Nethack is a classic roguelike game that has accumulated a modest but significant vulnerability footprint concentrated in a single product. Its disclosed flaws skew strongly toward critical-severity outcomes and cluster around memory-safety weaknesses—including classic buffer overflows, out-of-bounds reads, and improper memory-bounds restrictions—that are characteristic of long-lived C codebases with permissive parsing logic. Defenders maintaining or distributing Nethack should treat disclosed flaws as high-priority despite the vendor's narrow scope; live severity and exploitation details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nethack over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-19905CRITICAL NetHack 3.6.x before 3.6.4 is prone to a buffer overflow vulnerability when reading very long lines from configuration files. This affects systems that have NetHack installed suid/ | Dec 19, 2019 | 9.8 | 31 | NO | NO |
CVE-2020-5211CRITICAL In NetHack before 3.6.5, an invalid extended command in value for the AUTOCOMPLETE configuration file option can cause a buffer overflow resulting in a crash or remote code executi | Jan 28, 2020 | 9.8 | 30 | NO | NO |
CVE-2020-5212CRITICAL In NetHack before 3.6.5, an extremely long value for the MENUCOLOR configuration file option can cause a buffer overflow resulting in a crash or remote code execution/privilege esc | Jan 28, 2020 | 9.8 | 30 | NO | NO |
CVE-2020-5253CRITICAL NetHack before version 3.6.0 allowed malicious use of escaping of characters in the configuration file (usually .nethackrc) which could be exploited. This bug is patched in NetHack | Mar 10, 2020 | 9.8 | 27 | NO | NO |
CVE-2020-5214CRITICAL In NetHack before 3.6.5, detecting an unknown configuration file option can cause a buffer overflow resulting in a crash or remote code execution/privilege escalation. This vulnera | Jan 28, 2020 | 9.8 | 27 | NO | NO |
CVE-2020-5213CRITICAL In NetHack before 3.6.5, too long of a value for the SYMBOL configuration file option can cause a buffer overflow resulting in a crash or remote code execution/privilege escalation | Jan 28, 2020 | 9.8 | 24 | NO | NO |
CVE-2020-5209HIGH In NetHack before 3.6.5, unknown options starting with -de and -i can cause a buffer overflow resulting in a crash or remote code execution/privilege escalation. This vulnerability | Jan 28, 2020 | 7.8 | 24 | NO | NO |
CVE-2003-0358MEDIUM Buffer overflow in (1) nethack 3.4.0 and earlier, and (2) falconseye 1.9.3 and earlier, which is based on nethack, allows local users to gain privileges via a long -s command line | Jun 9, 2003 | 4.6 | 24 | NO | YES |
CVE-2020-5210HIGH In NetHack before 3.6.5, an invalid argument to the -w command line option can cause a buffer overflow resulting in a crash or remote code execution/privilege escalation. This vuln | Jan 28, 2020 | 7.8 | 23 | NO | NO |
CVE-2020-5254HIGH In NetHack before 3.6.6, some out-of-bound values for the hilite_status option can be exploited. NetHack 3.6.6 resolves this issue. | Mar 10, 2020 | 8.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nethack.
Media articles that mention a CVE ID that affects a product developed by Nethack — matched by CVE ID, not by vendor name.