properly validate the server SSL certificate, which allows remote attackers to obtain sensitive inactivision · call of duty elite · CWE-20 | Medium5.8 | — | 1.1% | Jan 22, 2013 |
22Monitor | CVE-2004-1664Proof of concept | Call of Duty 1.4 and earlier allows remote attackers to cause a denial of service (game end) via a large (1) query or (2) reply packet, whicactivision · call of duty | Medium5.0 | — | 7.6% | Sep 5, 2004 |
21Monitor | CVE-2005-0983No exploit | Quake 3 engine, as used in multiple games, allows remote attackers to cause a denial of service (client disconnect) via a long message, whicactivision · call of duty | Medium5.0 | — | 2.6% | May 2, 2005 |
- CVE-2018-1071849Plan
Stack-based buffer overflow in Activision Infinity Ward Call of Duty Modern Warfare 2 before 2018-04-26 allows remote attackers to execute a
CriticalCVSS 10.0Proof of conceptEPSS 30%activision · call of duty modern warfare 2May 3, 2018
- CVE-2018-2081740Plan
SV_SteamAuthClient in various Activision Infinity Ward Call of Duty games before 2015-08-11 is missing a size check when reading authBlob da
CriticalCVSS 9.8No exploitEPSS 4%activision · call of duty\Apr 19, 2019
- CVE-2019-2089340Plan
An issue was discovered in Activision Infinity Ward Call of Duty Modern Warfare 2 through 2019-12-11.
CriticalCVSS 9.8No exploitEPSS 2%activision · call of duty modern warfare 2Jun 30, 2020
- CVE-2006-505833Monitor
Buffer overflow in (1) Call of Duty 1.5b and earlier, (2) Call of Duty United Offensive 1.51b and earlier, and (3) Call of Duty 2 1.3 and ea
HighCVSS 7.5Proof of conceptEPSS 10%activision · call of dutySep 27, 2006
- CVE-2008-210629Monitor
Call of Duty 4 (CoD4) 1.5 and earlier allows remote authenticated users to cause a denial of service (crash) via a type 7 stats packet, whic
MediumCVSS 6.8Proof of conceptEPSS 8%activision · call of duty 4May 7, 2008
- CVE-2012-491823Monitor
Call of Duty Elite for iOS 2.0.1 does not properly validate the server SSL certificate, which allows remote attackers to obtain sensitive in
MediumCVSS 5.8No exploitEPSS 1%activision · call of duty eliteJan 22, 2013
- CVE-2004-166422Monitor
Call of Duty 1.4 and earlier allows remote attackers to cause a denial of service (game end) via a large (1) query or (2) reply packet, whic
MediumCVSS 5.0Proof of conceptEPSS 8%activision · call of dutySep 5, 2004
- CVE-2005-098321Monitor
Quake 3 engine, as used in multiple games, allows remote attackers to cause a denial of service (client disconnect) via a long message, whic
MediumCVSS 5.0No exploitEPSS 3%activision · call of dutyMay 2, 2005