Epicgames' vulnerability profile spans its game launcher, Unreal Engine development platform, and published titles, with disclosures centering on command injection, memory-safety issues, and permission-configuration weaknesses. The vendor's exposure reflects the complexity of interactive game engines and runtime systems that parse untrusted content and manage local privilege boundaries. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Epicgames over time
Signals from CVEs in this vendor scope (20 CVEs).
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2004-0608HIGH The Unreal Engine, as used in DeusEx 1.112fm and earlier, Devastation 390 and earlier, Mobile Forces 20000 and earlier, Nerf Arena Blast 1.2 and earlier, Postal 2 1337 and earlier, | Dec 6, 2004 | 10.0 | 81 | NO | YES |
CVE-2003-1431HIGH Buffer overflow in Epic Games Unreal Engine 226f through 436 allows remote attackers to cause a denial of service (crash) via a long host string in the Unreal URL. | Dec 31, 2003 | 7.1 | 35 | NO | YES |
CVE-2008-3409HIGH Buffer overflow in Unreal Tournament 3 1.3beta4 and earlier allows remote attackers to cause a denial of service (memory corruption and daemon crash) or possibly execute arbitrary | Jul 31, 2008 | 7.5 | 33 | NO | YES |
CVE-2003-1432HIGH Epic Games Unreal Engine 226f through 436 allows remote attackers to cause a denial of service (CPU consumption or crash) and possibly execute arbitrary code via (1) a packet with | Dec 31, 2003 | 10.0 | 33 | NO | NO |
CVE-2008-4243HIGH Directory traversal vulnerability in ImageServer (aka UTImageServer) in WebAdmin before 1.7 for Epic Games Unreal Tournament 3 (UT3) 1.3 allows remote attackers to read arbitrary f | Sep 25, 2008 | 7.8 | 30 | NO | YES |
CVE-2018-17707HIGH This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Epic Games Launcher versions prior to 8.2.2. User interaction is required to exp | Jan 24, 2019 | 8.8 | 29 | NO | NO |
CVE-2010-2702HIGH Buffer overflow in the UGameEngine::UpdateConnectingMessage function in the Unreal engine 1, 2, and 2.5, as used in multiple games including Unreal Tournament 2004, Unreal tourname | Jul 12, 2010 | 9.3 | 28 | NO | NO |
CVE-2003-1430MEDIUM Directory traversal vulnerability in Unreal Tournament Server 436 and earlier allows remote attackers to access known files via a ".." (dot dot) in an unreal:// URL. | Dec 31, 2003 | 5.0 | 28 | NO | YES |
CVE-2008-3396MEDIUM Unreal Tournament 2004 (UT2004) 3369 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a certain sequence of malforme | Jul 31, 2008 | 5.0 | 27 | NO | YES |
CVE-2004-1805MEDIUM Format string vulnerability in games using the Epic Games Unreal Engine 436 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via for | Dec 31, 2004 | 5.0 | 25 | NO | YES |
Signals from CVEs in this vendor scope (20 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Epicgames.
Media articles that mention a CVE ID that affects a product developed by Epicgames — matched by CVE ID, not by vendor name.