id software kayıtları
id software üreticisine ait 27 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 6
- Düzeltme kaydı olan
- %18,5
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Yıllara göre kayıt
Çubuk: toplam · koyu kısım: CISA KEV.
Tekrar eden sınıflar
- CWE-20 Improper Input Validation2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-134 Use of Externally-Controlled Format String1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
27 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2007-5248Kavram kanıtı | Multiple format string vulnerabilities in the ID Software Doom 3 engine, as used by Doom 3 1.3.1 and earlier, Quake 4 1.4.2 and earlier, andid software · doom 3 · CWE-134 | Kritik9,3 | — | %7,5 | 6 Eki 2007 |
32İzleyin | CVE-2006-2236Kavram kanıtı | Buffer overflow in the Quake 3 Engine, as used by (1) ET 2.60, (2) Return to Castle Wolfenstein 1.41, and (3) Quake III Arena 1.32b allows rid software · quake 3 arena | Yüksek7,6 | — | %7,6 | 8 May 2006 |
32İzleyin | CVE-2006-2875Kavram kanıtı | Stack-based buffer overflow in the CL_ParseDownload function of Quake 3 Engine 1.32c and earlier, as used in multiple products, allows remotid software · quake 3 engine | Yüksek7,5 | — | %6,8 | 6 Haz 2006 |
32İzleyin | CVE-2006-3401Kavram kanıtı | Stack-based buffer overflow in Quake 3 Engine as used by Quake 3: Arena 1.32b and 1.32c allows remote attackers to cause a denial of serviceid software · quake 3 engine · CWE-119 | Yüksek7,5 | — | %5,7 | 6 Tem 2006 |
31İzleyin | CVE-2006-3400Kavram kanıtı | Stack-based buffer overflow in the CG_ServerCommand function in Quake 3 Engine as used by Soldier of Fortune 2 (SOF2MP) GOLD 1.03 allows remid software · quake 3 engine | Yüksek7,5 | — | %4,8 | 6 Tem 2006 |
31İzleyin | CVE-2004-2593İstismar yok | Buffer overflow in command-packet processing of Quake II server before R1Q2, as used in multiple products, allows remote attackers to cause id software · quake ii server | Yüksek7,5 | — | %3,8 | 31 Ara 2004 |
31İzleyin | CVE-2006-2082İstismar yok | Directory traversal vulnerability in Quake 3 engine, as used in products including Quake3 Arena, Return to Castle Wolfenstein, Wolfenstein: id software · quake 3 engine | Yüksek7,5 | — | %2,6 | 9 May 2006 |
31İzleyin | CVE-1999-1505İstismar yok | Buffer overflow in QuakeWorld 2.10 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary commands via id software · quakeworld | Yüksek7,5 | — | %2,0 | 7 Nis 1998 |
31İzleyin | CVE-1999-1502İstismar yok | Buffer overflows in Quake 1.9 client allows remote malicious servers to execute arbitrary commands via long (1) precache paths, (2) server nid software · quake | Yüksek7,5 | — | %1,9 | 8 Nis 1998 |
25İzleyin | CVE-2000-0303İstismar yok | Quake3 Arena allows malicious server operators to read or modify files on a client via a dot dot (..) attack.id software · quake 3 arena | Orta6,4 | — | %1,3 | 3 May 2000 |
22İzleyin | CVE-2005-0430Kavram kanıtı | The Quake 3 engine, as used in multiple game packages, allows remote attackers to cause a denial of service (shutdown game server) and possiid software · quake 3 engine | Orta5,0 | — | %7,5 | 12 Şub 2005 |
22İzleyin | CVE-2002-0770Kavram kanıtı | Quake 2 (Q2) server 3.20 and 3.21 allows remote attackers to obtain sensitive server cvar variables, obtain directory listings, and execute id software · quake 2i server | Orta5,0 | — | %5,5 | 12 Ağu 2002 |
22İzleyin | CVE-2001-1289Kavram kanıtı | Quake 3 arena 1.29f and 1.29g allows remote attackers to cause a denial of service (crash) via a malformed connection packet that begins witid software · quake 3 arena | Orta5,0 | — | %5,2 | 29 Tem 2001 |
21İzleyin | CVE-2006-3325Kavram kanıtı | client/cl_parse.c in the id3 Quake 3 Engine 1.32c and the Icculus Quake 3 Engine (ioquake3) revision 810 and earlier allows remote maliciousid software · quake 3 engine | Orta5,0 | — | %4,8 | 30 Haz 2006 |
21İzleyin | CVE-2006-3324Kavram kanıtı | The Automatic Downloading option in the id3 Quake 3 Engine and the Icculus Quake 3 Engine (ioquake3) before revision 804 allows remote attacid software · quake 3 engine | Orta5,0 | — | %4,4 | 30 Haz 2006 |
21İzleyin | CVE-2004-2592Kavram kanıtı | Quake II server before R1Q2, as used in multiple products, allows remote attackers to cause a denial of service (application crash) via a moid software · quake ii server · CWE-20 | Orta5,0 | — | %3,7 | 31 Ara 2004 |
21İzleyin | CVE-1999-1569Kavram kanıtı | Quake 1 and NetQuake servers allow remote attackers to cause a denial of service (resource exhaustion or forced disconnection) via a flood oid software · quake | Orta5,0 | — | %3,2 | 17 Tem 2001 |
21İzleyin | CVE-2004-2595İstismar yok | Absolute path traversal vulnerability in Quake II server before R1Q2 on Linux, as used in multiple products, allows remote attackers to causid software · quake ii server linux | Orta5,0 | — | %2,8 | 31 Ara 2004 |
21İzleyin | CVE-2005-0983İstismar yok | Quake 3 engine, as used in multiple games, allows remote attackers to cause a denial of service (client disconnect) via a long message, whicactivision · call of duty | Orta5,0 | — | %2,6 | 2 May 2005 |
21İzleyin | CVE-2004-2596İstismar yok | Quake II server before R1Q2, as used in multiple products, allows remote attackers to cause a denial of service (exhaustion of connection slid software · quake ii server · CWE-20 | Orta5,0 | — | %1,9 | 31 Ara 2004 |
21İzleyin | CVE-2004-2594İstismar yok | Absolute path traversal vulnerability in Quake II server before R1Q2 on Windows, as used in multiple products, allows remote attackers to reid software · quake ii server windows | Orta5,0 | — | %1,8 | 31 Ara 2004 |
21İzleyin | CVE-2000-1080İstismar yok | Quake 1 (quake1) and ProQuake 1.01 and earlier allow remote attackers to cause a denial of service via a malformed (empty) UDP packet.id software · quake | Orta5,0 | — | %1,7 | 1 Kas 2000 |
20İzleyin | CVE-2004-2597İstismar yok | Quake II server before R1Q2, as used in multiple products, allows remote attackers to bypass IP-based access control rules via a userinfo stid software · quake ii server | Orta5,0 | — | %1,6 | 31 Ara 2004 |
20İzleyin | CVE-2004-2598İstismar yok | Quake II server before R1Q2, as used in multiple products, allows remote attackers to corrupt the server's client state data structure by exid software · quake ii server | Orta5,0 | — | %1,4 | 31 Ara 2004 |
20İzleyin | CVE-1999-1230İstismar yok | Quake 2 server allows remote attackers to cause a denial of service via a spoofed UDP packet with a source address of 127.0.0.1, which causeid software · quake 2 | Orta5,0 | — | %1,3 | 24 Ara 1997 |
- CVE-2007-524839İzleyin
Multiple format string vulnerabilities in the ID Software Doom 3 engine, as used by Doom 3 1.3.1 and earlier, Quake 4 1.4.2 and earlier, and
KritikCVSS 9,3Kavram kanıtıEPSS %7id software · doom 36 Eki 2007
- CVE-2006-223632İzleyin
Buffer overflow in the Quake 3 Engine, as used by (1) ET 2.60, (2) Return to Castle Wolfenstein 1.41, and (3) Quake III Arena 1.32b allows r
YüksekCVSS 7,6Kavram kanıtıEPSS %8id software · quake 3 arena8 May 2006
- CVE-2006-287532İzleyin
Stack-based buffer overflow in the CL_ParseDownload function of Quake 3 Engine 1.32c and earlier, as used in multiple products, allows remot
YüksekCVSS 7,5Kavram kanıtıEPSS %7id software · quake 3 engine6 Haz 2006
- CVE-2006-340132İzleyin
Stack-based buffer overflow in Quake 3 Engine as used by Quake 3: Arena 1.32b and 1.32c allows remote attackers to cause a denial of service
YüksekCVSS 7,5Kavram kanıtıEPSS %6id software · quake 3 engine6 Tem 2006
- CVE-2006-340031İzleyin
Stack-based buffer overflow in the CG_ServerCommand function in Quake 3 Engine as used by Soldier of Fortune 2 (SOF2MP) GOLD 1.03 allows rem
YüksekCVSS 7,5Kavram kanıtıEPSS %5id software · quake 3 engine6 Tem 2006
- CVE-2004-259331İzleyin
Buffer overflow in command-packet processing of Quake II server before R1Q2, as used in multiple products, allows remote attackers to cause
YüksekCVSS 7,5İstismar yokEPSS %4id software · quake ii server31 Ara 2004
- CVE-2006-208231İzleyin
Directory traversal vulnerability in Quake 3 engine, as used in products including Quake3 Arena, Return to Castle Wolfenstein, Wolfenstein:
YüksekCVSS 7,5İstismar yokEPSS %3id software · quake 3 engine9 May 2006
- CVE-1999-150531İzleyin
Buffer overflow in QuakeWorld 2.10 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary commands via
YüksekCVSS 7,5İstismar yokEPSS %2id software · quakeworld7 Nis 1998
- CVE-1999-150231İzleyin
Buffer overflows in Quake 1.9 client allows remote malicious servers to execute arbitrary commands via long (1) precache paths, (2) server n
YüksekCVSS 7,5İstismar yokEPSS %2id software · quake8 Nis 1998
- CVE-2000-030325İzleyin
Quake3 Arena allows malicious server operators to read or modify files on a client via a dot dot (..) attack.
OrtaCVSS 6,4İstismar yokEPSS %1id software · quake 3 arena3 May 2000
- CVE-2005-043022İzleyin
The Quake 3 engine, as used in multiple game packages, allows remote attackers to cause a denial of service (shutdown game server) and possi
OrtaCVSS 5,0Kavram kanıtıEPSS %8id software · quake 3 engine12 Şub 2005
- CVE-2002-077022İzleyin
Quake 2 (Q2) server 3.20 and 3.21 allows remote attackers to obtain sensitive server cvar variables, obtain directory listings, and execute
OrtaCVSS 5,0Kavram kanıtıEPSS %6id software · quake 2i server12 Ağu 2002
- CVE-2001-128922İzleyin
Quake 3 arena 1.29f and 1.29g allows remote attackers to cause a denial of service (crash) via a malformed connection packet that begins wit
OrtaCVSS 5,0Kavram kanıtıEPSS %5id software · quake 3 arena29 Tem 2001
- CVE-2006-332521İzleyin
client/cl_parse.c in the id3 Quake 3 Engine 1.32c and the Icculus Quake 3 Engine (ioquake3) revision 810 and earlier allows remote malicious
OrtaCVSS 5,0Kavram kanıtıEPSS %5id software · quake 3 engine30 Haz 2006
- CVE-2006-332421İzleyin
The Automatic Downloading option in the id3 Quake 3 Engine and the Icculus Quake 3 Engine (ioquake3) before revision 804 allows remote attac
OrtaCVSS 5,0Kavram kanıtıEPSS %4id software · quake 3 engine30 Haz 2006
- CVE-2004-259221İzleyin
Quake II server before R1Q2, as used in multiple products, allows remote attackers to cause a denial of service (application crash) via a mo
OrtaCVSS 5,0Kavram kanıtıEPSS %4id software · quake ii server31 Ara 2004
- CVE-1999-156921İzleyin
Quake 1 and NetQuake servers allow remote attackers to cause a denial of service (resource exhaustion or forced disconnection) via a flood o
OrtaCVSS 5,0Kavram kanıtıEPSS %3id software · quake17 Tem 2001
- CVE-2004-259521İzleyin
Absolute path traversal vulnerability in Quake II server before R1Q2 on Linux, as used in multiple products, allows remote attackers to caus
OrtaCVSS 5,0İstismar yokEPSS %3id software · quake ii server linux31 Ara 2004
- CVE-2005-098321İzleyin
Quake 3 engine, as used in multiple games, allows remote attackers to cause a denial of service (client disconnect) via a long message, whic
OrtaCVSS 5,0İstismar yokEPSS %3activision · call of duty2 May 2005
- CVE-2004-259621İzleyin
Quake II server before R1Q2, as used in multiple products, allows remote attackers to cause a denial of service (exhaustion of connection sl
OrtaCVSS 5,0İstismar yokEPSS %2id software · quake ii server31 Ara 2004
- CVE-2004-259421İzleyin
Absolute path traversal vulnerability in Quake II server before R1Q2 on Windows, as used in multiple products, allows remote attackers to re
OrtaCVSS 5,0İstismar yokEPSS %2id software · quake ii server windows31 Ara 2004
- CVE-2000-108021İzleyin
Quake 1 (quake1) and ProQuake 1.01 and earlier allow remote attackers to cause a denial of service via a malformed (empty) UDP packet.
OrtaCVSS 5,0İstismar yokEPSS %2id software · quake1 Kas 2000
- CVE-2004-259720İzleyin
Quake II server before R1Q2, as used in multiple products, allows remote attackers to bypass IP-based access control rules via a userinfo st
OrtaCVSS 5,0İstismar yokEPSS %2id software · quake ii server31 Ara 2004
- CVE-2004-259820İzleyin
Quake II server before R1Q2, as used in multiple products, allows remote attackers to corrupt the server's client state data structure by ex
OrtaCVSS 5,0İstismar yokEPSS %1id software · quake ii server31 Ara 2004
- CVE-1999-123020İzleyin
Quake 2 server allows remote attackers to cause a denial of service via a spoofed UDP packet with a source address of 127.0.0.1, which cause
OrtaCVSS 5,0İstismar yokEPSS %1id software · quake 224 Ara 1997