Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Epic Games

First CVE: Apr 2, 2003Active for: 23 yearsTotal CVEs: 20
37.9
VTI Score
Medium

Epic Games' vulnerability footprint centers on its Unreal Engine graphics and game-development platform alongside gaming products including Unreal Tournament variants and its game launcher, representing a moderately prominent attack surface spanning both developer-tool and end-user contexts. Vulnerabilities affecting the vendor recur through weakness classes including buffer-boundary violations, input-validation gaps, path-traversal conditions, and authentication weaknesses characteristic of large codebases exposed to both untrusted content and user input; the vendor's disclosures have a strong tendency toward public exploit availability. Live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
20
Total CVEs
More Total CVEs than 95% of tracked vendors
0.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 9% of tracked vendors
6.5
Avg CVSS Score
Higher Avg CVSS Score than 29% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Epic Games over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 2, 2003
23 years ago
Most Recent CVE
Dec 12, 2024
589 days ago

Products(6 total)

Top CVEs

Signals from CVEs in this vendor scope (20 CVEs).

20 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2004-0608HIGH
The Unreal Engine, as used in DeusEx 1.112fm and earlier, Devastation 390 and earlier, Mobile Forces 20000 and earlier, Nerf Arena Blast 1.2 and earlier, Postal 2 1337 and earlier,
Dec 6, 200410.081NOYES
CVE-2003-1431HIGH
Buffer overflow in Epic Games Unreal Engine 226f through 436 allows remote attackers to cause a denial of service (crash) via a long host string in the Unreal URL.
Dec 31, 20037.135NOYES
CVE-2008-3409HIGH
Buffer overflow in Unreal Tournament 3 1.3beta4 and earlier allows remote attackers to cause a denial of service (memory corruption and daemon crash) or possibly execute arbitrary
Jul 31, 20087.533NOYES
CVE-2003-1432HIGH
Epic Games Unreal Engine 226f through 436 allows remote attackers to cause a denial of service (CPU consumption or crash) and possibly execute arbitrary code via (1) a packet with
Dec 31, 200310.033NONO
CVE-2008-4243HIGH
Directory traversal vulnerability in ImageServer (aka UTImageServer) in WebAdmin before 1.7 for Epic Games Unreal Tournament 3 (UT3) 1.3 allows remote attackers to read arbitrary f
Sep 25, 20087.830NOYES
CVE-2018-17707HIGH
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Epic Games Launcher versions prior to 8.2.2. User interaction is required to exp
Jan 24, 20198.829NONO
CVE-2010-2702HIGH
Buffer overflow in the UGameEngine::UpdateConnectingMessage function in the Unreal engine 1, 2, and 2.5, as used in multiple games including Unreal Tournament 2004, Unreal tourname
Jul 12, 20109.328NONO
CVE-2003-1430MEDIUM
Directory traversal vulnerability in Unreal Tournament Server 436 and earlier allows remote attackers to access known files via a ".." (dot dot) in an unreal:// URL.
Dec 31, 20035.028NOYES
CVE-2008-3396MEDIUM
Unreal Tournament 2004 (UT2004) 3369 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a certain sequence of malforme
Jul 31, 20085.027NOYES
CVE-2004-1805MEDIUM
Format string vulnerability in games using the Epic Games Unreal Engine 436 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via for
Dec 31, 20045.025NOYES
View all 20 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products20 CVEs
55%
45%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local1 (5.0%)
Network1 (5.0%)
Unknown18 (90.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (10.0%)
High0 (0.0%)
Unknown18 (90.0%)
User Interaction
None1 (5.0%)
Unknown18 (90.0%)
Required1 (5.0%)
Privileges Required
Low1 (5.0%)
High0 (0.0%)
None1 (5.0%)
Unknown18 (90.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (20 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
5.0% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
11 CVEs
55.0% of CVEs· 84th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Epic Games.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Epic Games — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Epic Games's Products

View all 2 CNAs →

Top CWEs