Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
tremulous tremulous vulnerabilities and exploits
(subscribe to this query)
7.8
CVSSv2
CVE-2010-5077
server/sv_main.c in Quake3 Arena, as used in ioquake3 before r1762, OpenArena, Tremulous, and other products, allows remote malicious users to cause a denial of service (network traffic amplification) via a spoofed (1) getstatus or (2) rcon request.
Tremulous Tremulous
Openarena Openarena
Ioquake3 Ioquake3 Engine
10
CVSSv2
CVE-2011-3012
The ioQuake3 engine, as used in World of Padman 1.2 and previous versions, Tremulous 1.1.0, and ioUrbanTerror 2007-12-20, does not check for dangerous file extensions before writing to the quake3 directory, which allows remote malicious users to execute arbitrary code via a craft...
Tremulous Tremulous 1.1.0
Urbanterror Iourbanterror 2007-12-20
Ioquake3 Ioquake3 Engine
Worldofpadman World Of Padman
10
CVSSv2
CVE-2011-2764
The FS_CheckFilenameIsNotExecutable function in qcommon/files.c in the ioQuake3 engine 1.36 and previous versions, as used in World of Padman, Smokin' Guns, OpenArena, Tremulous, and ioUrbanTerror, does not properly determine dangerous file extensions, which allows remote ma...
Urbanterror Iourbanterror
Ioquake3 Ioquake3 Engine 1.36
Tremulous Tremulous
Ioquake3 Ioquake3 Engine
Smokin-guns Smokin' Guns
Worldofpadman World Of Padman
Openarena Openarena
7.5
CVSSv2
CVE-2006-2082
Directory traversal vulnerability in Quake 3 engine, as used in products including Quake3 Arena, Return to Castle Wolfenstein, Wolfenstein: Enemy Territory, and Star Trek Voyager: Elite Force, when the sv_allowdownload cvar is enabled, allows remote malicious users to read arbitr...
Id Software Quake 3 Engine
5
CVSSv2
CVE-2006-3324
The Automatic Downloading option in the id3 Quake 3 Engine and the Icculus Quake 3 Engine (ioquake3) before revision 804 allows remote malicious users to overwrite arbitrary files in the quake3 directory (fs_homepath cvar) via a long string of filenames, as contained in the neede...
Id Software Quake 3 Engine Icculus 803
Id Software Quake 3 Engine
Id Software Quake 3 Engine 1.32b
Id Software Quake 3 Engine 1.32c
Id Software Quake 3 Engine Icculus 804
1 EDB exploit
7.5
CVSSv2
CVE-2006-2875
Stack-based buffer overflow in the CL_ParseDownload function of Quake 3 Engine 1.32c and previous versions, as used in multiple products, allows remote malicious users to execute arbitrary code via a svc_download command with compressed data that triggers the overflow during expa...
Id Software Quake 3 Engine
1 EDB exploit
7.6
CVSSv2
CVE-2006-2236
Buffer overflow in the Quake 3 Engine, as used by (1) ET 2.60, (2) Return to Castle Wolfenstein 1.41, and (3) Quake III Arena 1.32b allows remote malicious users to execute arbitrary commands via a long remapShader command.
Id Software Return To Castle Wolfenstein 1.41
Id Software Wolfenstein Enemy Territory 2.60
Id Software Quake 3 Arena 1.32b
Id Software Quake 3 Engine 1.32b
1 EDB exploit
5
CVSSv2
CVE-2006-3325
client/cl_parse.c in the id3 Quake 3 Engine 1.32c and the Icculus Quake 3 Engine (ioquake3) revision 810 and previous versions allows remote malicious servers to overwrite arbitrary write-protected cvars variables on the client, such as cl_allowdownload for Automatic Downloading ...
Id Software Quake 3 Engine Icculus 808
Id Software Quake 3 Engine Icculus 809
Id Software Quake 3 Engine Icculus 807
Id Software Quake 3 Engine Icculus 803
Id Software Quake 3 Engine Icculus 805
Id Software Quake 3 Engine
Id Software Quake 3 Engine 1.32b
Id Software Quake 3 Engine Icculus 806
Id Software Quake 3 Engine Icculus 810
Id Software Quake 3 Engine 1.32c
Id Software Quake 3 Engine Icculus 804
2 EDB exploits
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-5834
CVE-2024-30100
CVE-2024-4577
physical
dos
CVE-2024-30099
CVE-2024-27801
CVE-2024-32146
logic flaw
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started