Even Balance develops anti-cheat systems for online gaming, primarily through its PunkBuster product and associated database components, with a modest vulnerability footprint concentrated in this narrow product line. The durable signal centers on format-string handling issues and related input-control weaknesses characteristic of client-side security enforcement code. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Even Balance over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-26037CRITICAL Directory Traversal vulnerability in Server functionalty in Even Balance Punkbuster version 1.902 before 1.905 allows remote attackers to execute arbitrary code. | Aug 16, 2023 | 9.8 | 30 | NO | NO |
CVE-2006-2587MEDIUM Buffer overflow in the WebTool HTTP server component in (1) PunkBuster before 1.229, as used by multiple products including (2) America's Army 1.228 and earlier, (3) Battlefield 19 | May 25, 2006 | 5.0 | 24 | NO | YES |
CVE-2004-2340HIGH ** UNVERIFIABLE ** SQL injection vulnerability in PunkBuster Screenshot Database (PB-DB) Alpha 6 allows remote attackers to execute arbitrary SQL commands via the username and pas | Dec 31, 2004 | 7.5 | 19 | NO | NO |
CVE-2006-0771MEDIUM Format string vulnerability in PunkBuster 1.180 and earlier, as used by Soldier of Fortune II and possibly other games, allows remote attackers to cause a denial of service (server | Feb 18, 2006 | 6.4 | 18 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Even Balance.
Media articles that mention a CVE ID that affects a product developed by Even Balance — matched by CVE ID, not by vendor name.