NetHack records
11 published records for vendor nethack.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 4
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')9
- CWE-125 Out-of-bounds Read1
- CWE-184 Incomplete List of Disallowed Inputs1
The weakness classes this vendor ships most often: where to look.
CWEAll records
11 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2019-19905Proof of concept | NetHack 3.6.x before 3.6.4 is prone to a buffer overflow vulnerability when reading very long lines from configuration files.nethack · nethack · CWE-120 | Critical9.8 | — | 3.4% | Dec 19, 2019 |
39Monitor | CVE-2020-5214No exploit | NetHack error recovery after syntax error in configuration file is subject to a buffer overflownethack · nethack · CWE-120 | Critical9.8 | — | 1.1% | Jan 28, 2020 |
39Monitor | CVE-2020-5211No exploit | NetHack AUTOCOMPLETE configuration file option is subject to a buffer overflownethack · nethack · CWE-120 | Critical9.8 | — | 1.1% | Jan 28, 2020 |
39Monitor | CVE-2020-5212No exploit | NetHack MENUCOLOR configuration file option is subject to a buffer overflownethack · nethack · CWE-120 | Critical9.8 | — | 1.1% | Jan 28, 2020 |
39Monitor | CVE-2020-5213No exploit | NetHack SYMBOL configuration file option is subject to a buffer overflownethack · nethack · CWE-120 | Critical9.8 | — | 1.1% | Jan 28, 2020 |
39Monitor | CVE-2020-5253No exploit | Privilege escalation in NetHacknethack · nethack · CWE-184 | Critical9.8 | — | 0.5% | Mar 10, 2020 |
32Monitor | CVE-2020-5254Proof of concept | NetHack hilite_status parsing privilege escalationnethack · nethack · CWE-125 | High8.1 | — | 1.1% | Mar 10, 2020 |
31Monitor | CVE-2020-5209No exploit | NetHack command line parsing of options starting with -de and -i is subject to a buffer overflownethack · nethack · CWE-120 | High7.8 | — | 0.8% | Jan 28, 2020 |
31Monitor | CVE-2020-5210No exploit | NetHack command line -w option parsing is subject to a buffer overflownethack · nethack · CWE-120 | High7.8 | — | 0.8% | Jan 28, 2020 |
22Monitor | CVE-2023-24809No exploit | NetHack Call command buffer overflownethack · nethack · CWE-120 | Medium5.5 | — | 0.2% | Feb 17, 2023 |
18Monitor | CVE-2003-0358Proof of concept | Buffer overflow in (1) nethack 3.4.0 and earlier, and (2) falconseye 1.9.3 and earlier, which is based on nethack, allows local users to gainethack · nethack · CWE-120 | Medium4.6 | — | 1.2% | Jun 9, 2003 |
- CVE-2019-1990540Plan
NetHack 3.6.x before 3.6.4 is prone to a buffer overflow vulnerability when reading very long lines from configuration files.
CriticalCVSS 9.8Proof of conceptEPSS 3%nethack · nethackDec 19, 2019
- CVE-2020-521439Monitor
NetHack error recovery after syntax error in configuration file is subject to a buffer overflow
CriticalCVSS 9.8No exploitEPSS 1%nethack · nethackJan 28, 2020
- CVE-2020-521139Monitor
NetHack AUTOCOMPLETE configuration file option is subject to a buffer overflow
CriticalCVSS 9.8No exploitEPSS 1%nethack · nethackJan 28, 2020
- CVE-2020-521239Monitor
NetHack MENUCOLOR configuration file option is subject to a buffer overflow
CriticalCVSS 9.8No exploitEPSS 1%nethack · nethackJan 28, 2020
- CVE-2020-521339Monitor
NetHack SYMBOL configuration file option is subject to a buffer overflow
CriticalCVSS 9.8No exploitEPSS 1%nethack · nethackJan 28, 2020
- CVE-2020-525339Monitor
Privilege escalation in NetHack
CriticalCVSS 9.8No exploitEPSS 1%nethack · nethackMar 10, 2020
- CVE-2020-525432Monitor
NetHack hilite_status parsing privilege escalation
HighCVSS 8.1Proof of conceptEPSS 1%nethack · nethackMar 10, 2020
- CVE-2020-520931Monitor
NetHack command line parsing of options starting with -de and -i is subject to a buffer overflow
HighCVSS 7.8No exploitEPSS 1%nethack · nethackJan 28, 2020
- CVE-2020-521031Monitor
NetHack command line -w option parsing is subject to a buffer overflow
HighCVSS 7.8No exploitEPSS 1%nethack · nethackJan 28, 2020
- CVE-2023-2480922Monitor
NetHack Call command buffer overflow
MediumCVSS 5.5No exploitEPSS 0%nethack · nethackFeb 17, 2023
- CVE-2003-035818Monitor
Buffer overflow in (1) nethack 3.4.0 and earlier, and (2) falconseye 1.9.3 and earlier, which is based on nethack, allows local users to gai
MediumCVSS 4.6Proof of conceptEPSS 1%nethack · nethackJun 9, 2003