ioquake3 kayıtları
ioquake3 üreticisine ait 7 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 3
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-20 Improper Input Validation4
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-59 Improper Link Resolution Before File Access ('Link Following')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
7 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
43Planlayın | CVE-2011-2764İstismar yok | The FS_CheckFilenameIsNotExecutable function in qcommon/files.c in the ioQuake3 engine 1.36 and earlier, as used in World of Padman, Smokin'ioquake3 · ioquake3 engine · CWE-20 | Kritik10,0 | — | %8,7 | 3 Ağu 2011 |
42Planlayın | CVE-2011-3012İstismar yok | The ioQuake3 engine, as used in World of Padman 1.2 and earlier, Tremulous 1.1.0, and ioUrbanTerror 2007-12-20, does not check for dangerousioquake3 · ioquake3 engine · CWE-20 | Kritik10,0 | — | %8,0 | 9 Ağu 2011 |
40Planlayın | CVE-2017-11721İstismar yok | Buffer overflow in ioquake3 before 2017-08-02 allows remote attackers to cause a denial of service (application crash) or possibly have unspioquake3 · ioquake3 · CWE-119 | Kritik9,8 | — | %2,5 | 3 Ağu 2017 |
32İzleyin | CVE-2010-5077İstismar yok | server/sv_main.c in Quake3 Arena, as used in ioquake3 before r1762, OpenArena, Tremulous, and other products, allows remote attackers to cauioquake3 · ioquake3 engine · CWE-20 | Yüksek7,8 | — | %2,1 | 27 Eki 2014 |
31İzleyin | CVE-2011-1412İstismar yok | sys/sys_unix.c in the ioQuake3 engine on Unix and Linux, as used in World of Padman 1.5.x before 1.5.1.1 and OpenArena 0.8.x-15 and 0.8.x-16ioquake3 · ioquake3 engine · CWE-20 | Yüksek7,5 | — | %4,2 | 3 Ağu 2011 |
31İzleyin | CVE-2017-6903İstismar yok | In ioquake3 before 2017-03-14, the auto-downloading feature has insufficient content restrictions.ioquake3 · ioquake3 | Yüksek7,8 | — | %1,3 | 14 Mar 2017 |
22İzleyin | CVE-2012-3345İstismar yok | ioquake3 before r2253 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/ioq3.pid temporary file.ioquake3 · ioquake3 engine · CWE-59 | Orta5,6 | — | %0,3 | 15 Haz 2012 |
- CVE-2011-276443Planlayın
The FS_CheckFilenameIsNotExecutable function in qcommon/files.c in the ioQuake3 engine 1.36 and earlier, as used in World of Padman, Smokin'
KritikCVSS 10,0İstismar yokEPSS %9ioquake3 · ioquake3 engine3 Ağu 2011
- CVE-2011-301242Planlayın
The ioQuake3 engine, as used in World of Padman 1.2 and earlier, Tremulous 1.1.0, and ioUrbanTerror 2007-12-20, does not check for dangerous
KritikCVSS 10,0İstismar yokEPSS %8ioquake3 · ioquake3 engine9 Ağu 2011
- CVE-2017-1172140Planlayın
Buffer overflow in ioquake3 before 2017-08-02 allows remote attackers to cause a denial of service (application crash) or possibly have unsp
KritikCVSS 9,8İstismar yokEPSS %3ioquake3 · ioquake33 Ağu 2017
- CVE-2010-507732İzleyin
server/sv_main.c in Quake3 Arena, as used in ioquake3 before r1762, OpenArena, Tremulous, and other products, allows remote attackers to cau
YüksekCVSS 7,8İstismar yokEPSS %2ioquake3 · ioquake3 engine27 Eki 2014
- CVE-2011-141231İzleyin
sys/sys_unix.c in the ioQuake3 engine on Unix and Linux, as used in World of Padman 1.5.x before 1.5.1.1 and OpenArena 0.8.x-15 and 0.8.x-16
YüksekCVSS 7,5İstismar yokEPSS %4ioquake3 · ioquake3 engine3 Ağu 2011
- CVE-2017-690331İzleyin
In ioquake3 before 2017-03-14, the auto-downloading feature has insufficient content restrictions.
YüksekCVSS 7,8İstismar yokEPSS %1ioquake3 · ioquake314 Mar 2017
- CVE-2012-334522İzleyin
ioquake3 before r2253 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/ioq3.pid temporary file.
OrtaCVSS 5,6İstismar yokEPSS %0ioquake3 · ioquake3 engine15 Haz 2012