Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
openarena openarena vulnerabilities and exploits
(subscribe to this query)
668
VMScore
CVE-2011-1412
sys/sys_unix.c in the ioQuake3 engine on Unix and Linux, as used in World of Padman 1.5.x prior to 1.5.1.1 and OpenArena 0.8.x-15 and 0.8.x-16, allows remote game servers to execute arbitrary commands via shell metacharacters in a long fs_game variable.
Ioquake3 Ioquake3 Engine
Worldofpadman World Of Padman 1.5
Openarena Openarena 0.8.x-15
Openarena Openarena 0.8.x-16
694
VMScore
CVE-2010-5077
server/sv_main.c in Quake3 Arena, as used in ioquake3 before r1762, OpenArena, Tremulous, and other products, allows remote malicious users to cause a denial of service (network traffic amplification) via a spoofed (1) getstatus or (2) rcon request.
Tremulous Tremulous
Openarena Openarena
Ioquake3 Ioquake3 Engine
890
VMScore
CVE-2011-2764
The FS_CheckFilenameIsNotExecutable function in qcommon/files.c in the ioQuake3 engine 1.36 and previous versions, as used in World of Padman, Smokin' Guns, OpenArena, Tremulous, and ioUrbanTerror, does not properly determine dangerous file extensions, which allows remote ma...
Ioquake3 Ioquake3 Engine 1.36
Worldofpadman World Of Padman
Tremulous Tremulous
Urbanterror Iourbanterror
Ioquake3 Ioquake3 Engine
Smokin-guns Smokin\\' Guns
Openarena Openarena
828
VMScore
CVE-2017-6903
In ioquake3 prior to 2017-03-14, the auto-downloading feature has insufficient content restrictions. This also affects Quake III Arena, OpenArena, OpenJK, iortcw, and other id Tech 3 (aka Quake 3 engine) forks. A malicious auto-downloaded file can trigger loading of crafted auto-...
Ioquake3 Ioquake3
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-5248
CVE-2024-3110
CVE-2024-5552
CVE-2024-29415
HTML injection
CVE-2024-3095
TCP
type confusion
CVE-2024-1800
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started