Toribash is an indie physics-based fighting game with a modestly represented vulnerability footprint centered on its single core product. The recurring disclosures involve input-validation and unclassified weaknesses, typical of game engines that parse player actions and network traffic; vulnerabilities in this product frequently acquire public exploit code. Current severity, exploitation activity, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Toribash over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-4446HIGH Format string vulnerability in the server in Toribash 2.71 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the NICK command (client ni | Aug 21, 2007 | 7.5 | 29 | NO | YES |
CVE-2007-4447HIGH Multiple buffer overflows in the client in Toribash 2.71 and earlier allow remote attackers to (1) execute arbitrary code via a long game command in a replay (.rpl) file and (2) ca | Aug 21, 2007 | 7.5 | 20 | NO | NO |
CVE-2007-4451MEDIUM The server in Toribash 2.71 and earlier on Windows allows remote attackers to cause a denial of service (continuous beep and server hang) via certain commands that contain many 0x0 | Aug 21, 2007 | 5.0 | 16 | NO | NO |
CVE-2007-4448MEDIUM The server in Toribash 2.71 and earlier does not properly handle partially joined clients that are temporarily assigned the ID of -1, which allows remote attackers to cause a denia | Aug 21, 2007 | 5.0 | 15 | NO | NO |
CVE-2007-4449MEDIUM The client in Toribash 2.71 and earlier allows remote attackers to cause a denial of service (application hang) via a command without an LF character, as demonstrated by a SAY comm | Aug 21, 2007 | 5.0 | 15 | NO | NO |
CVE-2007-4450MEDIUM The server in Toribash 2.71 and earlier does not properly handle long commands, which allows remote attackers to trigger a protocol violation in which data is sent to other clients | Aug 21, 2007 | 5.0 | 15 | NO | NO |
CVE-2007-4452MEDIUM The client in Toribash 2.71 and earlier allows remote attackers to cause a denial of service (disconnection) via a long (1) emote or (2) SPEC command. | Aug 21, 2007 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Toribash.
Media articles that mention a CVE ID that affects a product developed by Toribash — matched by CVE ID, not by vendor name.