Activision's vulnerability profile concentrates in its flagship Call of Duty franchise, a series of widely played multiplayer games whose network connectivity and native codebases expose them to memory-safety and input-validation flaws. Vulnerabilities affecting these titles skew strongly toward critical severity and frequently acquire public exploit code, reflecting both the security-sensitive nature of game engines and the appeal of exploits targeting popular networked entertainment platforms. Current severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Activision over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-10718CRITICAL Stack-based buffer overflow in Activision Infinity Ward Call of Duty Modern Warfare 2 before 2018-04-26 allows remote attackers to execute arbitrary code via crafted packets. | May 3, 2018 | 10.0 | 59 | NO | YES |
CVE-2019-20893CRITICAL An issue was discovered in Activision Infinity Ward Call of Duty Modern Warfare 2 through 2019-12-11. PartyHost_HandleJoinPartyRequest has a buffer overflow vulnerability and can b | Jun 30, 2020 | 9.8 | 32 | NO | NO |
CVE-2018-20817CRITICAL SV_SteamAuthClient in various Activision Infinity Ward Call of Duty games before 2015-08-11 is missing a size check when reading authBlob data into a buffer, which allows one to ex | Apr 19, 2019 | 9.8 | 32 | NO | NO |
CVE-2006-5058HIGH Buffer overflow in (1) Call of Duty 1.5b and earlier, (2) Call of Duty United Offensive 1.51b and earlier, and (3) Call of Duty 2 1.3 and earlier allows remote attackers to execute | Sep 28, 2006 | 7.5 | 32 | NO | YES |
CVE-2008-2106MEDIUM Call of Duty 4 (CoD4) 1.5 and earlier allows remote authenticated users to cause a denial of service (crash) via a type 7 stats packet, which triggers a memcpy with a negative valu | May 7, 2008 | 6.8 | 31 | NO | YES |
CVE-2004-1664MEDIUM Call of Duty 1.4 and earlier allows remote attackers to cause a denial of service (game end) via a large (1) query or (2) reply packet, which is not properly handled by the buffer | Sep 5, 2004 | 5.0 | 25 | NO | YES |
CVE-2012-4918MEDIUM Call of Duty Elite for iOS 2.0.1 does not properly validate the server SSL certificate, which allows remote attackers to obtain sensitive information via a Man-in-the-Middle (MITM) | Jan 22, 2013 | 5.8 | 20 | NO | NO |
CVE-2005-0983MEDIUM Quake 3 engine, as used in multiple games, allows remote attackers to cause a denial of service (client disconnect) via a long message, which is not properly truncated and causes t | May 2, 2005 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Activision.
Media articles that mention a CVE ID that affects a product developed by Activision — matched by CVE ID, not by vendor name.