Doomsday maintains a narrowly scoped product line centered on a single offering, with its vulnerability surface characterized by memory-safety and code-injection issues typical of systems handling untrusted input or dynamic code generation. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Doomsday over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-4642HIGH Multiple buffer overflows in Doomsday (aka deng) 1.9.0-beta5.1 and earlier allow remote attackers to execute arbitrary code via a long chat (PKT_CHAT) message that is not properly | Aug 31, 2007 | 10.0 | 43 | NO | YES |
CVE-2006-1618HIGH Format string vulnerability in the (1) Con_message and (2) conPrintf functions in con_main.c in Doomsday engine 1.8.6 allows remote attackers to execute arbitrary code via format s | Apr 5, 2006 | 7.5 | 34 | NO | YES |
CVE-2007-4644HIGH Format string vulnerability in the Cl_GetPackets function in cl_main.c in the client in Doomsday (aka deng) 1.9.0-beta5.1 and earlier allows remote Doomsday servers to execute arbi | Aug 31, 2007 | 7.5 | 20 | NO | NO |
CVE-2007-4643MEDIUM Integer underflow in Doomsday (aka deng) 1.9.0-beta5.1 and earlier allows remote attackers to cause a denial of service (daemon crash) via a PKT_CHAT packet with a data length less | Aug 31, 2007 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Doomsday.
Media articles that mention a CVE ID that affects a product developed by Doomsday — matched by CVE ID, not by vendor name.