Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
–

128 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.6)0.51%—Joey Hess Bsdgames12/4/200616/6/2026
Buffer overflow in pl_main.c in sail in BSDgames before 2.17-7 allows local users to execute arbitrary code via a long player name that is used in a scanf function call.
ModificadaAlta (7.5)2.1%—Bsd-games Tetris-bsd30/3/200616/6/2026
Multiple buffer overflows in the checkscores function in scores.c in tetris-bsd in bsd-games before 2.17-r1 in Gentoo Linux might allow local users with games group membership to gain privileges by modifying tetris-bsd.scores to contain crafted executable content, which is executed when another user launches…
ModificadaAlta (7.5)3.3%💥 ExploitCynical Games Shoutlive1/3/200616/6/2026
Multiple direct static code injection vulnerabilities in savesettings.php in ShoutLIVE 1.1.0 allow remote attackers to execute arbitrary PHP code via variables that are written to settings.php.
ModificadaMedia (4.3)1.4%—Cynical Games Shoutlive1/3/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in post.php in ShoutLIVE 1.1.0 allow remote attackers to inject arbitrary web script or HTML via certain variables when posting new messages.
ModificadaMedia (5)3.0%💥 ExploitAfsl Games Battle Carry4/11/200516/6/2026
Battle Carry .005 and earlier allows remote attackers to cause a denial of service (inaccessible port) via a large packet, which triggers a socket error and terminates the socket that is listening on the server's UDP port.
ModificadaMedia (5)3.4%💥 ExploitLS Games WAR Times24/5/200516/6/2026
Buffer overflow in LS Games War Times 1.03 and earlier allows remote attackers to cause a denial of service (server crash) via a long nickname.
ModificadaMedia (5)1.7%—Gamespy SDK Cd-key Validation Toolkit14/5/200516/6/2026
Gamespy cd-key validation system allows remote attackers to cause a denial of service (cd-key already in use) by capturing and replaying a cd-key authorization session.
ModificadaMedia (5)1.8%—Gamespy Cd-key Validation System11/5/200516/6/2026
GameSpy SDK CD-Key Validation Toolkit, as used by many online games, allows remote attackers to bypass the CD key validation by sending a spoofed \disc\ command, which tells the server the CD key is no longer in use.
ModificadaAlta (7.5)2.4%—Lgames Ltris2/5/200516/6/2026
Buffer overflow in LTris before 1.0.10 allows local users to execute arbitrary code via a crafted highscores file.
ModificadaMedia (5)3.4%💥 ExploitTargem Games Battle Mages31/12/200416/6/2026
Targem Battle Mages 1.0 allows remote attackers to cause a denial of service (infinite loop) via a UDP packet with incomplete data, which causes the server to enter an infinite loop while waiting to read the rest of the data that is not sent.
ModificadaMedia (5)2.9%—Impressions Games Lords OF THE Realm III31/12/200416/6/2026
Lords of the Realm III 1.01 and earlier, when in the lobby stage, allows remote attackers to cause a denial of service (crash from unallocated memory write) via a long user nickname.
ModificadaMedia (5)2.4%💥 ExploitEpic Games Unreal EngineEpic Games Unreal TournamentEpic Games Unreal Tournament 200331/12/200416/6/2026
Directory traversal vulnerability in manifest.ini in Unreal engine allows remote attackers to overwrite arbitrary files via .. (dot dot) sequences in a UMOD (Unreal MOD) file.
ModificadaMedia (5)1.5%—Gamespy Roger WilcoGamespy Roger Wilco Dedicated ServerGamespy Roger Wilco Graphical ServerGamespy Roger Wilco Mark31/12/200416/6/2026
The client and server for Roger Wilco 1.4.1.6 and earlier or Roger Wilco Base Station 0.30a and earlier report sensitive information such as IDs and source IP addresses, which allows remote attackers to obtain sensitive information.
ModificadaMedia (5)5.7%💥 ExploitGamespy Roger Wilco Dedicated ServerGamespy Roger Wilco Graphical Server31/12/200416/6/2026
Roger Wilco 1.4.1.6 and earlier or Roger Wilco Base Station 0.30a and earlier allows remote attackers to cause a denial of service (application crash) via a long, malformed UDP datagram.
ModificadaMedia (5)2.3%💥 ExploitRoger Wilco Base StationAIGamespy Roger WilcoAI31/12/200416/6/2026
Roger Wilco 1.4.1.6 and earlier, or Roger Wilco Base Station 0.30a or earlier, allows remote attackers to send audio to arbitrary channels, aka the "Voices from the deep" bug.
ModificadaMedia (5)6.4%💥 ExploitEpic Games Unreal Engine31/12/200416/6/2026
Format string vulnerability in games using the Epic Games Unreal Engine 436 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in class names.
ModificadaAlta (10)74%💥 ExploitArush DevastationDreamforge TNN Outdoors PRO HunterEpic Games Unreal EngineEpic Games Unreal Tournament+106/12/200416/6/2026
The Unreal Engine, as used in DeusEx 1.112fm and earlier, Devastation 390 and earlier, Mobile Forces 20000 and earlier, Nerf Arena Blast 1.2 and earlier, Postal 2 1337 and earlier, Rune 107 and earlier, Tactical Ops 3.4.0 and earlier, Unreal 1 226f and earlier, Unreal II XMP 7710 and earlier, Unreal Tournament 451b…
ModificadaMedia (4.6)0.89%💥 ExploitLgames Lbreakout229/3/200416/6/2026
Buffer overflow in lbreakout2 allows local users to gain 'games' group privileges via a large HOME environment variable to (1) editor.c, (2) theme.c, (3) manager.c, (4) config.c, (5) game.c, (6) levels.c, or (7) main.c.
ModificadaMedia (5)1.7%—Fluidgames THE Rage23/3/200416/6/2026
The Rage 1.01 and earlier allows remote attackers to cause a denial of service (infinite loop) via a TCP packet with the port and IP address set to zero.
ModificadaAlta (7.1)5.2%💥 ExploitEpic Games Unreal Engine31/12/200316/6/2026
Buffer overflow in Epic Games Unreal Engine 226f through 436 allows remote attackers to cause a denial of service (crash) via a long host string in the Unreal URL.
ModificadaAlta (10)7.5%—Epic Games Unreal EngineEpic Games Unreal Tournament 200331/12/200316/6/2026
Epic Games Unreal Engine 226f through 436 allows remote attackers to cause a denial of service (CPU consumption or crash) and possibly execute arbitrary code via (1) a packet with a negative size value, which is treated as a large positive number during memory allocation, or (2) a negative size value in a package file.
ModificadaMedia (5)2.8%💥 ExploitEpic Games Unreal Engine31/12/200316/6/2026
Directory traversal vulnerability in Unreal Tournament Server 436 and earlier allows remote attackers to access known files via a ".." (dot dot) in an unreal:// URL.
ModificadaMedia (4.6)0.92%💥 ExploitLgames Ltris31/12/200316/6/2026
Buffer overflow in LTris 1.0.1 of FreeBSD Ports Collection 2003-02-25 and earlier allows local users to execute arbitrary code with gid "games" permission via a long HOME environment variable.
ModificadaMedia (4.3)1.2%—Epic Games Unreal Engine31/12/200316/6/2026
Epic Games Unreal Engine 226f through 436 does not validate the challenge key, which allows remote attackers to exhaust the player limit by joining the game multiple times.
ModificadaMedia (5)6.2%💥 ExploitGamespy3d Gamespy 3D31/12/200316/6/2026
Multiple GameSpy 3D 2.62 compatible gaming servers generate very large UDP responses to small requests, which allows remote attackers to use the servers as an amplifier in DDoS attacks with spoofed UDP query packets, as demonstrated using Battlefield 1942.