Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2557▼ 320 respecto a la semana anterior
Críticas / altas1342▲ 78 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
38 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 2.3% | — | Quake3e Project Quake3e | 16/7/2019 | 17/6/2026 | Quake3e < 5ed740d is affected by: Buffer Overflow. The impact is: Possible code execution and denial of service. The component is: Argument string creation. | |
| Modificada | Crítica (9.8) | 2.5% | — | Ioquake3 | 3/8/2017 | 17/6/2026 | Buffer overflow in ioquake3 before 2017-08-02 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted packet. | |
| Modificada | Alta (7.8) | 1.3% | — | Ioquake3 | 14/3/2017 | 17/6/2026 | In ioquake3 before 2017-03-14, the auto-downloading feature has insufficient content restrictions. This also affects Quake III Arena, OpenArena, OpenJK, iortcw, and other id Tech 3 (aka Quake 3 engine) forks. A malicious auto-downloaded file can trigger loading of crafted auto-downloaded files as native code DLLs. A… | |
| Modificada | Alta (7.8) | 2.1% | — | Ioquake3 EngineOpenarenaTremulous | 27/10/2014 | 16/6/2026 | server/sv_main.c in Quake3 Arena, as used in ioquake3 before r1762, OpenArena, Tremulous, and other products, allows remote attackers to cause a denial of service (network traffic amplification) via a spoofed (1) getstatus or (2) rcon request. | |
| Modificada | Media (5.6) | 0.29% | — | Ioquake3 Engine | 15/6/2012 | 16/6/2026 | ioquake3 before r2253 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/ioq3.pid temporary file. | |
| Modificada | Alta (10) | 8.0% | — | Ioquake3 EngineTremulousIourbanterrorWorldofpadman World OF Padman | 9/8/2011 | 16/6/2026 | The ioQuake3 engine, as used in World of Padman 1.2 and earlier, Tremulous 1.1.0, and ioUrbanTerror 2007-12-20, does not check for dangerous file extensions before writing to the quake3 directory, which allows remote attackers to execute arbitrary code via a crafted third-party addon that creates a Trojan horse DLL… | |
| Modificada | Alta (10) | 8.7% | — | Ioquake3 EngineOpenarenaSmokin-guns Smokin' GunsTremulous+2 | 4/8/2011 | 16/6/2026 | The FS_CheckFilenameIsNotExecutable function in qcommon/files.c in the ioQuake3 engine 1.36 and earlier, as used in World of Padman, Smokin' Guns, OpenArena, Tremulous, and ioUrbanTerror, does not properly determine dangerous file extensions, which allows remote attackers to execute arbitrary code via a crafted… | |
| Modificada | Alta (7.5) | 4.2% | — | Ioquake3 EngineOpenarenaWorldofpadman World OF Padman | 4/8/2011 | 16/6/2026 | sys/sys_unix.c in the ioQuake3 engine on Unix and Linux, as used in World of Padman 1.5.x before 1.5.1.1 and OpenArena 0.8.x-15 and 0.8.x-16, allows remote game servers to execute arbitrary commands via shell metacharacters in a long fs_game variable. | |
| Modificada | Media (5) | 5.2% | — | IrcuQuakenet Snircd | 25/3/2008 | 16/6/2026 | The send_user_mode function in s_user.c in (1) Undernet ircu 2.10.12.12 and earlier, (2) snircd 1.3.4 and earlier, and unspecified other ircu derivatives allows remote attackers to cause a denial of service (daemon crash) via a malformed MODE command. | |
| Modificada | Alta (9.3) | 7.5% | — | ID Software Doom 3ID Software Quake 4Take2games Prey | 6/10/2007 | 16/6/2026 | Multiple format string vulnerabilities in the ID Software Doom 3 engine, as used by Doom 3 1.3.1 and earlier, Quake 4 1.4.2 and earlier, and Prey 1.3 and earlier, when Punkbuster (PB) is enabled, allow remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via format string specifiers… | |
| Modificada | Alta (7.5) | 4.8% | — | ID Software Quake 3 EngineRaven Software Soldier OF Fortune 2 | 6/7/2006 | 16/6/2026 | Stack-based buffer overflow in the CG_ServerCommand function in Quake 3 Engine as used by Soldier of Fortune 2 (SOF2MP) GOLD 1.03 allows remote attackers to cause a denial of service and possibly execute code by sending a long command from the server. | |
| Modificada | Alta (7.5) | 5.7% | — | ID Software Quake 3 Engine | 6/7/2006 | 16/6/2026 | Stack-based buffer overflow in Quake 3 Engine as used by Quake 3: Arena 1.32b and 1.32c allows remote attackers to cause a denial of service and possibly execute code via long CS_ITEMS values. | |
| Modificada | Media (5) | 4.4% | — | ID Software Quake 3 Engine | 30/6/2006 | 16/6/2026 | The Automatic Downloading option in the id3 Quake 3 Engine and the Icculus Quake 3 Engine (ioquake3) before revision 804 allows remote attackers to overwrite arbitrary files in the quake3 directory (fs_homepath cvar) via a long string of filenames, as contained in the neededpaks buffer. | |
| Modificada | Media (5) | 4.8% | — | ID Software Quake 3 Engine | 30/6/2006 | 16/6/2026 | client/cl_parse.c in the id3 Quake 3 Engine 1.32c and the Icculus Quake 3 Engine (ioquake3) revision 810 and earlier allows remote malicious servers to overwrite arbitrary write-protected cvars variables on the client, such as cl_allowdownload for Automatic Downloading and fs_homepath for the quake3 path, via a string… | |
| Modificada | Alta (7.5) | 6.8% | — | ID Software Quake 3 Engine | 7/6/2006 | 16/6/2026 | Stack-based buffer overflow in the CL_ParseDownload function of Quake 3 Engine 1.32c and earlier, as used in multiple products, allows remote attackers to execute arbitrary code via a svc_download command with compressed data that triggers the overflow during expansion. | |
| Modificada | Alta (7.5) | 2.6% | — | ID Software Quake 3 Engine | 10/5/2006 | 16/6/2026 | Directory traversal vulnerability in Quake 3 engine, as used in products including Quake3 Arena, Return to Castle Wolfenstein, Wolfenstein: Enemy Territory, and Star Trek Voyager: Elite Force, when the sv_allowdownload cvar is enabled, allows remote attackers to read arbitrary files from the server via ".." sequences… | |
| Modificada | Alta (7.6) | 7.6% | — | ID Software Quake 3 ArenaID Software Quake 3 EngineID Software Return TO Castle WolfensteinID Software Wolfenstein Enemy Territory | 8/5/2006 | 16/6/2026 | Buffer overflow in the Quake 3 Engine, as used by (1) ET 2.60, (2) Return to Castle Wolfenstein 1.41, and (3) Quake III Arena 1.32b allows remote attackers to execute arbitrary commands via a long remapShader command. | |
| Modificada | Media (5) | 2.6% | — | Activision Call OF DutyActivision Call OF Duty United OffensiveActivision Return TO Castle WolfensteinID Software Quake 3 Arena+6 | 2/5/2005 | 16/6/2026 | Quake 3 engine, as used in multiple games, allows remote attackers to cause a denial of service (client disconnect) via a long message, which is not properly truncated and causes the engine to process the remaining data as if it were network data. | |
| Modificada | Media (5) | 7.5% | — | ID Software Quake 3 Engine | 12/2/2005 | 16/6/2026 | The Quake 3 engine, as used in multiple game packages, allows remote attackers to cause a denial of service (shutdown game server) and possibly crash the server via a long infostring, possibly triggering a buffer overflow. | |
| Modificada | Media (5) | 1.8% | — | ID Software Quake II Server Windows | 31/12/2004 | 16/6/2026 | Absolute path traversal vulnerability in Quake II server before R1Q2 on Windows, as used in multiple products, allows remote attackers to read arbitrary files via a "\/" in a pathname argument, as demonstrated by "download \/server.cfg". | |
| Modificada | Media (5) | 3.7% | — | ID Software Quake II Server | 31/12/2004 | 16/6/2026 | Quake II server before R1Q2, as used in multiple products, allows remote attackers to cause a denial of service (application crash) via a modified client that asks the server to send data stored at a negative array offset, which is not handled when processing Configstrings and Baselines. | |
| Modificada | Media (5) | 2.8% | — | ID Software Quake II Server Linux | 31/12/2004 | 16/6/2026 | Absolute path traversal vulnerability in Quake II server before R1Q2 on Linux, as used in multiple products, allows remote attackers to cause a denial of service (application crash) via a download command with a full pathname for a directory in the argument, which causes the server to crash when it cannot read data. | |
| Modificada | Baja (2.1) | 0.39% | — | Quake IIAIR1q2AI | 31/12/2004 | 16/6/2026 | Multiple buffer overflows in Quake II server before R1Q2, as used in multiple products, allow local users to cause a denial of service (application crash) via the server console or rcon. | |
| Modificada | Alta (7.5) | 3.8% | — | ID Software Quake II Server | 31/12/2004 | 16/6/2026 | Buffer overflow in command-packet processing of Quake II server before R1Q2, as used in multiple products, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a packet with a long cmd_args buffer. | |
| Modificada | Media (5) | 1.9% | — | ID Software Quake II Server | 31/12/2004 | 16/6/2026 | Quake II server before R1Q2, as used in multiple products, allows remote attackers to cause a denial of service (exhaustion of connection slots) via a large number of connections from the same IP address. |