Skip to content
Noroxi

id software records

27 published records for vendor id software.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
6
With a fix record
18.5%
Median publish → KEV
No record has entered KEV

All records

27 records
  • CVE-2007-5248
    39Monitor

    Multiple format string vulnerabilities in the ID Software Doom 3 engine, as used by Doom 3 1.3.1 and earlier, Quake 4 1.4.2 and earlier, and

    CriticalCVSS 9.3Proof of conceptEPSS 7%

    id software · doom 3Oct 6, 2007

  • CVE-2006-2236
    32Monitor

    Buffer overflow in the Quake 3 Engine, as used by (1) ET 2.60, (2) Return to Castle Wolfenstein 1.41, and (3) Quake III Arena 1.32b allows r

    HighCVSS 7.6Proof of conceptEPSS 8%

    id software · quake 3 arenaMay 8, 2006

  • CVE-2006-2875
    32Monitor

    Stack-based buffer overflow in the CL_ParseDownload function of Quake 3 Engine 1.32c and earlier, as used in multiple products, allows remot

    HighCVSS 7.5Proof of conceptEPSS 7%

    id software · quake 3 engineJun 6, 2006

  • CVE-2006-3401
    32Monitor

    Stack-based buffer overflow in Quake 3 Engine as used by Quake 3: Arena 1.32b and 1.32c allows remote attackers to cause a denial of service

    HighCVSS 7.5Proof of conceptEPSS 6%

    id software · quake 3 engineJul 6, 2006

  • CVE-2006-3400
    31Monitor

    Stack-based buffer overflow in the CG_ServerCommand function in Quake 3 Engine as used by Soldier of Fortune 2 (SOF2MP) GOLD 1.03 allows rem

    HighCVSS 7.5Proof of conceptEPSS 5%

    id software · quake 3 engineJul 6, 2006

  • CVE-2004-2593
    31Monitor

    Buffer overflow in command-packet processing of Quake II server before R1Q2, as used in multiple products, allows remote attackers to cause

    HighCVSS 7.5No exploitEPSS 4%

    id software · quake ii serverDec 31, 2004

  • CVE-2006-2082
    31Monitor

    Directory traversal vulnerability in Quake 3 engine, as used in products including Quake3 Arena, Return to Castle Wolfenstein, Wolfenstein:

    HighCVSS 7.5No exploitEPSS 3%

    id software · quake 3 engineMay 9, 2006

  • CVE-1999-1505
    31Monitor

    Buffer overflow in QuakeWorld 2.10 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary commands via

    HighCVSS 7.5No exploitEPSS 2%

    id software · quakeworldApr 7, 1998

  • CVE-1999-1502
    31Monitor

    Buffer overflows in Quake 1.9 client allows remote malicious servers to execute arbitrary commands via long (1) precache paths, (2) server n

    HighCVSS 7.5No exploitEPSS 2%

    id software · quakeApr 8, 1998

  • CVE-2000-0303
    25Monitor

    Quake3 Arena allows malicious server operators to read or modify files on a client via a dot dot (..) attack.

    MediumCVSS 6.4No exploitEPSS 1%

    id software · quake 3 arenaMay 3, 2000

  • CVE-2005-0430
    22Monitor

    The Quake 3 engine, as used in multiple game packages, allows remote attackers to cause a denial of service (shutdown game server) and possi

    MediumCVSS 5.0Proof of conceptEPSS 8%

    id software · quake 3 engineFeb 12, 2005

  • CVE-2002-0770
    22Monitor

    Quake 2 (Q2) server 3.20 and 3.21 allows remote attackers to obtain sensitive server cvar variables, obtain directory listings, and execute

    MediumCVSS 5.0Proof of conceptEPSS 6%

    id software · quake 2i serverAug 12, 2002

  • CVE-2001-1289
    22Monitor

    Quake 3 arena 1.29f and 1.29g allows remote attackers to cause a denial of service (crash) via a malformed connection packet that begins wit

    MediumCVSS 5.0Proof of conceptEPSS 5%

    id software · quake 3 arenaJul 29, 2001

  • CVE-2006-3325
    21Monitor

    client/cl_parse.c in the id3 Quake 3 Engine 1.32c and the Icculus Quake 3 Engine (ioquake3) revision 810 and earlier allows remote malicious

    MediumCVSS 5.0Proof of conceptEPSS 5%

    id software · quake 3 engineJun 30, 2006

  • CVE-2006-3324
    21Monitor

    The Automatic Downloading option in the id3 Quake 3 Engine and the Icculus Quake 3 Engine (ioquake3) before revision 804 allows remote attac

    MediumCVSS 5.0Proof of conceptEPSS 4%

    id software · quake 3 engineJun 30, 2006

  • CVE-2004-2592
    21Monitor

    Quake II server before R1Q2, as used in multiple products, allows remote attackers to cause a denial of service (application crash) via a mo

    MediumCVSS 5.0Proof of conceptEPSS 4%

    id software · quake ii serverDec 31, 2004

  • CVE-1999-1569
    21Monitor

    Quake 1 and NetQuake servers allow remote attackers to cause a denial of service (resource exhaustion or forced disconnection) via a flood o

    MediumCVSS 5.0Proof of conceptEPSS 3%

    id software · quakeJul 17, 2001

  • CVE-2004-2595
    21Monitor

    Absolute path traversal vulnerability in Quake II server before R1Q2 on Linux, as used in multiple products, allows remote attackers to caus

    MediumCVSS 5.0No exploitEPSS 3%

    id software · quake ii server linuxDec 31, 2004

  • CVE-2005-0983
    21Monitor

    Quake 3 engine, as used in multiple games, allows remote attackers to cause a denial of service (client disconnect) via a long message, whic

    MediumCVSS 5.0No exploitEPSS 3%

    activision · call of dutyMay 2, 2005

  • CVE-2004-2596
    21Monitor

    Quake II server before R1Q2, as used in multiple products, allows remote attackers to cause a denial of service (exhaustion of connection sl

    MediumCVSS 5.0No exploitEPSS 2%

    id software · quake ii serverDec 31, 2004

  • CVE-2004-2594
    21Monitor

    Absolute path traversal vulnerability in Quake II server before R1Q2 on Windows, as used in multiple products, allows remote attackers to re

    MediumCVSS 5.0No exploitEPSS 2%

    id software · quake ii server windowsDec 31, 2004

  • CVE-2000-1080
    21Monitor

    Quake 1 (quake1) and ProQuake 1.01 and earlier allow remote attackers to cause a denial of service via a malformed (empty) UDP packet.

    MediumCVSS 5.0No exploitEPSS 2%

    id software · quakeNov 1, 2000

  • CVE-2004-2597
    20Monitor

    Quake II server before R1Q2, as used in multiple products, allows remote attackers to bypass IP-based access control rules via a userinfo st

    MediumCVSS 5.0No exploitEPSS 2%

    id software · quake ii serverDec 31, 2004

  • CVE-2004-2598
    20Monitor

    Quake II server before R1Q2, as used in multiple products, allows remote attackers to corrupt the server's client state data structure by ex

    MediumCVSS 5.0No exploitEPSS 1%

    id software · quake ii serverDec 31, 2004

  • CVE-1999-1230
    20Monitor

    Quake 2 server allows remote attackers to cause a denial of service via a spoofed UDP packet with a source address of 127.0.0.1, which cause

    MediumCVSS 5.0No exploitEPSS 1%

    id software · quake 2Dec 24, 1997