Teeworlds is a multiplayer online shooter game whose vulnerability footprint concentrates in a single client-server application and skews strongly toward critical-severity outcomes, reflecting memory-safety and input-handling weaknesses endemic to game engines written in native code. The durable signal centers on a pattern of buffer overflows, integer overflows, improper input validation, and memory-management issues that recur across the application—flaws typical of parsing and network-protocol handling in interactive software where malformed input from untrusted peers can corrupt memory or redirect execution. Defenders deploying or operating this game should prioritize patches from the vendor; current severity, exploitation status, and CVE counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Teeworlds over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-10879CRITICAL In Teeworlds 0.7.2, there is an integer overflow in CDataFileReader::Open() in engine/shared/datafile.cpp that can lead to a buffer overflow and possibly remote code execution, bec | Apr 5, 2019 | 9.8 | 33 | NO | NO |
CVE-2019-10878CRITICAL In Teeworlds 0.7.2, there is a failed bounds check in CDataFileReader::GetData() and CDataFileReader::ReplaceData() and related functions in engine/shared/datafile.cpp that can lea | Apr 5, 2019 | 9.8 | 32 | NO | NO |
CVE-2016-9400CRITICAL The CClient::ProcessServerPacket method in engine/client/client.cpp in Teeworlds before 0.6.4 allows remote servers to write to arbitrary physical memory locations and possibly exe | Feb 22, 2017 | 9.8 | 32 | NO | NO |
CVE-2019-10877CRITICAL In Teeworlds 0.7.2, there is an integer overflow in CMap::Load() in engine/shared/map.cpp that can lead to a buffer overflow, because multiplication of width and height is mishandl | Apr 5, 2019 | 9.8 | 31 | NO | NO |
CVE-2019-20787CRITICAL Teeworlds before 0.7.4 has an integer overflow when computing a tilemap size. | Apr 22, 2020 | 9.8 | 30 | NO | NO |
CVE-2021-43518HIGH Teeworlds up to and including 0.7.5 is vulnerable to Buffer Overflow. A map parser does not validate m_Channels value coming from a map file, leading to a buffer overflow. A malici | Dec 15, 2021 | 7.8 | 26 | NO | NO |
CVE-2023-31517HIGH A memory leak in the component CConsole::Chain of Teeworlds v0.7.5 allows attackers to cause a Denial of Service (DoS) via opening a crafted file. | May 23, 2023 | 7.5 | 25 | NO | NO |
CVE-2018-18541HIGH In Teeworlds before 0.6.5, connection packets could be forged. There was no challenge-response involved in the connection build up. A remote attacker could send connection packets | Oct 20, 2018 | 7.5 | 25 | NO | NO |
CVE-2020-12066HIGH CServer::SendMsg in engine/server/server.cpp in Teeworlds 0.7.x before 0.7.5 allows remote attackers to shut down the server. | Apr 22, 2020 | 7.5 | 20 | NO | NO |
CVE-2023-31518MEDIUM A heap use-after-free in the component CDataFileReader::GetItem of teeworlds v0.7.5 allows attackers to cause a Denial of Service (DoS) via a crafted map file. | May 23, 2023 | 5.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Teeworlds.
Media articles that mention a CVE ID that affects a product developed by Teeworlds — matched by CVE ID, not by vendor name.