America's Army maintains a small portfolio of military-themed online games and training applications, with its vulnerability footprint concentrated in the core game client and related proving-ground components. The observed weakness classes center on improper input validation and buffer-boundary handling, typical of interactive game software processing untrusted player input. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Americasarmy over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-10531HIGH An issue was discovered in the America's Army Proving Grounds platform for the Unreal Engine. With a false packet sent via UDP, the application server responds with several bytes, | Jul 10, 2019 | 7.5 | 19 | NO | NO |
CVE-2008-3492MEDIUM America's Army (aka AA or Army Game Project) 2.8.3.1 and earlier allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted UDP packet, | Aug 6, 2008 | 5.0 | 15 | NO | NO |
CVE-2007-5249MEDIUM Multiple buffer overflows in the logging function in the Unreal engine, as used by America's Army and America's Army Special Forces 2.8.2 and earlier, when Punkbuster (PB) is enabl | Oct 6, 2007 | 4.3 | 14 | NO | NO |
CVE-2007-5250MEDIUM The Windows dedicated server for the Unreal engine, as used by America's Army and America's Army Special Forces 2.8.2 and earlier, when Punkbuster (PB) is enabled, allows remote at | Oct 6, 2007 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Americasarmy.
Media articles that mention a CVE ID that affects a product developed by Americasarmy — matched by CVE ID, not by vendor name.