Cor Entertainment's vulnerability footprint centers on the Alien Arena game series, a niche multiplayer shooter with a narrow but persistent product scope. The recurring weakness classes—format string mishandling and improper input validation—reflect the parsing demands of network game protocols and user-supplied content, attack surfaces inherent to multiplayer game engines. Public exploit code has been developed for vulnerabilities in this vendor's products; live severity, exploitation activity, and current exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cor Entertainment over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-4754HIGH Format string vulnerability in the safe_bprintf function in acesrc/acebot_cmds.c in Alien Arena 2007 6.10 and earlier allows remote attackers to cause a denial of service (daemon c | Sep 8, 2007 | 7.5 | 30 | NO | YES |
CVE-2006-1145MEDIUM Format string vulnerability in the safe_cprintf function in acebot_cmds.c in Alien Arena 2006 Gold Edition 5.00 allows remote attackers (possibly authenticated) to execute arbitrar | Mar 10, 2006 | 6.5 | 27 | NO | YES |
CVE-2006-1146MEDIUM Stack-based buffer overflow in the Cmd_Say_f function in g_cmds.c in Alien Arena 2006 Gold Edition 5.00 allows remote attackers (possibly authenticated) to execute arbitrary code b | Mar 10, 2006 | 6.5 | 27 | NO | YES |
CVE-2010-3439MEDIUM It is possible to cause a DoS condition by causing the server to crash in alien-arena 7.33 by supplying various invalid parameters to the download command. | Nov 12, 2019 | 6.5 | 22 | NO | NO |
CVE-2006-1147MEDIUM The Com_sprintf function in q_shared.c in Alien Arena 2006 Gold Edition 5.00 does not properly NULL terminate certain long strings, which allows remote attackers (possibly authenti | Mar 10, 2006 | 4.0 | 21 | NO | YES |
CVE-2007-4755MEDIUM Alien Arena 2007 6.10 and earlier allows remote attackers to cause a denial of service (client disconnect) by sending a client_connect command in a forged packet from the server to | Sep 8, 2007 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cor Entertainment.
Media articles that mention a CVE ID that affects a product developed by Cor Entertainment — matched by CVE ID, not by vendor name.