İçeriğe atla
Noroxi

valvesoftware kayıtları

valvesoftware üreticisine ait 29 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
4
Düzeltme kaydı olan
%3,4
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Bug bounty kapsamı

Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.

Tüm kayıtlar

29 kayıt
  • CVE-2020-6016
    41Planlayın

    Valve's Game Networking Sockets prior to version v1.2.0 improperly handles unreliable segments with negative offsets in function SNP_Receive

    KritikCVSS 9,8İstismar yokEPSS %6

    valvesoftware · game networking sockets18 Kas 2020

  • CVE-2017-17877
    40Planlayın

    An issue was discovered in Valve Steam Link build 643.

    KritikCVSS 9,8İstismar yokEPSS %4

    valvesoftware · steam link firmware27 Ara 2017

  • CVE-2020-6018
    40Planlayın

    Valve's Game Networking Sockets prior to version v1.2.0 improperly handles long encrypted messages in function AES_GCM_DecryptContext::Decry

    KritikCVSS 9,8İstismar yokEPSS %3

    valvesoftware · game networking sockets1 Ara 2020

  • CVE-2020-6017
    40Planlayın

    Valve's Game Networking Sockets prior to version v1.2.0 improperly handles long unreliable segments in function SNP_ReceiveUnreliableSegment

    KritikCVSS 9,8İstismar yokEPSS %3

    valvesoftware · game networking sockets3 Ara 2020

  • CVE-2017-17878
    39İzleyin

    An issue was discovered in Valve Steam Link build 643.

    KritikCVSS 9,8İstismar yokEPSS %2

    valvesoftware · steam link firmware27 Ara 2017

  • CVE-2023-35855
    39İzleyin

    A buffer overflow in Counter-Strike through 8684 allows a game server to execute arbitrary code on a remote client's machine by modifying th

    KritikCVSS 9,8İstismar yokEPSS %1

    valvesoftware · counter-strike19 Haz 2023

  • CVE-2019-15943
    38İzleyin

    vphysics.dll in Counter-Strike: Global Offensive before 1.37.1.1 allows remote attackers to achieve code execution or denial of service by c

    YüksekCVSS 8,8Kavram kanıtıEPSS %9

    valvesoftware · counter-strike\19 Eyl 2019

  • CVE-2021-30481
    37İzleyin

    Valve Steam before 2021-04-17, when a Source engine game is installed, allows remote authenticated users to execute arbitrary code because o

    KritikCVSS 9,0Kavram kanıtıEPSS %4

    valvesoftware · steam client10 Nis 2021

  • CVE-2020-7949
    32İzleyin

    schemasystem.dll in Valve Dota 2 before 7.23f allows remote attackers to achieve code execution or denial of service by creating a gaming se

    YüksekCVSS 7,8Kavram kanıtıEPSS %4

    valvesoftware · dota 227 Oca 2020

  • CVE-2020-9005
    32İzleyin

    meshsystem.dll in Valve Dota 2 through 2020-02-17 allows remote attackers to achieve code execution or denial of service by creating a gamin

    YüksekCVSS 7,8İstismar yokEPSS %2

    valvesoftware · dota 217 Şub 2020

  • CVE-2020-7950
    32İzleyin

    meshsystem.dll in Valve Dota 2 before 7.23f allows remote attackers to achieve code execution or denial of service by creating a gaming serv

    YüksekCVSS 7,8İstismar yokEPSS %2

    valvesoftware · dota 227 Oca 2020

  • CVE-2020-7951
    32İzleyin

    meshsystem.dll in Valve Dota 2 before 7.23e allows remote attackers to achieve code execution or denial of service by creating a gaming serv

    YüksekCVSS 7,8İstismar yokEPSS %2

    valvesoftware · dota 227 Oca 2020

  • CVE-2020-7952
    32İzleyin

    rendersystemdx9.dll in Valve Dota 2 before 7.23f allows remote attackers to achieve code execution or denial of service by creating a gaming

    YüksekCVSS 7,8İstismar yokEPSS %2

    valvesoftware · dota 227 Oca 2020

  • CVE-2020-6019
    31İzleyin

    Valve's Game Networking Sockets prior to version v1.2.0 improperly handles inlined statistics messages in function CConnectionTransportUDPBa

    YüksekCVSS 7,5İstismar yokEPSS %3

    valvesoftware · game networking sockets13 Kas 2020

  • CVE-2020-12242
    31İzleyin

    Valve Source allows local users to gain privileges by writing to the /tmp/hl2_relaunch file, which is later executed in the context of a dif

    YüksekCVSS 7,8Kavram kanıtıEPSS %1

    valvesoftware · source27 Nis 2020

  • CVE-2019-17180
    31İzleyin

    Valve Steam Client before 2019-09-12 allows placing or appending partially controlled filesystem content, as demonstrated by file modificati

    YüksekCVSS 7,8İstismar yokEPSS %1

    valvesoftware · steam client4 Eki 2019

  • CVE-2020-15530
    31İzleyin

    An issue was discovered in Valve Steam Client 2.10.91.91.

    YüksekCVSS 7,8İstismar yokEPSS %1

    valvesoftware · steam client4 Tem 2020

  • CVE-2019-15315
    31İzleyin

    Valve Steam Client for Windows through 2019-08-16 allows privilege escalation (to NT AUTHORITY\SYSTEM) because local users can replace the c

    YüksekCVSS 7,8İstismar yokEPSS %0

    valvesoftware · steam client21 Ağu 2019

  • CVE-2023-38312
    30İzleyin

    A directory traversal vulnerability in Valve Counter-Strike 8684 allows a client (with remote control access to a game server) to read arbit

    YüksekCVSS 7,5İstismar yokEPSS %1

    valvesoftware · counter-strike15 Eki 2023

  • CVE-2023-30382
    29İzleyin

    A buffer overflow in the component hl.exe of Valve Half-Life up to 5433873 allows attackers to execute arbitrary code and escalate privilege

    YüksekCVSS 7,3İstismar yokEPSS %0

    valvesoftware · half-life23 May 2023

  • CVE-2015-7985
    28İzleyin

    Valve Steam 2.10.91.91 uses weak permissions (Users: read and write) for the Install folder, which allows local users to gain privileges via

    YüksekCVSS 7,2Kavram kanıtıEPSS %1

    valvesoftware · steam client24 Kas 2015

  • CVE-2019-15316
    28İzleyin

    Valve Steam Client for Windows through 2019-08-20 has weak folder permissions, leading to privilege escalation (to NT AUTHORITY\SYSTEM) via

    YüksekCVSS 7,0İstismar yokEPSS %0

    valvesoftware · steam client21 Ağu 2019

  • CVE-2019-14743
    26İzleyin

    In Valve Steam Client for Windows through 2019-08-07, HKLM\SOFTWARE\Wow6432Node\Valve\Steam has explicit "Full control" for the Users group,

    OrtaCVSS 6,6İstismar yokEPSS %1

    valvesoftware · steam client7 Ağu 2019

  • CVE-2015-4016
    21İzleyin

    The client detection protocol in Valve Steam allows remote attackers to cause a denial of service (process crash) via a crafted response to

    OrtaCVSS 5,0İstismar yokEPSS %3

    valvesoftware · steam client20 May 2015

  • CVE-2008-7203
    21İzleyin

    Valve Software Half-Life Counter-Strike 1.6 allows remote attackers to cause a denial of service (crash) via multiple crafted login packets.

    OrtaCVSS 5,0Kavram kanıtıEPSS %3

    valvesoftware · counter-strike11 Eyl 2009