Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
128 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.6) | 0.51% | — | Joey Hess Bsdgames | 12/4/2006 | 16/6/2026 | Buffer overflow in pl_main.c in sail in BSDgames before 2.17-7 allows local users to execute arbitrary code via a long player name that is used in a scanf function call. | |
| Modificada | Alta (7.5) | 2.1% | — | Bsd-games Tetris-bsd | 30/3/2006 | 16/6/2026 | Multiple buffer overflows in the checkscores function in scores.c in tetris-bsd in bsd-games before 2.17-r1 in Gentoo Linux might allow local users with games group membership to gain privileges by modifying tetris-bsd.scores to contain crafted executable content, which is executed when another user launches… | |
| Modificada | Alta (7.5) | 3.3% | 💥 Exploit | Cynical Games Shoutlive | 1/3/2006 | 16/6/2026 | Multiple direct static code injection vulnerabilities in savesettings.php in ShoutLIVE 1.1.0 allow remote attackers to execute arbitrary PHP code via variables that are written to settings.php. | |
| Modificada | Media (4.3) | 1.4% | — | Cynical Games Shoutlive | 1/3/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in post.php in ShoutLIVE 1.1.0 allow remote attackers to inject arbitrary web script or HTML via certain variables when posting new messages. | |
| Modificada | Media (5) | 3.0% | 💥 Exploit | Afsl Games Battle Carry | 4/11/2005 | 16/6/2026 | Battle Carry .005 and earlier allows remote attackers to cause a denial of service (inaccessible port) via a large packet, which triggers a socket error and terminates the socket that is listening on the server's UDP port. | |
| Modificada | Media (5) | 3.4% | 💥 Exploit | LS Games WAR Times | 24/5/2005 | 16/6/2026 | Buffer overflow in LS Games War Times 1.03 and earlier allows remote attackers to cause a denial of service (server crash) via a long nickname. | |
| Modificada | Media (5) | 1.7% | — | Gamespy SDK Cd-key Validation Toolkit | 14/5/2005 | 16/6/2026 | Gamespy cd-key validation system allows remote attackers to cause a denial of service (cd-key already in use) by capturing and replaying a cd-key authorization session. | |
| Modificada | Media (5) | 1.8% | — | Gamespy Cd-key Validation System | 11/5/2005 | 16/6/2026 | GameSpy SDK CD-Key Validation Toolkit, as used by many online games, allows remote attackers to bypass the CD key validation by sending a spoofed \disc\ command, which tells the server the CD key is no longer in use. | |
| Modificada | Alta (7.5) | 2.4% | — | Lgames Ltris | 2/5/2005 | 16/6/2026 | Buffer overflow in LTris before 1.0.10 allows local users to execute arbitrary code via a crafted highscores file. | |
| Modificada | Media (5) | 3.4% | 💥 Exploit | Targem Games Battle Mages | 31/12/2004 | 16/6/2026 | Targem Battle Mages 1.0 allows remote attackers to cause a denial of service (infinite loop) via a UDP packet with incomplete data, which causes the server to enter an infinite loop while waiting to read the rest of the data that is not sent. | |
| Modificada | Media (5) | 2.9% | — | Impressions Games Lords OF THE Realm III | 31/12/2004 | 16/6/2026 | Lords of the Realm III 1.01 and earlier, when in the lobby stage, allows remote attackers to cause a denial of service (crash from unallocated memory write) via a long user nickname. | |
| Modificada | Media (5) | 2.4% | 💥 Exploit | Epic Games Unreal EngineEpic Games Unreal TournamentEpic Games Unreal Tournament 2003 | 31/12/2004 | 16/6/2026 | Directory traversal vulnerability in manifest.ini in Unreal engine allows remote attackers to overwrite arbitrary files via .. (dot dot) sequences in a UMOD (Unreal MOD) file. | |
| Modificada | Media (5) | 1.5% | — | Gamespy Roger WilcoGamespy Roger Wilco Dedicated ServerGamespy Roger Wilco Graphical ServerGamespy Roger Wilco Mark | 31/12/2004 | 16/6/2026 | The client and server for Roger Wilco 1.4.1.6 and earlier or Roger Wilco Base Station 0.30a and earlier report sensitive information such as IDs and source IP addresses, which allows remote attackers to obtain sensitive information. | |
| Modificada | Media (5) | 5.7% | 💥 Exploit | Gamespy Roger Wilco Dedicated ServerGamespy Roger Wilco Graphical Server | 31/12/2004 | 16/6/2026 | Roger Wilco 1.4.1.6 and earlier or Roger Wilco Base Station 0.30a and earlier allows remote attackers to cause a denial of service (application crash) via a long, malformed UDP datagram. | |
| Modificada | Media (5) | 2.3% | 💥 Exploit | Roger Wilco Base StationAIGamespy Roger WilcoAI | 31/12/2004 | 16/6/2026 | Roger Wilco 1.4.1.6 and earlier, or Roger Wilco Base Station 0.30a or earlier, allows remote attackers to send audio to arbitrary channels, aka the "Voices from the deep" bug. | |
| Modificada | Media (5) | 6.4% | 💥 Exploit | Epic Games Unreal Engine | 31/12/2004 | 16/6/2026 | Format string vulnerability in games using the Epic Games Unreal Engine 436 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in class names. | |
| Modificada | Alta (10) | 74% | 💥 Exploit | Arush DevastationDreamforge TNN Outdoors PRO HunterEpic Games Unreal EngineEpic Games Unreal Tournament+10 | 6/12/2004 | 16/6/2026 | The Unreal Engine, as used in DeusEx 1.112fm and earlier, Devastation 390 and earlier, Mobile Forces 20000 and earlier, Nerf Arena Blast 1.2 and earlier, Postal 2 1337 and earlier, Rune 107 and earlier, Tactical Ops 3.4.0 and earlier, Unreal 1 226f and earlier, Unreal II XMP 7710 and earlier, Unreal Tournament 451b… | |
| Modificada | Media (4.6) | 0.89% | 💥 Exploit | Lgames Lbreakout2 | 29/3/2004 | 16/6/2026 | Buffer overflow in lbreakout2 allows local users to gain 'games' group privileges via a large HOME environment variable to (1) editor.c, (2) theme.c, (3) manager.c, (4) config.c, (5) game.c, (6) levels.c, or (7) main.c. | |
| Modificada | Media (5) | 1.7% | — | Fluidgames THE Rage | 23/3/2004 | 16/6/2026 | The Rage 1.01 and earlier allows remote attackers to cause a denial of service (infinite loop) via a TCP packet with the port and IP address set to zero. | |
| Modificada | Alta (7.1) | 5.2% | 💥 Exploit | Epic Games Unreal Engine | 31/12/2003 | 16/6/2026 | Buffer overflow in Epic Games Unreal Engine 226f through 436 allows remote attackers to cause a denial of service (crash) via a long host string in the Unreal URL. | |
| Modificada | Alta (10) | 7.5% | — | Epic Games Unreal EngineEpic Games Unreal Tournament 2003 | 31/12/2003 | 16/6/2026 | Epic Games Unreal Engine 226f through 436 allows remote attackers to cause a denial of service (CPU consumption or crash) and possibly execute arbitrary code via (1) a packet with a negative size value, which is treated as a large positive number during memory allocation, or (2) a negative size value in a package file. | |
| Modificada | Media (5) | 2.8% | 💥 Exploit | Epic Games Unreal Engine | 31/12/2003 | 16/6/2026 | Directory traversal vulnerability in Unreal Tournament Server 436 and earlier allows remote attackers to access known files via a ".." (dot dot) in an unreal:// URL. | |
| Modificada | Media (4.6) | 0.92% | 💥 Exploit | Lgames Ltris | 31/12/2003 | 16/6/2026 | Buffer overflow in LTris 1.0.1 of FreeBSD Ports Collection 2003-02-25 and earlier allows local users to execute arbitrary code with gid "games" permission via a long HOME environment variable. | |
| Modificada | Media (4.3) | 1.2% | — | Epic Games Unreal Engine | 31/12/2003 | 16/6/2026 | Epic Games Unreal Engine 226f through 436 does not validate the challenge key, which allows remote attackers to exhaust the player limit by joining the game multiple times. | |
| Modificada | Media (5) | 6.2% | 💥 Exploit | Gamespy3d Gamespy 3D | 31/12/2003 | 16/6/2026 | Multiple GameSpy 3D 2.62 compatible gaming servers generate very large UDP responses to small requests, which allows remote attackers to use the servers as an amplifier in DDoS attacks with spoofed UDP query packets, as demonstrated using Battlefield 1942. |