Epic Games' vulnerability footprint centers on its Unreal Engine graphics and game-development platform alongside gaming products including Unreal Tournament variants and its game launcher, representing a moderately prominent attack surface spanning both developer-tool and end-user contexts. Vulnerabilities affecting the vendor recur through weakness classes including buffer-boundary violations, input-validation gaps, path-traversal conditions, and authentication weaknesses characteristic of large codebases exposed to both untrusted content and user input; the vendor's disclosures have a strong tendency toward public exploit availability. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Epic Games over time
Signals from CVEs in this vendor scope (20 CVEs).
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2004-0608HIGH The Unreal Engine, as used in DeusEx 1.112fm and earlier, Devastation 390 and earlier, Mobile Forces 20000 and earlier, Nerf Arena Blast 1.2 and earlier, Postal 2 1337 and earlier, | Dec 6, 2004 | 10.0 | 81 | NO | YES |
CVE-2003-1431HIGH Buffer overflow in Epic Games Unreal Engine 226f through 436 allows remote attackers to cause a denial of service (crash) via a long host string in the Unreal URL. | Dec 31, 2003 | 7.1 | 35 | NO | YES |
CVE-2008-3409HIGH Buffer overflow in Unreal Tournament 3 1.3beta4 and earlier allows remote attackers to cause a denial of service (memory corruption and daemon crash) or possibly execute arbitrary | Jul 31, 2008 | 7.5 | 33 | NO | YES |
CVE-2003-1432HIGH Epic Games Unreal Engine 226f through 436 allows remote attackers to cause a denial of service (CPU consumption or crash) and possibly execute arbitrary code via (1) a packet with | Dec 31, 2003 | 10.0 | 33 | NO | NO |
CVE-2008-4243HIGH Directory traversal vulnerability in ImageServer (aka UTImageServer) in WebAdmin before 1.7 for Epic Games Unreal Tournament 3 (UT3) 1.3 allows remote attackers to read arbitrary f | Sep 25, 2008 | 7.8 | 30 | NO | YES |
CVE-2018-17707HIGH This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Epic Games Launcher versions prior to 8.2.2. User interaction is required to exp | Jan 24, 2019 | 8.8 | 29 | NO | NO |
CVE-2010-2702HIGH Buffer overflow in the UGameEngine::UpdateConnectingMessage function in the Unreal engine 1, 2, and 2.5, as used in multiple games including Unreal Tournament 2004, Unreal tourname | Jul 12, 2010 | 9.3 | 28 | NO | NO |
CVE-2003-1430MEDIUM Directory traversal vulnerability in Unreal Tournament Server 436 and earlier allows remote attackers to access known files via a ".." (dot dot) in an unreal:// URL. | Dec 31, 2003 | 5.0 | 28 | NO | YES |
CVE-2008-3396MEDIUM Unreal Tournament 2004 (UT2004) 3369 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a certain sequence of malforme | Jul 31, 2008 | 5.0 | 27 | NO | YES |
CVE-2004-1805MEDIUM Format string vulnerability in games using the Epic Games Unreal Engine 436 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via for | Dec 31, 2004 | 5.0 | 25 | NO | YES |
Signals from CVEs in this vendor scope (20 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Epic Games.
Media articles that mention a CVE ID that affects a product developed by Epic Games — matched by CVE ID, not by vendor name.