Raven Software's vulnerability profile centers on its legacy Soldier of Fortune game franchise, a narrowly scoped but historically notable product line. Vulnerabilities affecting these titles have recurred through memory-safety issues such as buffer boundary violations and frequently acquire public exploit code, reflecting the attack surface of aging game engines. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Raven Software over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-3400HIGH Stack-based buffer overflow in the CG_ServerCommand function in Quake 3 Engine as used by Soldier of Fortune 2 (SOF2MP) GOLD 1.03 allows remote attackers to cause a denial of servi | Jul 6, 2006 | 7.5 | 31 | NO | YES |
CVE-2004-1542MEDIUM Buffer overflow in Soldier of Fortune II 1.03 Gold and earlier allows remote attackers to cause a denial of service (server or client crash) via a long (1) query or (2) reply. | Dec 31, 2004 | 5.0 | 29 | NO | YES |
CVE-2009-3924HIGH Buffer overflow in pbsv.dll, as used in Soldier of Fortune II and possibly other applications when Even Balance PunkBuster 1.728 or earlier is enabled, allows remote attackers to c | Nov 10, 2009 | 9.3 | 26 | NO | NO |
CVE-2005-0568MEDIUM Soldier of Fortune II 1.03 gold allows remote attackers to cause a denial of service (application crash) via a large cl_guid value, which results in an invalid pointer dereference. | May 2, 2005 | 5.0 | 23 | NO | YES |
CVE-2005-2115MEDIUM Soldier of Fortune II 1.02x and 1.03 allows remote attackers to cause a denial of service (server crash) via a large ID value in the ignore command, which is used as an array index | Jul 5, 2005 | 5.0 | 15 | NO | NO |
CVE-2005-0983MEDIUM Quake 3 engine, as used in multiple games, allows remote attackers to cause a denial of service (client disconnect) via a long message, which is not properly truncated and causes t | May 2, 2005 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Raven Software.
Media articles that mention a CVE ID that affects a product developed by Raven Software — matched by CVE ID, not by vendor name.