Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

38 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)1.6%—ID Software Quake II Server31/12/200416/6/2026
Quake II server before R1Q2, as used in multiple products, allows remote attackers to bypass IP-based access control rules via a userinfo string that already contains an "ip" key/value pair but is also long enough to cause a new key/value pair to be truncated, which interferes with the server's ability to find the…
ModificadaMedia (5)1.4%—ID Software Quake II ServerAI31/12/200416/6/2026
Quake II server before R1Q2, as used in multiple products, allows remote attackers to corrupt the server's client state data structure by exiting a session without a valid disconnect command, then reconnecting, which prevents a mod from being notified of changes in the client state. NOTE: the impact of this issue will…
ModificadaMedia (5)5.5%—ID Software Quake 2I Server12/8/200216/6/2026
Quake 2 (Q2) server 3.20 and 3.21 allows remote attackers to obtain sensitive server cvar variables, obtain directory listings, and execute Q2 server admin commands via a client that does not expand "$" macros, which causes the server to expand the macros and leak the information, as demonstrated using "say…
ModificadaMedia (5)5.2%—ID Software Quake 3 Arena29/7/200116/6/2026
Quake 3 arena 1.29f and 1.29g allows remote attackers to cause a denial of service (crash) via a malformed connection packet that begins with several char-255 characters.
ModificadaMedia (5)3.2%—ID Software Quake17/7/200116/6/2026
Quake 1 and NetQuake servers allow remote attackers to cause a denial of service (resource exhaustion or forced disconnection) via a flood of spoofed UDP connection packets, which exceeds the server's player limit.
ModificadaMedia (5)1.7%—ID Software QuakeJ. P. Grossman Proquake1/11/200016/6/2026
Quake 1 (quake1) and ProQuake 1.01 and earlier allow remote attackers to cause a denial of service via a malformed (empty) UDP packet.
ModificadaMedia (6.4)1.3%—ID Software Quake 3 Arena3/5/200016/6/2026
Quake3 Arena allows malicious server operators to read or modify files on a client via a dot dot (..) attack.
ModificadaMedia (5)1.3%—SGI Quake 1 Server22/12/199916/6/2026
Quake 1 server responds to an initial UDP game connection request with a large amount of traffic, which allows remote attackers to use the server as an amplifier in a "Smurf" style attack on another host, by spoofing the connection request.
ModificadaAlta (10)1.6%—Quakenbush NT Password AppraiserAI1/1/199916/6/2026
The demo version of the Quakenbush NT Password Appraiser sends passwords across the network in plaintext.
ModificadaAlta (7.5)1.9%—ID Software Quake8/4/199816/6/2026
Buffer overflows in Quake 1.9 client allows remote malicious servers to execute arbitrary commands via long (1) precache paths, (2) server name, (3) server address, or (4) argument to the map console command.
ModificadaAlta (7.5)2.0%—ID Software Quakeworld7/4/199816/6/2026
Buffer overflow in QuakeWorld 2.10 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary commands via a long initial connect packet.
ModificadaBaja (2.1)0.47%—ID Software Quake 2 Server25/2/199816/6/2026
Quake 2 server 3.13 on Linux does not properly check file permissions for the config.cfg configuration file, which allows local users to read arbitrary files via a symlink from config.cfg to the target file.
ModificadaMedia (5)1.3%—ID Software Quake 224/12/199716/6/2026
Quake 2 server allows remote attackers to cause a denial of service via a spoofed UDP packet with a source address of 127.0.0.1, which causes the server to attempt to connect to itself.