Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
ioquake3 ioquake3 vulnerabilities and exploits
(subscribe to this query)
7.8
CVSSv3
CVE-2017-6903
In ioquake3 prior to 2017-03-14, the auto-downloading feature has insufficient content restrictions. This also affects Quake III Arena, OpenArena, OpenJK, iortcw, and other id Tech 3 (aka Quake 3 engine) forks. A malicious auto-downloaded file can trigger loading of crafted auto-...
Ioquake3 Ioquake3
9.8
CVSSv3
CVE-2017-11721
Buffer overflow in ioquake3 prior to 2017-08-02 allows remote malicious users to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted packet.
Ioquake3 Ioquake3
NA
CVE-2012-3345
ioquake3 before r2253 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/ioq3.pid temporary file.
Ioquake3 Ioquake3 Engine
NA
CVE-2011-2764
The FS_CheckFilenameIsNotExecutable function in qcommon/files.c in the ioQuake3 engine 1.36 and previous versions, as used in World of Padman, Smokin' Guns, OpenArena, Tremulous, and ioUrbanTerror, does not properly determine dangerous file extensions, which allows remote ma...
Ioquake3 Ioquake3 Engine 1.36
Worldofpadman World Of Padman
Tremulous Tremulous
Urbanterror Iourbanterror
Ioquake3 Ioquake3 Engine
Smokin-guns Smokin\\' Guns
Openarena Openarena
NA
CVE-2010-5077
server/sv_main.c in Quake3 Arena, as used in ioquake3 before r1762, OpenArena, Tremulous, and other products, allows remote malicious users to cause a denial of service (network traffic amplification) via a spoofed (1) getstatus or (2) rcon request.
Tremulous Tremulous
Openarena Openarena
Ioquake3 Ioquake3 Engine
NA
CVE-2011-3012
The ioQuake3 engine, as used in World of Padman 1.2 and previous versions, Tremulous 1.1.0, and ioUrbanTerror 2007-12-20, does not check for dangerous file extensions before writing to the quake3 directory, which allows remote malicious users to execute arbitrary code via a craft...
Worldofpadman World Of Padman
Ioquake3 Ioquake3 Engine
Tremulous Tremulous 1.1.0
Urbanterror Iourbanterror 2007-12-20
NA
CVE-2011-1412
sys/sys_unix.c in the ioQuake3 engine on Unix and Linux, as used in World of Padman 1.5.x prior to 1.5.1.1 and OpenArena 0.8.x-15 and 0.8.x-16, allows remote game servers to execute arbitrary commands via shell metacharacters in a long fs_game variable.
Ioquake3 Ioquake3 Engine
Worldofpadman World Of Padman 1.5
Openarena Openarena 0.8.x-15
Openarena Openarena 0.8.x-16
NA
CVE-2006-3324
The Automatic Downloading option in the id3 Quake 3 Engine and the Icculus Quake 3 Engine (ioquake3) before revision 804 allows remote malicious users to overwrite arbitrary files in the quake3 directory (fs_homepath cvar) via a long string of filenames, as contained in the neede...
Id Software Quake 3 Engine 1.32c
Id Software Quake 3 Engine Icculus 803
Id Software Quake 3 Engine
Id Software Quake 3 Engine 1.32b
Id Software Quake 3 Engine Icculus 804
1 EDB exploit
NA
CVE-2006-3325
client/cl_parse.c in the id3 Quake 3 Engine 1.32c and the Icculus Quake 3 Engine (ioquake3) revision 810 and previous versions allows remote malicious servers to overwrite arbitrary write-protected cvars variables on the client, such as cl_allowdownload for Automatic Downloading ...
Id Software Quake 3 Engine Icculus 804
Id Software Quake 3 Engine Icculus 805
Id Software Quake 3 Engine 1.32c
Id Software Quake 3 Engine Icculus 803
Id Software Quake 3 Engine Icculus 810
Id Software Quake 3 Engine
Id Software Quake 3 Engine 1.32b
Id Software Quake 3 Engine Icculus 808
Id Software Quake 3 Engine Icculus 809
Id Software Quake 3 Engine Icculus 806
Id Software Quake 3 Engine Icculus 807
2 EDB exploits
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-33572
CVE-2024-24919
CVE-2024-0230
CVE-2024-32714
HTML injection
local file inclusion
CVE-2024-31098
CVE-2024-31244
privilege
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started