Skip to content
Noroxi

valvesoftware records

29 published records for vendor valvesoftware.

Bug bounty scope

The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.

All records

29 records
  • Valve's Game Networking Sockets prior to version v1.2.0 improperly handles unreliable segments with negative offsets in function SNP_Receive

    CriticalCVSS 9.8No exploitEPSS 6%

    valvesoftware · game networking socketsNov 18, 2020

  • An issue was discovered in Valve Steam Link build 643.

    CriticalCVSS 9.8No exploitEPSS 4%

    valvesoftware · steam link firmwareDec 27, 2017

  • Valve's Game Networking Sockets prior to version v1.2.0 improperly handles long encrypted messages in function AES_GCM_DecryptContext::Decry

    CriticalCVSS 9.8No exploitEPSS 3%

    valvesoftware · game networking socketsDec 1, 2020

  • Valve's Game Networking Sockets prior to version v1.2.0 improperly handles long unreliable segments in function SNP_ReceiveUnreliableSegment

    CriticalCVSS 9.8No exploitEPSS 3%

    valvesoftware · game networking socketsDec 3, 2020

  • An issue was discovered in Valve Steam Link build 643.

    CriticalCVSS 9.8No exploitEPSS 2%

    valvesoftware · steam link firmwareDec 27, 2017

  • A buffer overflow in Counter-Strike through 8684 allows a game server to execute arbitrary code on a remote client's machine by modifying th

    CriticalCVSS 9.8No exploitEPSS 1%

    valvesoftware · counter-strikeJun 19, 2023

  • vphysics.dll in Counter-Strike: Global Offensive before 1.37.1.1 allows remote attackers to achieve code execution or denial of service by c

    HighCVSS 8.8Proof of conceptEPSS 9%

    valvesoftware · counter-strike\Sep 19, 2019

  • Valve Steam before 2021-04-17, when a Source engine game is installed, allows remote authenticated users to execute arbitrary code because o

    CriticalCVSS 9.0Proof of conceptEPSS 4%

    valvesoftware · steam clientApr 10, 2021

  • CVE-2020-7949
    32Monitor

    schemasystem.dll in Valve Dota 2 before 7.23f allows remote attackers to achieve code execution or denial of service by creating a gaming se

    HighCVSS 7.8Proof of conceptEPSS 4%

    valvesoftware · dota 2Jan 27, 2020

  • CVE-2020-9005
    32Monitor

    meshsystem.dll in Valve Dota 2 through 2020-02-17 allows remote attackers to achieve code execution or denial of service by creating a gamin

    HighCVSS 7.8No exploitEPSS 2%

    valvesoftware · dota 2Feb 17, 2020

  • CVE-2020-7950
    32Monitor

    meshsystem.dll in Valve Dota 2 before 7.23f allows remote attackers to achieve code execution or denial of service by creating a gaming serv

    HighCVSS 7.8No exploitEPSS 2%

    valvesoftware · dota 2Jan 27, 2020

  • CVE-2020-7951
    32Monitor

    meshsystem.dll in Valve Dota 2 before 7.23e allows remote attackers to achieve code execution or denial of service by creating a gaming serv

    HighCVSS 7.8No exploitEPSS 2%

    valvesoftware · dota 2Jan 27, 2020

  • CVE-2020-7952
    32Monitor

    rendersystemdx9.dll in Valve Dota 2 before 7.23f allows remote attackers to achieve code execution or denial of service by creating a gaming

    HighCVSS 7.8No exploitEPSS 2%

    valvesoftware · dota 2Jan 27, 2020

  • CVE-2020-6019
    31Monitor

    Valve's Game Networking Sockets prior to version v1.2.0 improperly handles inlined statistics messages in function CConnectionTransportUDPBa

    HighCVSS 7.5No exploitEPSS 3%

    valvesoftware · game networking socketsNov 13, 2020

  • Valve Source allows local users to gain privileges by writing to the /tmp/hl2_relaunch file, which is later executed in the context of a dif

    HighCVSS 7.8Proof of conceptEPSS 1%

    valvesoftware · sourceApr 27, 2020

  • Valve Steam Client before 2019-09-12 allows placing or appending partially controlled filesystem content, as demonstrated by file modificati

    HighCVSS 7.8No exploitEPSS 1%

    valvesoftware · steam clientOct 4, 2019

  • An issue was discovered in Valve Steam Client 2.10.91.91.

    HighCVSS 7.8No exploitEPSS 1%

    valvesoftware · steam clientJul 4, 2020

  • Valve Steam Client for Windows through 2019-08-16 allows privilege escalation (to NT AUTHORITY\SYSTEM) because local users can replace the c

    HighCVSS 7.8No exploitEPSS 0%

    valvesoftware · steam clientAug 21, 2019

  • A directory traversal vulnerability in Valve Counter-Strike 8684 allows a client (with remote control access to a game server) to read arbit

    HighCVSS 7.5No exploitEPSS 1%

    valvesoftware · counter-strikeOct 15, 2023

  • A buffer overflow in the component hl.exe of Valve Half-Life up to 5433873 allows attackers to execute arbitrary code and escalate privilege

    HighCVSS 7.3No exploitEPSS 0%

    valvesoftware · half-lifeMay 23, 2023

  • CVE-2015-7985
    28Monitor

    Valve Steam 2.10.91.91 uses weak permissions (Users: read and write) for the Install folder, which allows local users to gain privileges via

    HighCVSS 7.2Proof of conceptEPSS 1%

    valvesoftware · steam clientNov 24, 2015

  • Valve Steam Client for Windows through 2019-08-20 has weak folder permissions, leading to privilege escalation (to NT AUTHORITY\SYSTEM) via

    HighCVSS 7.0No exploitEPSS 0%

    valvesoftware · steam clientAug 21, 2019

  • In Valve Steam Client for Windows through 2019-08-07, HKLM\SOFTWARE\Wow6432Node\Valve\Steam has explicit "Full control" for the Users group,

    MediumCVSS 6.6No exploitEPSS 1%

    valvesoftware · steam clientAug 7, 2019

  • CVE-2015-4016
    21Monitor

    The client detection protocol in Valve Steam allows remote attackers to cause a denial of service (process crash) via a crafted response to

    MediumCVSS 5.0No exploitEPSS 3%

    valvesoftware · steam clientMay 20, 2015

  • CVE-2008-7203
    21Monitor

    Valve Software Half-Life Counter-Strike 1.6 allows remote attackers to cause a denial of service (crash) via multiple crafted login packets.

    MediumCVSS 5.0Proof of conceptEPSS 3%

    valvesoftware · counter-strikeSep 11, 2009