CVE-2004-1805 is a format string vulnerability affecting games utilizing Epic Games Unreal Engine version 436. This flaw allows remote attackers to trigger a denial of service (crash) and potentially execute arbitrary code by injecting format string specifiers into class names. With a CVSS score of 5.0 and a FAUCET Risk Score of 91/100, it presents a moderate to high risk, requiring no authentication and low attack complexity to achieve a denial of service. While not actively exploited in the wild (no KEV entry), an exploit for Unreal Tournament Server 436.0 exists on ExploitDB, indicating public knowledge of a proof-of-concept. Community discussion and media coverage are minimal, suggesting a low profile despite the available exploit.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
226fCPE matchmatch criteria | cpe:2.3:a:epic_games:unreal_engine:226f:*:*:*:*:*:*:* | ||
433CPE matchmatch criteria | cpe:2.3:a:epic_games:unreal_engine:433:*:*:*:*:*:*:* | ||
436CPE matchmatch criteria | cpe:2.3:a:epic_games:unreal_engine:436:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.