Id Software's vulnerability footprint centers on a focused set of game engines and multiplayer server products, including the Quake engine lineage and related titles, that have achieved enduring prominence in competitive gaming and custom-server communities. The recurring weakness classes—input validation failures, memory-buffer boundary violations, and format-string issues—reflect the low-level graphics and networking code inherent to these engines and are characteristic of software developed in an era before memory-safety tooling became standard. Public exploit code has frequently materialized for vulnerabilities in this portfolio, consistent with the appeal of these platforms for demonstration, modding, and competitive play where technical depth drives researcher interest. Defenders should account for legacy game servers and client installations that may persist in enterprise networks or remain accessible from the internet; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Id Software over time
Signals from CVEs in this vendor scope (28 CVEs).
28 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-5248HIGH Multiple format string vulnerabilities in the ID Software Doom 3 engine, as used by Doom 3 1.3.1 and earlier, Quake 4 1.4.2 and earlier, and Prey 1.3 and earlier, when Punkbuster ( | Oct 6, 2007 | 9.3 | 36 | NO | YES |
CVE-2006-3400HIGH Stack-based buffer overflow in the CG_ServerCommand function in Quake 3 Engine as used by Soldier of Fortune 2 (SOF2MP) GOLD 1.03 allows remote attackers to cause a denial of servi | Jul 6, 2006 | 7.5 | 31 | NO | YES |
CVE-2006-2875HIGH Stack-based buffer overflow in the CL_ParseDownload function of Quake 3 Engine 1.32c and earlier, as used in multiple products, allows remote attackers to execute arbitrary code vi | Jun 7, 2006 | 7.5 | 31 | NO | YES |
CVE-2006-2236HIGH Buffer overflow in the Quake 3 Engine, as used by (1) ET 2.60, (2) Return to Castle Wolfenstein 1.41, and (3) Quake III Arena 1.32b allows remote attackers to execute arbitrary com | May 8, 2006 | 7.6 | 31 | NO | YES |
CVE-2006-3401HIGH Stack-based buffer overflow in Quake 3 Engine as used by Quake 3: Arena 1.32b and 1.32c allows remote attackers to cause a denial of service and possibly execute code via long CS_I | Jul 6, 2006 | 7.5 | 30 | NO | YES |
CVE-2001-1289MEDIUM Quake 3 arena 1.29f and 1.29g allows remote attackers to cause a denial of service (crash) via a malformed connection packet that begins with several char-255 characters. | Jul 29, 2001 | 5.0 | 29 | NO | YES |
CVE-1999-1569MEDIUM Quake 1 and NetQuake servers allow remote attackers to cause a denial of service (resource exhaustion or forced disconnection) via a flood of spoofed UDP connection packets, which | Jul 17, 2001 | 5.0 | 28 | NO | YES |
CVE-2005-0430MEDIUM The Quake 3 engine, as used in multiple game packages, allows remote attackers to cause a denial of service (shutdown game server) and possibly crash the server via a long infostri | Feb 12, 2005 | 5.0 | 25 | NO | YES |
CVE-2020-15007CRITICAL A buffer overflow in the M_LoadDefaults function in m_misc.c in id Tech 1 (aka Doom engine) allows arbitrary code execution via an unsafe usage of fscanf, because it does not limit | Jun 24, 2020 | 9.8 | 24 | NO | NO |
CVE-2006-3324MEDIUM The Automatic Downloading option in the id3 Quake 3 Engine and the Icculus Quake 3 Engine (ioquake3) before revision 804 allows remote attackers to overwrite arbitrary files in the | Jun 30, 2006 | 5.0 | 24 | NO | YES |
Signals from CVEs in this vendor scope (28 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Id Software.
Media articles that mention a CVE ID that affects a product developed by Id Software — matched by CVE ID, not by vendor name.