Записи id software
27 опубликованных записей вендора id software.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 6
- С записью об исправлении
- 18,5 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
- CWE-20 Improper Input Validation2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-134 Use of Externally-Controlled Format String1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
27 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2007-5248Proof of concept | Multiple format string vulnerabilities in the ID Software Doom 3 engine, as used by Doom 3 1.3.1 and earlier, Quake 4 1.4.2 and earlier, andid software · doom 3 · CWE-134 | Критическая9,3 | — | 7,5 % | 6 окт. 2007 г. |
32Наблюдать | CVE-2006-2236Proof of concept | Buffer overflow in the Quake 3 Engine, as used by (1) ET 2.60, (2) Return to Castle Wolfenstein 1.41, and (3) Quake III Arena 1.32b allows rid software · quake 3 arena | Высокая7,6 | — | 7,6 % | 8 мая 2006 г. |
32Наблюдать | CVE-2006-2875Proof of concept | Stack-based buffer overflow in the CL_ParseDownload function of Quake 3 Engine 1.32c and earlier, as used in multiple products, allows remotid software · quake 3 engine | Высокая7,5 | — | 6,8 % | 6 июн. 2006 г. |
32Наблюдать | CVE-2006-3401Proof of concept | Stack-based buffer overflow in Quake 3 Engine as used by Quake 3: Arena 1.32b and 1.32c allows remote attackers to cause a denial of serviceid software · quake 3 engine · CWE-119 | Высокая7,5 | — | 5,7 % | 6 июл. 2006 г. |
31Наблюдать | CVE-2006-3400Proof of concept | Stack-based buffer overflow in the CG_ServerCommand function in Quake 3 Engine as used by Soldier of Fortune 2 (SOF2MP) GOLD 1.03 allows remid software · quake 3 engine | Высокая7,5 | — | 4,8 % | 6 июл. 2006 г. |
31Наблюдать | CVE-2004-2593Эксплойта нет | Buffer overflow in command-packet processing of Quake II server before R1Q2, as used in multiple products, allows remote attackers to cause id software · quake ii server | Высокая7,5 | — | 3,8 % | 31 дек. 2004 г. |
31Наблюдать | CVE-2006-2082Эксплойта нет | Directory traversal vulnerability in Quake 3 engine, as used in products including Quake3 Arena, Return to Castle Wolfenstein, Wolfenstein: id software · quake 3 engine | Высокая7,5 | — | 2,6 % | 9 мая 2006 г. |
31Наблюдать | CVE-1999-1505Эксплойта нет | Buffer overflow in QuakeWorld 2.10 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary commands via id software · quakeworld | Высокая7,5 | — | 2,0 % | 7 апр. 1998 г. |
31Наблюдать | CVE-1999-1502Эксплойта нет | Buffer overflows in Quake 1.9 client allows remote malicious servers to execute arbitrary commands via long (1) precache paths, (2) server nid software · quake | Высокая7,5 | — | 1,9 % | 8 апр. 1998 г. |
25Наблюдать | CVE-2000-0303Эксплойта нет | Quake3 Arena allows malicious server operators to read or modify files on a client via a dot dot (..) attack.id software · quake 3 arena | Средняя6,4 | — | 1,3 % | 3 мая 2000 г. |
22Наблюдать | CVE-2005-0430Proof of concept | The Quake 3 engine, as used in multiple game packages, allows remote attackers to cause a denial of service (shutdown game server) and possiid software · quake 3 engine | Средняя5,0 | — | 7,5 % | 12 февр. 2005 г. |
22Наблюдать | CVE-2002-0770Proof of concept | Quake 2 (Q2) server 3.20 and 3.21 allows remote attackers to obtain sensitive server cvar variables, obtain directory listings, and execute id software · quake 2i server | Средняя5,0 | — | 5,5 % | 12 авг. 2002 г. |
22Наблюдать | CVE-2001-1289Proof of concept | Quake 3 arena 1.29f and 1.29g allows remote attackers to cause a denial of service (crash) via a malformed connection packet that begins witid software · quake 3 arena | Средняя5,0 | — | 5,2 % | 29 июл. 2001 г. |
21Наблюдать | CVE-2006-3325Proof of concept | client/cl_parse.c in the id3 Quake 3 Engine 1.32c and the Icculus Quake 3 Engine (ioquake3) revision 810 and earlier allows remote maliciousid software · quake 3 engine | Средняя5,0 | — | 4,8 % | 30 июн. 2006 г. |
21Наблюдать | CVE-2006-3324Proof of concept | The Automatic Downloading option in the id3 Quake 3 Engine and the Icculus Quake 3 Engine (ioquake3) before revision 804 allows remote attacid software · quake 3 engine | Средняя5,0 | — | 4,4 % | 30 июн. 2006 г. |
21Наблюдать | CVE-2004-2592Proof of concept | Quake II server before R1Q2, as used in multiple products, allows remote attackers to cause a denial of service (application crash) via a moid software · quake ii server · CWE-20 | Средняя5,0 | — | 3,7 % | 31 дек. 2004 г. |
21Наблюдать | CVE-1999-1569Proof of concept | Quake 1 and NetQuake servers allow remote attackers to cause a denial of service (resource exhaustion or forced disconnection) via a flood oid software · quake | Средняя5,0 | — | 3,2 % | 17 июл. 2001 г. |
21Наблюдать | CVE-2004-2595Эксплойта нет | Absolute path traversal vulnerability in Quake II server before R1Q2 on Linux, as used in multiple products, allows remote attackers to causid software · quake ii server linux | Средняя5,0 | — | 2,8 % | 31 дек. 2004 г. |
21Наблюдать | CVE-2005-0983Эксплойта нет | Quake 3 engine, as used in multiple games, allows remote attackers to cause a denial of service (client disconnect) via a long message, whicactivision · call of duty | Средняя5,0 | — | 2,6 % | 2 мая 2005 г. |
21Наблюдать | CVE-2004-2596Эксплойта нет | Quake II server before R1Q2, as used in multiple products, allows remote attackers to cause a denial of service (exhaustion of connection slid software · quake ii server · CWE-20 | Средняя5,0 | — | 1,9 % | 31 дек. 2004 г. |
21Наблюдать | CVE-2004-2594Эксплойта нет | Absolute path traversal vulnerability in Quake II server before R1Q2 on Windows, as used in multiple products, allows remote attackers to reid software · quake ii server windows | Средняя5,0 | — | 1,8 % | 31 дек. 2004 г. |
21Наблюдать | CVE-2000-1080Эксплойта нет | Quake 1 (quake1) and ProQuake 1.01 and earlier allow remote attackers to cause a denial of service via a malformed (empty) UDP packet.id software · quake | Средняя5,0 | — | 1,7 % | 1 нояб. 2000 г. |
20Наблюдать | CVE-2004-2597Эксплойта нет | Quake II server before R1Q2, as used in multiple products, allows remote attackers to bypass IP-based access control rules via a userinfo stid software · quake ii server | Средняя5,0 | — | 1,6 % | 31 дек. 2004 г. |
20Наблюдать | CVE-2004-2598Эксплойта нет | Quake II server before R1Q2, as used in multiple products, allows remote attackers to corrupt the server's client state data structure by exid software · quake ii server | Средняя5,0 | — | 1,4 % | 31 дек. 2004 г. |
20Наблюдать | CVE-1999-1230Эксплойта нет | Quake 2 server allows remote attackers to cause a denial of service via a spoofed UDP packet with a source address of 127.0.0.1, which causeid software · quake 2 | Средняя5,0 | — | 1,3 % | 24 дек. 1997 г. |
- CVE-2007-524839Наблюдать
Multiple format string vulnerabilities in the ID Software Doom 3 engine, as used by Doom 3 1.3.1 and earlier, Quake 4 1.4.2 and earlier, and
КритическаяCVSS 9,3Proof of conceptEPSS 7 %id software · doom 36 окт. 2007 г.
- CVE-2006-223632Наблюдать
Buffer overflow in the Quake 3 Engine, as used by (1) ET 2.60, (2) Return to Castle Wolfenstein 1.41, and (3) Quake III Arena 1.32b allows r
ВысокаяCVSS 7,6Proof of conceptEPSS 8 %id software · quake 3 arena8 мая 2006 г.
- CVE-2006-287532Наблюдать
Stack-based buffer overflow in the CL_ParseDownload function of Quake 3 Engine 1.32c and earlier, as used in multiple products, allows remot
ВысокаяCVSS 7,5Proof of conceptEPSS 7 %id software · quake 3 engine6 июн. 2006 г.
- CVE-2006-340132Наблюдать
Stack-based buffer overflow in Quake 3 Engine as used by Quake 3: Arena 1.32b and 1.32c allows remote attackers to cause a denial of service
ВысокаяCVSS 7,5Proof of conceptEPSS 6 %id software · quake 3 engine6 июл. 2006 г.
- CVE-2006-340031Наблюдать
Stack-based buffer overflow in the CG_ServerCommand function in Quake 3 Engine as used by Soldier of Fortune 2 (SOF2MP) GOLD 1.03 allows rem
ВысокаяCVSS 7,5Proof of conceptEPSS 5 %id software · quake 3 engine6 июл. 2006 г.
- CVE-2004-259331Наблюдать
Buffer overflow in command-packet processing of Quake II server before R1Q2, as used in multiple products, allows remote attackers to cause
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %id software · quake ii server31 дек. 2004 г.
- CVE-2006-208231Наблюдать
Directory traversal vulnerability in Quake 3 engine, as used in products including Quake3 Arena, Return to Castle Wolfenstein, Wolfenstein:
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %id software · quake 3 engine9 мая 2006 г.
- CVE-1999-150531Наблюдать
Buffer overflow in QuakeWorld 2.10 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary commands via
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %id software · quakeworld7 апр. 1998 г.
- CVE-1999-150231Наблюдать
Buffer overflows in Quake 1.9 client allows remote malicious servers to execute arbitrary commands via long (1) precache paths, (2) server n
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %id software · quake8 апр. 1998 г.
- CVE-2000-030325Наблюдать
Quake3 Arena allows malicious server operators to read or modify files on a client via a dot dot (..) attack.
СредняяCVSS 6,4Эксплойта нетEPSS 1 %id software · quake 3 arena3 мая 2000 г.
- CVE-2005-043022Наблюдать
The Quake 3 engine, as used in multiple game packages, allows remote attackers to cause a denial of service (shutdown game server) and possi
СредняяCVSS 5,0Proof of conceptEPSS 8 %id software · quake 3 engine12 февр. 2005 г.
- CVE-2002-077022Наблюдать
Quake 2 (Q2) server 3.20 and 3.21 allows remote attackers to obtain sensitive server cvar variables, obtain directory listings, and execute
СредняяCVSS 5,0Proof of conceptEPSS 6 %id software · quake 2i server12 авг. 2002 г.
- CVE-2001-128922Наблюдать
Quake 3 arena 1.29f and 1.29g allows remote attackers to cause a denial of service (crash) via a malformed connection packet that begins wit
СредняяCVSS 5,0Proof of conceptEPSS 5 %id software · quake 3 arena29 июл. 2001 г.
- CVE-2006-332521Наблюдать
client/cl_parse.c in the id3 Quake 3 Engine 1.32c and the Icculus Quake 3 Engine (ioquake3) revision 810 and earlier allows remote malicious
СредняяCVSS 5,0Proof of conceptEPSS 5 %id software · quake 3 engine30 июн. 2006 г.
- CVE-2006-332421Наблюдать
The Automatic Downloading option in the id3 Quake 3 Engine and the Icculus Quake 3 Engine (ioquake3) before revision 804 allows remote attac
СредняяCVSS 5,0Proof of conceptEPSS 4 %id software · quake 3 engine30 июн. 2006 г.
- CVE-2004-259221Наблюдать
Quake II server before R1Q2, as used in multiple products, allows remote attackers to cause a denial of service (application crash) via a mo
СредняяCVSS 5,0Proof of conceptEPSS 4 %id software · quake ii server31 дек. 2004 г.
- CVE-1999-156921Наблюдать
Quake 1 and NetQuake servers allow remote attackers to cause a denial of service (resource exhaustion or forced disconnection) via a flood o
СредняяCVSS 5,0Proof of conceptEPSS 3 %id software · quake17 июл. 2001 г.
- CVE-2004-259521Наблюдать
Absolute path traversal vulnerability in Quake II server before R1Q2 on Linux, as used in multiple products, allows remote attackers to caus
СредняяCVSS 5,0Эксплойта нетEPSS 3 %id software · quake ii server linux31 дек. 2004 г.
- CVE-2005-098321Наблюдать
Quake 3 engine, as used in multiple games, allows remote attackers to cause a denial of service (client disconnect) via a long message, whic
СредняяCVSS 5,0Эксплойта нетEPSS 3 %activision · call of duty2 мая 2005 г.
- CVE-2004-259621Наблюдать
Quake II server before R1Q2, as used in multiple products, allows remote attackers to cause a denial of service (exhaustion of connection sl
СредняяCVSS 5,0Эксплойта нетEPSS 2 %id software · quake ii server31 дек. 2004 г.
- CVE-2004-259421Наблюдать
Absolute path traversal vulnerability in Quake II server before R1Q2 on Windows, as used in multiple products, allows remote attackers to re
СредняяCVSS 5,0Эксплойта нетEPSS 2 %id software · quake ii server windows31 дек. 2004 г.
- CVE-2000-108021Наблюдать
Quake 1 (quake1) and ProQuake 1.01 and earlier allow remote attackers to cause a denial of service via a malformed (empty) UDP packet.
СредняяCVSS 5,0Эксплойта нетEPSS 2 %id software · quake1 нояб. 2000 г.
- CVE-2004-259720Наблюдать
Quake II server before R1Q2, as used in multiple products, allows remote attackers to bypass IP-based access control rules via a userinfo st
СредняяCVSS 5,0Эксплойта нетEPSS 2 %id software · quake ii server31 дек. 2004 г.
- CVE-2004-259820Наблюдать
Quake II server before R1Q2, as used in multiple products, allows remote attackers to corrupt the server's client state data structure by ex
СредняяCVSS 5,0Эксплойта нетEPSS 1 %id software · quake ii server31 дек. 2004 г.
- CVE-1999-123020Наблюдать
Quake 2 server allows remote attackers to cause a denial of service via a spoofed UDP packet with a source address of 127.0.0.1, which cause
СредняяCVSS 5,0Эксплойта нетEPSS 1 %id software · quake 224 дек. 1997 г.