Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
38 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 1.6% | — | ID Software Quake II Server | 31/12/2004 | 16/6/2026 | Quake II server before R1Q2, as used in multiple products, allows remote attackers to bypass IP-based access control rules via a userinfo string that already contains an "ip" key/value pair but is also long enough to cause a new key/value pair to be truncated, which interferes with the server's ability to find the… | |
| Modificada | Media (5) | 1.4% | — | ID Software Quake II ServerAI | 31/12/2004 | 16/6/2026 | Quake II server before R1Q2, as used in multiple products, allows remote attackers to corrupt the server's client state data structure by exiting a session without a valid disconnect command, then reconnecting, which prevents a mod from being notified of changes in the client state. NOTE: the impact of this issue will… | |
| Modificada | Media (5) | 5.5% | — | ID Software Quake 2I Server | 12/8/2002 | 16/6/2026 | Quake 2 (Q2) server 3.20 and 3.21 allows remote attackers to obtain sensitive server cvar variables, obtain directory listings, and execute Q2 server admin commands via a client that does not expand "$" macros, which causes the server to expand the macros and leak the information, as demonstrated using "say… | |
| Modificada | Media (5) | 5.2% | — | ID Software Quake 3 Arena | 29/7/2001 | 16/6/2026 | Quake 3 arena 1.29f and 1.29g allows remote attackers to cause a denial of service (crash) via a malformed connection packet that begins with several char-255 characters. | |
| Modificada | Media (5) | 3.2% | — | ID Software Quake | 17/7/2001 | 16/6/2026 | Quake 1 and NetQuake servers allow remote attackers to cause a denial of service (resource exhaustion or forced disconnection) via a flood of spoofed UDP connection packets, which exceeds the server's player limit. | |
| Modificada | Media (5) | 1.7% | — | ID Software QuakeJ. P. Grossman Proquake | 1/11/2000 | 16/6/2026 | Quake 1 (quake1) and ProQuake 1.01 and earlier allow remote attackers to cause a denial of service via a malformed (empty) UDP packet. | |
| Modificada | Media (6.4) | 1.3% | — | ID Software Quake 3 Arena | 3/5/2000 | 16/6/2026 | Quake3 Arena allows malicious server operators to read or modify files on a client via a dot dot (..) attack. | |
| Modificada | Media (5) | 1.3% | — | SGI Quake 1 Server | 22/12/1999 | 16/6/2026 | Quake 1 server responds to an initial UDP game connection request with a large amount of traffic, which allows remote attackers to use the server as an amplifier in a "Smurf" style attack on another host, by spoofing the connection request. | |
| Modificada | Alta (10) | 1.6% | — | Quakenbush NT Password AppraiserAI | 1/1/1999 | 16/6/2026 | The demo version of the Quakenbush NT Password Appraiser sends passwords across the network in plaintext. | |
| Modificada | Alta (7.5) | 1.9% | — | ID Software Quake | 8/4/1998 | 16/6/2026 | Buffer overflows in Quake 1.9 client allows remote malicious servers to execute arbitrary commands via long (1) precache paths, (2) server name, (3) server address, or (4) argument to the map console command. | |
| Modificada | Alta (7.5) | 2.0% | — | ID Software Quakeworld | 7/4/1998 | 16/6/2026 | Buffer overflow in QuakeWorld 2.10 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary commands via a long initial connect packet. | |
| Modificada | Baja (2.1) | 0.47% | — | ID Software Quake 2 Server | 25/2/1998 | 16/6/2026 | Quake 2 server 3.13 on Linux does not properly check file permissions for the config.cfg configuration file, which allows local users to read arbitrary files via a symlink from config.cfg to the target file. | |
| Modificada | Media (5) | 1.3% | — | ID Software Quake 2 | 24/12/1997 | 16/6/2026 | Quake 2 server allows remote attackers to cause a denial of service via a spoofed UDP packet with a source address of 127.0.0.1, which causes the server to attempt to connect to itself. |