Quake 3 Engine

Vendor:

First CVE: Feb 12, 2005 · Active for 21 years

9
Total CVEs
More Total CVEs than 86% of tracked products
4.5
Avg CVEs / Year
Higher CVE frequency than 86% of tracked products
6.4
Avg CVSS
Higher Avg CVSS than 27% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Quake 3 Engine over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 12, 2005
21 years ago
Most Recent CVE
Jul 6, 2006
7,324 days ago

CVE Severity & Scoring

Quake 3 Engine9 CVEs
All CVEs352,427 CVEs
MediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown9 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown9 (100.0%)
User Interaction
None0 (0.0%)
Unknown9 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown9 (100.0%)

Top CVEs

Signals from CVEs in this product scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Stack-based buffer overflow in the CG_ServerCommand function in Quake 3 Engine as used by Soldier of Fortune 2 (SOF2MP) GOLD 1.03 allows remote attackers to cause a denial of servi
Jul 6, 20067.531NOYES
Stack-based buffer overflow in the CL_ParseDownload function of Quake 3 Engine 1.32c and earlier, as used in multiple products, allows remote attackers to execute arbitrary code vi
Jun 7, 20067.531NOYES
Buffer overflow in the Quake 3 Engine, as used by (1) ET 2.60, (2) Return to Castle Wolfenstein 1.41, and (3) Quake III Arena 1.32b allows remote attackers to execute arbitrary com
May 8, 20067.631NOYES
Stack-based buffer overflow in Quake 3 Engine as used by Quake 3: Arena 1.32b and 1.32c allows remote attackers to cause a denial of service and possibly execute code via long CS_I
Jul 6, 20067.530NOYES
The Quake 3 engine, as used in multiple game packages, allows remote attackers to cause a denial of service (shutdown game server) and possibly crash the server via a long infostri
Feb 12, 20055.025NOYES
The Automatic Downloading option in the id3 Quake 3 Engine and the Icculus Quake 3 Engine (ioquake3) before revision 804 allows remote attackers to overwrite arbitrary files in the
Jun 30, 20065.024NOYES
client/cl_parse.c in the id3 Quake 3 Engine 1.32c and the Icculus Quake 3 Engine (ioquake3) revision 810 and earlier allows remote malicious servers to overwrite arbitrary write-pr
Jun 30, 20065.024NOYES
Directory traversal vulnerability in Quake 3 engine, as used in products including Quake3 Arena, Return to Castle Wolfenstein, Wolfenstein: Enemy Territory, and Star Trek Voyager:
May 10, 20067.520NONO
Quake 3 engine, as used in multiple games, allows remote attackers to cause a denial of service (client disconnect) via a long message, which is not properly truncated and causes t
May 2, 20055.015NONO

Exploit Exposure

Signals from CVEs in this product scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
7 CVEs
77.8% of CVEs· 93rd percentile

Social Chatter

Signals from CVEs in this product scope (9 CVEs).

Media Mentions

Signals from CVEs in this product scope (9 CVEs).

Top CNAs Publishing CVEs For Quake 3 Engine

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
icculus_81227.55.2%02
icculus_81015.04.7%01
icculus_80915.04.7%01
icculus_80815.04.7%01
icculus_80715.04.7%01
icculus_80615.04.7%01
icculus_80515.04.7%01
icculus_80425.04.5%02
icculus_80325.04.5%02
1.32c46.34.9%04
1.32b56.55.4%05