Перейти к содержимому
Noroxi

Записи valvesoftware

29 опубликованных записей вендора valvesoftware.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
4
С записью об исправлении
3,4 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Охват bug bounty

Вендор продукта присутствует в публичной программе. Сопоставление по имени; проверьте текст scope в программе.

Все записи

29 записей
  • CVE-2020-6016
    41В плане

    Valve's Game Networking Sockets prior to version v1.2.0 improperly handles unreliable segments with negative offsets in function SNP_Receive

    КритическаяCVSS 9,8Эксплойта нетEPSS 6 %

    valvesoftware · game networking sockets18 нояб. 2020 г.

  • CVE-2017-17877
    40В плане

    An issue was discovered in Valve Steam Link build 643.

    КритическаяCVSS 9,8Эксплойта нетEPSS 4 %

    valvesoftware · steam link firmware27 дек. 2017 г.

  • CVE-2020-6018
    40В плане

    Valve's Game Networking Sockets prior to version v1.2.0 improperly handles long encrypted messages in function AES_GCM_DecryptContext::Decry

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    valvesoftware · game networking sockets1 дек. 2020 г.

  • CVE-2020-6017
    40В плане

    Valve's Game Networking Sockets prior to version v1.2.0 improperly handles long unreliable segments in function SNP_ReceiveUnreliableSegment

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    valvesoftware · game networking sockets3 дек. 2020 г.

  • CVE-2017-17878
    39Наблюдать

    An issue was discovered in Valve Steam Link build 643.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    valvesoftware · steam link firmware27 дек. 2017 г.

  • CVE-2023-35855
    39Наблюдать

    A buffer overflow in Counter-Strike through 8684 allows a game server to execute arbitrary code on a remote client's machine by modifying th

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    valvesoftware · counter-strike19 июн. 2023 г.

  • CVE-2019-15943
    38Наблюдать

    vphysics.dll in Counter-Strike: Global Offensive before 1.37.1.1 allows remote attackers to achieve code execution or denial of service by c

    ВысокаяCVSS 8,8Proof of conceptEPSS 9 %

    valvesoftware · counter-strike\19 сент. 2019 г.

  • CVE-2021-30481
    37Наблюдать

    Valve Steam before 2021-04-17, when a Source engine game is installed, allows remote authenticated users to execute arbitrary code because o

    КритическаяCVSS 9,0Proof of conceptEPSS 4 %

    valvesoftware · steam client10 апр. 2021 г.

  • CVE-2020-7949
    32Наблюдать

    schemasystem.dll in Valve Dota 2 before 7.23f allows remote attackers to achieve code execution or denial of service by creating a gaming se

    ВысокаяCVSS 7,8Proof of conceptEPSS 4 %

    valvesoftware · dota 227 янв. 2020 г.

  • CVE-2020-9005
    32Наблюдать

    meshsystem.dll in Valve Dota 2 through 2020-02-17 allows remote attackers to achieve code execution or denial of service by creating a gamin

    ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %

    valvesoftware · dota 217 февр. 2020 г.

  • CVE-2020-7950
    32Наблюдать

    meshsystem.dll in Valve Dota 2 before 7.23f allows remote attackers to achieve code execution or denial of service by creating a gaming serv

    ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %

    valvesoftware · dota 227 янв. 2020 г.

  • CVE-2020-7951
    32Наблюдать

    meshsystem.dll in Valve Dota 2 before 7.23e allows remote attackers to achieve code execution or denial of service by creating a gaming serv

    ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %

    valvesoftware · dota 227 янв. 2020 г.

  • CVE-2020-7952
    32Наблюдать

    rendersystemdx9.dll in Valve Dota 2 before 7.23f allows remote attackers to achieve code execution or denial of service by creating a gaming

    ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %

    valvesoftware · dota 227 янв. 2020 г.

  • CVE-2020-6019
    31Наблюдать

    Valve's Game Networking Sockets prior to version v1.2.0 improperly handles inlined statistics messages in function CConnectionTransportUDPBa

    ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %

    valvesoftware · game networking sockets13 нояб. 2020 г.

  • CVE-2020-12242
    31Наблюдать

    Valve Source allows local users to gain privileges by writing to the /tmp/hl2_relaunch file, which is later executed in the context of a dif

    ВысокаяCVSS 7,8Proof of conceptEPSS 1 %

    valvesoftware · source27 апр. 2020 г.

  • CVE-2019-17180
    31Наблюдать

    Valve Steam Client before 2019-09-12 allows placing or appending partially controlled filesystem content, as demonstrated by file modificati

    ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %

    valvesoftware · steam client4 окт. 2019 г.

  • CVE-2020-15530
    31Наблюдать

    An issue was discovered in Valve Steam Client 2.10.91.91.

    ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %

    valvesoftware · steam client4 июл. 2020 г.

  • CVE-2019-15315
    31Наблюдать

    Valve Steam Client for Windows through 2019-08-16 allows privilege escalation (to NT AUTHORITY\SYSTEM) because local users can replace the c

    ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %

    valvesoftware · steam client21 авг. 2019 г.

  • CVE-2023-38312
    30Наблюдать

    A directory traversal vulnerability in Valve Counter-Strike 8684 allows a client (with remote control access to a game server) to read arbit

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    valvesoftware · counter-strike15 окт. 2023 г.

  • CVE-2023-30382
    29Наблюдать

    A buffer overflow in the component hl.exe of Valve Half-Life up to 5433873 allows attackers to execute arbitrary code and escalate privilege

    ВысокаяCVSS 7,3Эксплойта нетEPSS 0 %

    valvesoftware · half-life23 мая 2023 г.

  • CVE-2015-7985
    28Наблюдать

    Valve Steam 2.10.91.91 uses weak permissions (Users: read and write) for the Install folder, which allows local users to gain privileges via

    ВысокаяCVSS 7,2Proof of conceptEPSS 1 %

    valvesoftware · steam client24 нояб. 2015 г.

  • CVE-2019-15316
    28Наблюдать

    Valve Steam Client for Windows through 2019-08-20 has weak folder permissions, leading to privilege escalation (to NT AUTHORITY\SYSTEM) via

    ВысокаяCVSS 7,0Эксплойта нетEPSS 0 %

    valvesoftware · steam client21 авг. 2019 г.

  • CVE-2019-14743
    26Наблюдать

    In Valve Steam Client for Windows through 2019-08-07, HKLM\SOFTWARE\Wow6432Node\Valve\Steam has explicit "Full control" for the Users group,

    СредняяCVSS 6,6Эксплойта нетEPSS 1 %

    valvesoftware · steam client7 авг. 2019 г.

  • CVE-2015-4016
    21Наблюдать

    The client detection protocol in Valve Steam allows remote attackers to cause a denial of service (process crash) via a crafted response to

    СредняяCVSS 5,0Эксплойта нетEPSS 3 %

    valvesoftware · steam client20 мая 2015 г.

  • CVE-2008-7203
    21Наблюдать

    Valve Software Half-Life Counter-Strike 1.6 allows remote attackers to cause a denial of service (crash) via multiple crafted login packets.

    СредняяCVSS 5,0Proof of conceptEPSS 3 %

    valvesoftware · counter-strike11 сент. 2009 г.