GameSpy's vulnerability profile centers on gaming infrastructure and authentication components, including the Roger Wilco dedicated and graphical servers and its CD-key validation system, which were widely integrated into competitive and consumer gaming environments. The vendor's disclosures frequently acquire public exploit code, reflecting the appeal of gaming infrastructure as a target for service disruption and credential compromise. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gamespy over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2003-0767HIGH Buffer overflow in RogerWilco graphical server 1.4.1.6 and earlier, dedicated server 0.32a and earlier for Windows, and 0.27 and earlier for Linux and BSD, allows remote attackers | Sep 17, 2003 | 7.5 | 32 | NO | YES |
CVE-2004-2449MEDIUM Roger Wilco 1.4.1.6 and earlier or Roger Wilco Base Station 0.30a and earlier allows remote attackers to cause a denial of service (application crash) via a long, malformed UDP dat | Dec 31, 2004 | 5.0 | 24 | NO | YES |
CVE-2004-2451MEDIUM Roger Wilco 1.4.1.6 and earlier, or Roger Wilco Base Station 0.30a or earlier, allows remote attackers to send audio to arbitrary channels, aka the "Voices from the deep" bug. | Dec 31, 2004 | 5.0 | 23 | NO | YES |
CVE-2003-0650HIGH Directory traversal vulnerability in GSAPAK.EXE for GameSpy Arcade, possibly versions before 1.3e, allows remote attackers to overwrite arbitrary files and execute arbitrary code v | Aug 27, 2003 | 7.5 | 20 | NO | NO |
CVE-2005-1504MEDIUM GameSpy SDK CD-Key Validation Toolkit, as used by many online games, allows remote attackers to bypass the CD key validation by sending a spoofed \disc\ command, which tells the se | May 11, 2005 | 5.0 | 16 | NO | NO |
CVE-2005-1556MEDIUM Gamespy cd-key validation system allows remote attackers to cause a denial of service (cd-key already in use) by capturing and replaying a cd-key authorization session. | May 14, 2005 | 5.0 | 15 | NO | NO |
CVE-2004-2450MEDIUM The client and server for Roger Wilco 1.4.1.6 and earlier or Roger Wilco Base Station 0.30a and earlier report sensitive information such as IDs and source IP addresses, which allo | Dec 31, 2004 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gamespy.
Media articles that mention a CVE ID that affects a product developed by Gamespy — matched by CVE ID, not by vendor name.