Blizzard records
4 published records for vendor blizzard.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-281 Improper Preservation of Permissions1
- CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')1
- CWE-427 Uncontrolled Search Path Element1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
4 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
38Monitor | CVE-2009-4768No exploit | Unspecified vulnerability in the JASS script interpreter in Warcraft III: The Frozen Throne 1.24b and earlier allows user-assisted remote atblizzard · warcraft 3 the frozen throne · CWE-94 | Critical9.3 | — | 3.4% | Apr 20, 2010 |
33Monitor | CVE-2025-27997No exploit | An issue in Blizzard Battle.net v2.40.0.15267 allows attackers to escalate privileges via placing a crafted shell script or executable into blizzard · battle.net · CWE-427 | High8.4 | — | 0.2% | May 21, 2025 |
31Monitor | CVE-2020-27383No exploit | Battle.net.exe in Battle.Net 1.27.1.12428 suffers from an elevation of privileges vulnerability which can be used by an "Authenticated User"blizzard · battle.net · CWE-281 | High7.8 | — | 0.3% | Jun 9, 2021 |
21Monitor | CVE-2017-14748No exploit | Race condition in Blizzard Overwatch 1.15.0.2 allows remote authenticated users to cause a denial of service (season bans and SR losses for blizzard · overwatch · CWE-362 | Medium5.3 | — | 1.1% | Sep 26, 2017 |
- CVE-2009-476838Monitor
Unspecified vulnerability in the JASS script interpreter in Warcraft III: The Frozen Throne 1.24b and earlier allows user-assisted remote at
CriticalCVSS 9.3No exploitEPSS 3%blizzard · warcraft 3 the frozen throneApr 20, 2010
- CVE-2025-2799733Monitor
An issue in Blizzard Battle.net v2.40.0.15267 allows attackers to escalate privileges via placing a crafted shell script or executable into
HighCVSS 8.4No exploitEPSS 0%blizzard · battle.netMay 21, 2025
- CVE-2020-2738331Monitor
Battle.net.exe in Battle.Net 1.27.1.12428 suffers from an elevation of privileges vulnerability which can be used by an "Authenticated User"
HighCVSS 7.8No exploitEPSS 0%blizzard · battle.netJun 9, 2021
- CVE-2017-1474821Monitor
Race condition in Blizzard Overwatch 1.15.0.2 allows remote authenticated users to cause a denial of service (season bans and SR losses for
MediumCVSS 5.3No exploitEPSS 1%blizzard · overwatchSep 26, 2017