valvesoftware kayıtları
valvesoftware üreticisine ait 29 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 4
- Düzeltme kaydı olan
- %3,4
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')4
- CWE-787 Out-of-bounds Write4
- CWE-20 Improper Input Validation2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-732 Incorrect Permission Assignment for Critical Resource2
- CWE-116 Improper Encoding or Escaping of Output1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWEBug bounty kapsamı
Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.
Tüm kayıtlar
29 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
41Planlayın | CVE-2020-6016İstismar yok | Valve's Game Networking Sockets prior to version v1.2.0 improperly handles unreliable segments with negative offsets in function SNP_Receivevalvesoftware · game networking sockets · CWE-590 | Kritik9,8 | — | %6,0 | 18 Kas 2020 |
40Planlayın | CVE-2017-17877İstismar yok | An issue was discovered in Valve Steam Link build 643.valvesoftware · steam link firmware | Kritik9,8 | — | %4,1 | 27 Ara 2017 |
40Planlayın | CVE-2020-6018İstismar yok | Valve's Game Networking Sockets prior to version v1.2.0 improperly handles long encrypted messages in function AES_GCM_DecryptContext::Decryvalvesoftware · game networking sockets · CWE-120 | Kritik9,8 | — | %3,2 | 1 Ara 2020 |
40Planlayın | CVE-2020-6017İstismar yok | Valve's Game Networking Sockets prior to version v1.2.0 improperly handles long unreliable segments in function SNP_ReceiveUnreliableSegmentvalvesoftware · game networking sockets · CWE-120 | Kritik9,8 | — | %3,2 | 3 Ara 2020 |
39İzleyin | CVE-2017-17878İstismar yok | An issue was discovered in Valve Steam Link build 643.valvesoftware · steam link firmware · CWE-327 | Kritik9,8 | — | %1,6 | 27 Ara 2017 |
39İzleyin | CVE-2023-35855İstismar yok | A buffer overflow in Counter-Strike through 8684 allows a game server to execute arbitrary code on a remote client's machine by modifying thvalvesoftware · counter-strike · CWE-120 | Kritik9,8 | — | %1,1 | 19 Haz 2023 |
38İzleyin | CVE-2019-15943Kavram kanıtı | vphysics.dll in Counter-Strike: Global Offensive before 1.37.1.1 allows remote attackers to achieve code execution or denial of service by cvalvesoftware · counter-strike\ · CWE-787 | Yüksek8,8 | — | %8,7 | 19 Eyl 2019 |
37İzleyin | CVE-2021-30481Kavram kanıtı | Valve Steam before 2021-04-17, when a Source engine game is installed, allows remote authenticated users to execute arbitrary code because ovalvesoftware · steam client · CWE-120 | Kritik9,0 | — | %3,5 | 10 Nis 2021 |
32İzleyin | CVE-2020-7949Kavram kanıtı | schemasystem.dll in Valve Dota 2 before 7.23f allows remote attackers to achieve code execution or denial of service by creating a gaming sevalvesoftware · dota 2 | Yüksek7,8 | — | %4,2 | 27 Oca 2020 |
32İzleyin | CVE-2020-9005İstismar yok | meshsystem.dll in Valve Dota 2 through 2020-02-17 allows remote attackers to achieve code execution or denial of service by creating a gaminvalvesoftware · dota 2 · CWE-787 | Yüksek7,8 | — | %2,2 | 17 Şub 2020 |
32İzleyin | CVE-2020-7950İstismar yok | meshsystem.dll in Valve Dota 2 before 7.23f allows remote attackers to achieve code execution or denial of service by creating a gaming servvalvesoftware · dota 2 | Yüksek7,8 | — | %1,9 | 27 Oca 2020 |
32İzleyin | CVE-2020-7951İstismar yok | meshsystem.dll in Valve Dota 2 before 7.23e allows remote attackers to achieve code execution or denial of service by creating a gaming servvalvesoftware · dota 2 · CWE-787 | Yüksek7,8 | — | %1,9 | 27 Oca 2020 |
32İzleyin | CVE-2020-7952İstismar yok | rendersystemdx9.dll in Valve Dota 2 before 7.23f allows remote attackers to achieve code execution or denial of service by creating a gamingvalvesoftware · dota 2 | Yüksek7,8 | — | %1,9 | 27 Oca 2020 |
31İzleyin | CVE-2020-6019İstismar yok | Valve's Game Networking Sockets prior to version v1.2.0 improperly handles inlined statistics messages in function CConnectionTransportUDPBavalvesoftware · game networking sockets · CWE-248 | Yüksek7,5 | — | %2,8 | 13 Kas 2020 |
31İzleyin | CVE-2020-12242Kavram kanıtı | Valve Source allows local users to gain privileges by writing to the /tmp/hl2_relaunch file, which is later executed in the context of a difvalvesoftware · source · CWE-78 | Yüksek7,8 | — | %1,1 | 27 Nis 2020 |
31İzleyin | CVE-2019-17180İstismar yok | Valve Steam Client before 2019-09-12 allows placing or appending partially controlled filesystem content, as demonstrated by file modificativalvesoftware · steam client · CWE-22 | Yüksek7,8 | — | %0,7 | 4 Eki 2019 |
31İzleyin | CVE-2020-15530İstismar yok | An issue was discovered in Valve Steam Client 2.10.91.91.valvesoftware · steam client · CWE-362 | Yüksek7,8 | — | %0,5 | 4 Tem 2020 |
31İzleyin | CVE-2019-15315İstismar yok | Valve Steam Client for Windows through 2019-08-16 allows privilege escalation (to NT AUTHORITY\SYSTEM) because local users can replace the cvalvesoftware · steam client · CWE-732 | Yüksek7,8 | — | %0,4 | 21 Ağu 2019 |
30İzleyin | CVE-2023-38312İstismar yok | A directory traversal vulnerability in Valve Counter-Strike 8684 allows a client (with remote control access to a game server) to read arbitvalvesoftware · counter-strike · CWE-22 | Yüksek7,5 | — | %0,8 | 15 Eki 2023 |
29İzleyin | CVE-2023-30382İstismar yok | A buffer overflow in the component hl.exe of Valve Half-Life up to 5433873 allows attackers to execute arbitrary code and escalate privilegevalvesoftware · half-life · CWE-787 | Yüksek7,3 | — | %0,2 | 23 May 2023 |
28İzleyin | CVE-2015-7985Kavram kanıtı | Valve Steam 2.10.91.91 uses weak permissions (Users: read and write) for the Install folder, which allows local users to gain privileges viavalvesoftware · steam client · CWE-276 | Yüksek7,2 | — | %1,0 | 24 Kas 2015 |
28İzleyin | CVE-2019-15316İstismar yok | Valve Steam Client for Windows through 2019-08-20 has weak folder permissions, leading to privilege escalation (to NT AUTHORITY\SYSTEM) via valvesoftware · steam client · CWE-367 | Yüksek7,0 | — | %0,4 | 21 Ağu 2019 |
26İzleyin | CVE-2019-14743İstismar yok | In Valve Steam Client for Windows through 2019-08-07, HKLM\SOFTWARE\Wow6432Node\Valve\Steam has explicit "Full control" for the Users group,valvesoftware · steam client · CWE-732 | Orta6,6 | — | %0,6 | 7 Ağu 2019 |
21İzleyin | CVE-2015-4016İstismar yok | The client detection protocol in Valve Steam allows remote attackers to cause a denial of service (process crash) via a crafted response to valvesoftware · steam client · CWE-20 | Orta5,0 | — | %3,0 | 20 May 2015 |
21İzleyin | CVE-2008-7203Kavram kanıtı | Valve Software Half-Life Counter-Strike 1.6 allows remote attackers to cause a denial of service (crash) via multiple crafted login packets.valvesoftware · counter-strike · CWE-399 | Orta5,0 | — | %2,6 | 11 Eyl 2009 |
- CVE-2020-601641Planlayın
Valve's Game Networking Sockets prior to version v1.2.0 improperly handles unreliable segments with negative offsets in function SNP_Receive
KritikCVSS 9,8İstismar yokEPSS %6valvesoftware · game networking sockets18 Kas 2020
- CVE-2017-1787740Planlayın
An issue was discovered in Valve Steam Link build 643.
KritikCVSS 9,8İstismar yokEPSS %4valvesoftware · steam link firmware27 Ara 2017
- CVE-2020-601840Planlayın
Valve's Game Networking Sockets prior to version v1.2.0 improperly handles long encrypted messages in function AES_GCM_DecryptContext::Decry
KritikCVSS 9,8İstismar yokEPSS %3valvesoftware · game networking sockets1 Ara 2020
- CVE-2020-601740Planlayın
Valve's Game Networking Sockets prior to version v1.2.0 improperly handles long unreliable segments in function SNP_ReceiveUnreliableSegment
KritikCVSS 9,8İstismar yokEPSS %3valvesoftware · game networking sockets3 Ara 2020
- CVE-2017-1787839İzleyin
An issue was discovered in Valve Steam Link build 643.
KritikCVSS 9,8İstismar yokEPSS %2valvesoftware · steam link firmware27 Ara 2017
- CVE-2023-3585539İzleyin
A buffer overflow in Counter-Strike through 8684 allows a game server to execute arbitrary code on a remote client's machine by modifying th
KritikCVSS 9,8İstismar yokEPSS %1valvesoftware · counter-strike19 Haz 2023
- CVE-2019-1594338İzleyin
vphysics.dll in Counter-Strike: Global Offensive before 1.37.1.1 allows remote attackers to achieve code execution or denial of service by c
YüksekCVSS 8,8Kavram kanıtıEPSS %9valvesoftware · counter-strike\19 Eyl 2019
- CVE-2021-3048137İzleyin
Valve Steam before 2021-04-17, when a Source engine game is installed, allows remote authenticated users to execute arbitrary code because o
KritikCVSS 9,0Kavram kanıtıEPSS %4valvesoftware · steam client10 Nis 2021
- CVE-2020-794932İzleyin
schemasystem.dll in Valve Dota 2 before 7.23f allows remote attackers to achieve code execution or denial of service by creating a gaming se
YüksekCVSS 7,8Kavram kanıtıEPSS %4valvesoftware · dota 227 Oca 2020
- CVE-2020-900532İzleyin
meshsystem.dll in Valve Dota 2 through 2020-02-17 allows remote attackers to achieve code execution or denial of service by creating a gamin
YüksekCVSS 7,8İstismar yokEPSS %2valvesoftware · dota 217 Şub 2020
- CVE-2020-795032İzleyin
meshsystem.dll in Valve Dota 2 before 7.23f allows remote attackers to achieve code execution or denial of service by creating a gaming serv
YüksekCVSS 7,8İstismar yokEPSS %2valvesoftware · dota 227 Oca 2020
- CVE-2020-795132İzleyin
meshsystem.dll in Valve Dota 2 before 7.23e allows remote attackers to achieve code execution or denial of service by creating a gaming serv
YüksekCVSS 7,8İstismar yokEPSS %2valvesoftware · dota 227 Oca 2020
- CVE-2020-795232İzleyin
rendersystemdx9.dll in Valve Dota 2 before 7.23f allows remote attackers to achieve code execution or denial of service by creating a gaming
YüksekCVSS 7,8İstismar yokEPSS %2valvesoftware · dota 227 Oca 2020
- CVE-2020-601931İzleyin
Valve's Game Networking Sockets prior to version v1.2.0 improperly handles inlined statistics messages in function CConnectionTransportUDPBa
YüksekCVSS 7,5İstismar yokEPSS %3valvesoftware · game networking sockets13 Kas 2020
- CVE-2020-1224231İzleyin
Valve Source allows local users to gain privileges by writing to the /tmp/hl2_relaunch file, which is later executed in the context of a dif
YüksekCVSS 7,8Kavram kanıtıEPSS %1valvesoftware · source27 Nis 2020
- CVE-2019-1718031İzleyin
Valve Steam Client before 2019-09-12 allows placing or appending partially controlled filesystem content, as demonstrated by file modificati
YüksekCVSS 7,8İstismar yokEPSS %1valvesoftware · steam client4 Eki 2019
- CVE-2020-1553031İzleyin
An issue was discovered in Valve Steam Client 2.10.91.91.
YüksekCVSS 7,8İstismar yokEPSS %1valvesoftware · steam client4 Tem 2020
- CVE-2019-1531531İzleyin
Valve Steam Client for Windows through 2019-08-16 allows privilege escalation (to NT AUTHORITY\SYSTEM) because local users can replace the c
YüksekCVSS 7,8İstismar yokEPSS %0valvesoftware · steam client21 Ağu 2019
- CVE-2023-3831230İzleyin
A directory traversal vulnerability in Valve Counter-Strike 8684 allows a client (with remote control access to a game server) to read arbit
YüksekCVSS 7,5İstismar yokEPSS %1valvesoftware · counter-strike15 Eki 2023
- CVE-2023-3038229İzleyin
A buffer overflow in the component hl.exe of Valve Half-Life up to 5433873 allows attackers to execute arbitrary code and escalate privilege
YüksekCVSS 7,3İstismar yokEPSS %0valvesoftware · half-life23 May 2023
- CVE-2015-798528İzleyin
Valve Steam 2.10.91.91 uses weak permissions (Users: read and write) for the Install folder, which allows local users to gain privileges via
YüksekCVSS 7,2Kavram kanıtıEPSS %1valvesoftware · steam client24 Kas 2015
- CVE-2019-1531628İzleyin
Valve Steam Client for Windows through 2019-08-20 has weak folder permissions, leading to privilege escalation (to NT AUTHORITY\SYSTEM) via
YüksekCVSS 7,0İstismar yokEPSS %0valvesoftware · steam client21 Ağu 2019
- CVE-2019-1474326İzleyin
In Valve Steam Client for Windows through 2019-08-07, HKLM\SOFTWARE\Wow6432Node\Valve\Steam has explicit "Full control" for the Users group,
OrtaCVSS 6,6İstismar yokEPSS %1valvesoftware · steam client7 Ağu 2019
- CVE-2015-401621İzleyin
The client detection protocol in Valve Steam allows remote attackers to cause a denial of service (process crash) via a crafted response to
OrtaCVSS 5,0İstismar yokEPSS %3valvesoftware · steam client20 May 2015
- CVE-2008-720321İzleyin
Valve Software Half-Life Counter-Strike 1.6 allows remote attackers to cause a denial of service (crash) via multiple crafted login packets.
OrtaCVSS 5,0Kavram kanıtıEPSS %3valvesoftware · counter-strike11 Eyl 2009