Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Nethack

First CVE: Jun 9, 2003Active for: 23 yearsTotal CVEs: 11
51.1
VTI Score
TOP TARGET

Nethack is a classic roguelike game that has accumulated a modest but significant vulnerability footprint concentrated in a single product. Its disclosed flaws skew strongly toward critical-severity outcomes and cluster around memory-safety weaknesses—including classic buffer overflows, out-of-bounds reads, and improper memory-bounds restrictions—that are characteristic of long-lived C codebases with permissive parsing logic. Defenders maintaining or distributing Nethack should treat disclosed flaws as high-priority despite the vendor's narrow scope; live severity and exploitation details are shown alongside this summary.

FAUCET AI Generated
11
Total CVEs
More Total CVEs than 92% of tracked vendors
2.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
8.4
Avg CVSS Score
Higher Avg CVSS Score than 82% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Nethack over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 9, 2003
23 years ago
Most Recent CVE
Feb 17, 2023
1,253 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (11 CVEs).

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-19905CRITICAL
NetHack 3.6.x before 3.6.4 is prone to a buffer overflow vulnerability when reading very long lines from configuration files. This affects systems that have NetHack installed suid/
Dec 19, 20199.831NONO
CVE-2020-5211CRITICAL
In NetHack before 3.6.5, an invalid extended command in value for the AUTOCOMPLETE configuration file option can cause a buffer overflow resulting in a crash or remote code executi
Jan 28, 20209.830NONO
CVE-2020-5212CRITICAL
In NetHack before 3.6.5, an extremely long value for the MENUCOLOR configuration file option can cause a buffer overflow resulting in a crash or remote code execution/privilege esc
Jan 28, 20209.830NONO
CVE-2020-5253CRITICAL
NetHack before version 3.6.0 allowed malicious use of escaping of characters in the configuration file (usually .nethackrc) which could be exploited. This bug is patched in NetHack
Mar 10, 20209.827NONO
CVE-2020-5214CRITICAL
In NetHack before 3.6.5, detecting an unknown configuration file option can cause a buffer overflow resulting in a crash or remote code execution/privilege escalation. This vulnera
Jan 28, 20209.827NONO
CVE-2020-5213CRITICAL
In NetHack before 3.6.5, too long of a value for the SYMBOL configuration file option can cause a buffer overflow resulting in a crash or remote code execution/privilege escalation
Jan 28, 20209.824NONO
CVE-2020-5209HIGH
In NetHack before 3.6.5, unknown options starting with -de and -i can cause a buffer overflow resulting in a crash or remote code execution/privilege escalation. This vulnerability
Jan 28, 20207.824NONO
CVE-2003-0358MEDIUM
Buffer overflow in (1) nethack 3.4.0 and earlier, and (2) falconseye 1.9.3 and earlier, which is based on nethack, allows local users to gain privileges via a long -s command line
Jun 9, 20034.624NOYES
CVE-2020-5210HIGH
In NetHack before 3.6.5, an invalid argument to the -w command line option can cause a buffer overflow resulting in a crash or remote code execution/privilege escalation. This vuln
Jan 28, 20207.823NONO
CVE-2020-5254HIGH
In NetHack before 3.6.6, some out-of-bound values for the hilite_status option can be exploited. NetHack 3.6.6 resolves this issue.
Mar 10, 20208.120NONO
View all 11 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products11 CVEs
18%
27%
55%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local3 (27.3%)
Network7 (63.6%)
Unknown1 (9.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (81.8%)
High1 (9.1%)
Unknown1 (9.1%)
User Interaction
None10 (90.9%)
Unknown1 (9.1%)
Required0 (0.0%)
Privileges Required
Low3 (27.3%)
High0 (0.0%)
None7 (63.6%)
Unknown1 (9.1%)

Exploit Exposure

Signals from CVEs in this vendor scope (11 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
9.1% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Nethack.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Nethack — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Nethack's Products

View all 2 CNAs →

Top CWEs