Overwolf records
5 published records for vendor overwolf.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-427 Uncontrolled Search Path Element2
- CWE-59 Improper Link Resolution Before File Access ('Link Following')1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
5 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2021-33501No exploit | Overwolf Client 0.169.0.22 allows XSS, with resultant Remote Code Execution, via an overwolfstore:// URL.overwolf · overwolf · CWE-79 | Critical9.6 | — | 7.9% | Jul 19, 2021 |
36Monitor | CVE-2020-15932No exploit | Overwolf before 0.149.2.30 mishandles Symbolic Links during updates, causing elevation of privileges.overwolf · overwolf · CWE-59 | High8.8 | — | 2.9% | Jul 24, 2020 |
33Monitor | CVE-2020-25214No exploit | In the client in Overwolf 0.149.2.30, a channel can be accessed or influenced by an actor that is not an endpoint.overwolf · overwolf | High8.1 | — | 3.1% | Oct 16, 2020 |
31Monitor | CVE-2024-7834No exploit | Local privilege escalation in Overwolfoverwolf · overwolf · CWE-427 | High7.8 | — | 0.3% | Sep 4, 2024 |
31Monitor | CVE-2021-20726No exploit | Untrusted search path vulnerability in The Installer of Overwolf 2.168.0.n and earlier allows an attacker to gain privileges and execute arboverwolf · overwolf · CWE-427 | High7.8 | — | 0.3% | May 24, 2021 |
- CVE-2021-3350140Plan
Overwolf Client 0.169.0.22 allows XSS, with resultant Remote Code Execution, via an overwolfstore:// URL.
CriticalCVSS 9.6No exploitEPSS 8%overwolf · overwolfJul 19, 2021
- CVE-2020-1593236Monitor
Overwolf before 0.149.2.30 mishandles Symbolic Links during updates, causing elevation of privileges.
HighCVSS 8.8No exploitEPSS 3%overwolf · overwolfJul 24, 2020
- CVE-2020-2521433Monitor
In the client in Overwolf 0.149.2.30, a channel can be accessed or influenced by an actor that is not an endpoint.
HighCVSS 8.1No exploitEPSS 3%overwolf · overwolfOct 16, 2020
- CVE-2024-783431Monitor
Local privilege escalation in Overwolf
HighCVSS 7.8No exploitEPSS 0%overwolf · overwolfSep 4, 2024
- CVE-2021-2072631Monitor
Untrusted search path vulnerability in The Installer of Overwolf 2.168.0.n and earlier allows an attacker to gain privileges and execute arb
HighCVSS 7.8No exploitEPSS 0%overwolf · overwolfMay 24, 2021