valvesoftware records
29 published records for vendor valvesoftware.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 4
- With a fix record
- 3.4%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')4
- CWE-787 Out-of-bounds Write4
- CWE-20 Improper Input Validation2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-732 Incorrect Permission Assignment for Critical Resource2
- CWE-116 Improper Encoding or Escaping of Output1
The weakness classes this vendor ships most often: where to look.
CWEBug bounty scope
The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.
All records
29 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2020-6016No exploit | Valve's Game Networking Sockets prior to version v1.2.0 improperly handles unreliable segments with negative offsets in function SNP_Receivevalvesoftware · game networking sockets · CWE-590 | Critical9.8 | — | 6.0% | Nov 18, 2020 |
40Plan | CVE-2017-17877No exploit | An issue was discovered in Valve Steam Link build 643.valvesoftware · steam link firmware | Critical9.8 | — | 4.1% | Dec 27, 2017 |
40Plan | CVE-2020-6018No exploit | Valve's Game Networking Sockets prior to version v1.2.0 improperly handles long encrypted messages in function AES_GCM_DecryptContext::Decryvalvesoftware · game networking sockets · CWE-120 | Critical9.8 | — | 3.2% | Dec 1, 2020 |
40Plan | CVE-2020-6017No exploit | Valve's Game Networking Sockets prior to version v1.2.0 improperly handles long unreliable segments in function SNP_ReceiveUnreliableSegmentvalvesoftware · game networking sockets · CWE-120 | Critical9.8 | — | 3.2% | Dec 3, 2020 |
39Monitor | CVE-2017-17878No exploit | An issue was discovered in Valve Steam Link build 643.valvesoftware · steam link firmware · CWE-327 | Critical9.8 | — | 1.6% | Dec 27, 2017 |
39Monitor | CVE-2023-35855No exploit | A buffer overflow in Counter-Strike through 8684 allows a game server to execute arbitrary code on a remote client's machine by modifying thvalvesoftware · counter-strike · CWE-120 | Critical9.8 | — | 1.1% | Jun 19, 2023 |
38Monitor | CVE-2019-15943Proof of concept | vphysics.dll in Counter-Strike: Global Offensive before 1.37.1.1 allows remote attackers to achieve code execution or denial of service by cvalvesoftware · counter-strike\ · CWE-787 | High8.8 | — | 8.7% | Sep 19, 2019 |
37Monitor | CVE-2021-30481Proof of concept | Valve Steam before 2021-04-17, when a Source engine game is installed, allows remote authenticated users to execute arbitrary code because ovalvesoftware · steam client · CWE-120 | Critical9.0 | — | 3.5% | Apr 10, 2021 |
32Monitor | CVE-2020-7949Proof of concept | schemasystem.dll in Valve Dota 2 before 7.23f allows remote attackers to achieve code execution or denial of service by creating a gaming sevalvesoftware · dota 2 | High7.8 | — | 4.2% | Jan 27, 2020 |
32Monitor | CVE-2020-9005No exploit | meshsystem.dll in Valve Dota 2 through 2020-02-17 allows remote attackers to achieve code execution or denial of service by creating a gaminvalvesoftware · dota 2 · CWE-787 | High7.8 | — | 2.2% | Feb 17, 2020 |
32Monitor | CVE-2020-7950No exploit | meshsystem.dll in Valve Dota 2 before 7.23f allows remote attackers to achieve code execution or denial of service by creating a gaming servvalvesoftware · dota 2 | High7.8 | — | 1.9% | Jan 27, 2020 |
32Monitor | CVE-2020-7951No exploit | meshsystem.dll in Valve Dota 2 before 7.23e allows remote attackers to achieve code execution or denial of service by creating a gaming servvalvesoftware · dota 2 · CWE-787 | High7.8 | — | 1.9% | Jan 27, 2020 |
32Monitor | CVE-2020-7952No exploit | rendersystemdx9.dll in Valve Dota 2 before 7.23f allows remote attackers to achieve code execution or denial of service by creating a gamingvalvesoftware · dota 2 | High7.8 | — | 1.9% | Jan 27, 2020 |
31Monitor | CVE-2020-6019No exploit | Valve's Game Networking Sockets prior to version v1.2.0 improperly handles inlined statistics messages in function CConnectionTransportUDPBavalvesoftware · game networking sockets · CWE-248 | High7.5 | — | 2.8% | Nov 13, 2020 |
31Monitor | CVE-2020-12242Proof of concept | Valve Source allows local users to gain privileges by writing to the /tmp/hl2_relaunch file, which is later executed in the context of a difvalvesoftware · source · CWE-78 | High7.8 | — | 1.1% | Apr 27, 2020 |
31Monitor | CVE-2019-17180No exploit | Valve Steam Client before 2019-09-12 allows placing or appending partially controlled filesystem content, as demonstrated by file modificativalvesoftware · steam client · CWE-22 | High7.8 | — | 0.7% | Oct 4, 2019 |
31Monitor | CVE-2020-15530No exploit | An issue was discovered in Valve Steam Client 2.10.91.91.valvesoftware · steam client · CWE-362 | High7.8 | — | 0.5% | Jul 4, 2020 |
31Monitor | CVE-2019-15315No exploit | Valve Steam Client for Windows through 2019-08-16 allows privilege escalation (to NT AUTHORITY\SYSTEM) because local users can replace the cvalvesoftware · steam client · CWE-732 | High7.8 | — | 0.4% | Aug 21, 2019 |
30Monitor | CVE-2023-38312No exploit | A directory traversal vulnerability in Valve Counter-Strike 8684 allows a client (with remote control access to a game server) to read arbitvalvesoftware · counter-strike · CWE-22 | High7.5 | — | 0.8% | Oct 15, 2023 |
29Monitor | CVE-2023-30382No exploit | A buffer overflow in the component hl.exe of Valve Half-Life up to 5433873 allows attackers to execute arbitrary code and escalate privilegevalvesoftware · half-life · CWE-787 | High7.3 | — | 0.2% | May 23, 2023 |
28Monitor | CVE-2015-7985Proof of concept | Valve Steam 2.10.91.91 uses weak permissions (Users: read and write) for the Install folder, which allows local users to gain privileges viavalvesoftware · steam client · CWE-276 | High7.2 | — | 1.0% | Nov 24, 2015 |
28Monitor | CVE-2019-15316No exploit | Valve Steam Client for Windows through 2019-08-20 has weak folder permissions, leading to privilege escalation (to NT AUTHORITY\SYSTEM) via valvesoftware · steam client · CWE-367 | High7.0 | — | 0.4% | Aug 21, 2019 |
26Monitor | CVE-2019-14743No exploit | In Valve Steam Client for Windows through 2019-08-07, HKLM\SOFTWARE\Wow6432Node\Valve\Steam has explicit "Full control" for the Users group,valvesoftware · steam client · CWE-732 | Medium6.6 | — | 0.6% | Aug 7, 2019 |
21Monitor | CVE-2015-4016No exploit | The client detection protocol in Valve Steam allows remote attackers to cause a denial of service (process crash) via a crafted response to valvesoftware · steam client · CWE-20 | Medium5.0 | — | 3.0% | May 20, 2015 |
21Monitor | CVE-2008-7203Proof of concept | Valve Software Half-Life Counter-Strike 1.6 allows remote attackers to cause a denial of service (crash) via multiple crafted login packets.valvesoftware · counter-strike · CWE-399 | Medium5.0 | — | 2.6% | Sep 11, 2009 |
- CVE-2020-601641Plan
Valve's Game Networking Sockets prior to version v1.2.0 improperly handles unreliable segments with negative offsets in function SNP_Receive
CriticalCVSS 9.8No exploitEPSS 6%valvesoftware · game networking socketsNov 18, 2020
- CVE-2017-1787740Plan
An issue was discovered in Valve Steam Link build 643.
CriticalCVSS 9.8No exploitEPSS 4%valvesoftware · steam link firmwareDec 27, 2017
- CVE-2020-601840Plan
Valve's Game Networking Sockets prior to version v1.2.0 improperly handles long encrypted messages in function AES_GCM_DecryptContext::Decry
CriticalCVSS 9.8No exploitEPSS 3%valvesoftware · game networking socketsDec 1, 2020
- CVE-2020-601740Plan
Valve's Game Networking Sockets prior to version v1.2.0 improperly handles long unreliable segments in function SNP_ReceiveUnreliableSegment
CriticalCVSS 9.8No exploitEPSS 3%valvesoftware · game networking socketsDec 3, 2020
- CVE-2017-1787839Monitor
An issue was discovered in Valve Steam Link build 643.
CriticalCVSS 9.8No exploitEPSS 2%valvesoftware · steam link firmwareDec 27, 2017
- CVE-2023-3585539Monitor
A buffer overflow in Counter-Strike through 8684 allows a game server to execute arbitrary code on a remote client's machine by modifying th
CriticalCVSS 9.8No exploitEPSS 1%valvesoftware · counter-strikeJun 19, 2023
- CVE-2019-1594338Monitor
vphysics.dll in Counter-Strike: Global Offensive before 1.37.1.1 allows remote attackers to achieve code execution or denial of service by c
HighCVSS 8.8Proof of conceptEPSS 9%valvesoftware · counter-strike\Sep 19, 2019
- CVE-2021-3048137Monitor
Valve Steam before 2021-04-17, when a Source engine game is installed, allows remote authenticated users to execute arbitrary code because o
CriticalCVSS 9.0Proof of conceptEPSS 4%valvesoftware · steam clientApr 10, 2021
- CVE-2020-794932Monitor
schemasystem.dll in Valve Dota 2 before 7.23f allows remote attackers to achieve code execution or denial of service by creating a gaming se
HighCVSS 7.8Proof of conceptEPSS 4%valvesoftware · dota 2Jan 27, 2020
- CVE-2020-900532Monitor
meshsystem.dll in Valve Dota 2 through 2020-02-17 allows remote attackers to achieve code execution or denial of service by creating a gamin
HighCVSS 7.8No exploitEPSS 2%valvesoftware · dota 2Feb 17, 2020
- CVE-2020-795032Monitor
meshsystem.dll in Valve Dota 2 before 7.23f allows remote attackers to achieve code execution or denial of service by creating a gaming serv
HighCVSS 7.8No exploitEPSS 2%valvesoftware · dota 2Jan 27, 2020
- CVE-2020-795132Monitor
meshsystem.dll in Valve Dota 2 before 7.23e allows remote attackers to achieve code execution or denial of service by creating a gaming serv
HighCVSS 7.8No exploitEPSS 2%valvesoftware · dota 2Jan 27, 2020
- CVE-2020-795232Monitor
rendersystemdx9.dll in Valve Dota 2 before 7.23f allows remote attackers to achieve code execution or denial of service by creating a gaming
HighCVSS 7.8No exploitEPSS 2%valvesoftware · dota 2Jan 27, 2020
- CVE-2020-601931Monitor
Valve's Game Networking Sockets prior to version v1.2.0 improperly handles inlined statistics messages in function CConnectionTransportUDPBa
HighCVSS 7.5No exploitEPSS 3%valvesoftware · game networking socketsNov 13, 2020
- CVE-2020-1224231Monitor
Valve Source allows local users to gain privileges by writing to the /tmp/hl2_relaunch file, which is later executed in the context of a dif
HighCVSS 7.8Proof of conceptEPSS 1%valvesoftware · sourceApr 27, 2020
- CVE-2019-1718031Monitor
Valve Steam Client before 2019-09-12 allows placing or appending partially controlled filesystem content, as demonstrated by file modificati
HighCVSS 7.8No exploitEPSS 1%valvesoftware · steam clientOct 4, 2019
- CVE-2020-1553031Monitor
An issue was discovered in Valve Steam Client 2.10.91.91.
HighCVSS 7.8No exploitEPSS 1%valvesoftware · steam clientJul 4, 2020
- CVE-2019-1531531Monitor
Valve Steam Client for Windows through 2019-08-16 allows privilege escalation (to NT AUTHORITY\SYSTEM) because local users can replace the c
HighCVSS 7.8No exploitEPSS 0%valvesoftware · steam clientAug 21, 2019
- CVE-2023-3831230Monitor
A directory traversal vulnerability in Valve Counter-Strike 8684 allows a client (with remote control access to a game server) to read arbit
HighCVSS 7.5No exploitEPSS 1%valvesoftware · counter-strikeOct 15, 2023
- CVE-2023-3038229Monitor
A buffer overflow in the component hl.exe of Valve Half-Life up to 5433873 allows attackers to execute arbitrary code and escalate privilege
HighCVSS 7.3No exploitEPSS 0%valvesoftware · half-lifeMay 23, 2023
- CVE-2015-798528Monitor
Valve Steam 2.10.91.91 uses weak permissions (Users: read and write) for the Install folder, which allows local users to gain privileges via
HighCVSS 7.2Proof of conceptEPSS 1%valvesoftware · steam clientNov 24, 2015
- CVE-2019-1531628Monitor
Valve Steam Client for Windows through 2019-08-20 has weak folder permissions, leading to privilege escalation (to NT AUTHORITY\SYSTEM) via
HighCVSS 7.0No exploitEPSS 0%valvesoftware · steam clientAug 21, 2019
- CVE-2019-1474326Monitor
In Valve Steam Client for Windows through 2019-08-07, HKLM\SOFTWARE\Wow6432Node\Valve\Steam has explicit "Full control" for the Users group,
MediumCVSS 6.6No exploitEPSS 1%valvesoftware · steam clientAug 7, 2019
- CVE-2015-401621Monitor
The client detection protocol in Valve Steam allows remote attackers to cause a denial of service (process crash) via a crafted response to
MediumCVSS 5.0No exploitEPSS 3%valvesoftware · steam clientMay 20, 2015
- CVE-2008-720321Monitor
Valve Software Half-Life Counter-Strike 1.6 allows remote attackers to cause a denial of service (crash) via multiple crafted login packets.
MediumCVSS 5.0Proof of conceptEPSS 3%valvesoftware · counter-strikeSep 11, 2009