Ufo2000 is a niche turn-based tactical game project with a minimal vulnerability footprint concentrated in the game application itself. The disclosed weaknesses are classified broadly and do not yet indicate a pattern that would characterize the vendor's security profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ufo2000 over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-3788HIGH Multiple buffer overflows in multiplay.cpp in UFO2000 svn 1057 allow remote attackers to execute arbitrary code via (1) a long unit name in Net::recv_add_unit,; (2) large values to | Jul 24, 2006 | 7.5 | 21 | NO | NO |
CVE-2006-3789HIGH Multiple array index errors in the (1) recv_rules, (2) recv_select_unit, (3) recv_options, and (4) recv_unit_data functions in multiplay.cpp in UFO2000 svn 1057 allow remote attack | Jul 24, 2006 | 7.5 | 20 | NO | NO |
CVE-2006-3792HIGH SQL injection vulnerability in ServerClientUfo::recv_packet in server_protocol.cpp in UFO2000 svn 1057 allows remote attackers to execute arbitrary SQL commands via unspecified vec | Jul 24, 2006 | 7.5 | 20 | NO | NO |
CVE-2006-3790MEDIUM The decode_stringmap function in server_transport.cpp for UFO2000 svn 1057 allows remote attackers to cause a denial of service (daemon termination) via a keysize or valsize that i | Jul 24, 2006 | 5.0 | 15 | NO | NO |
CVE-2006-3791MEDIUM The decode_stringmap function in server_transport.cpp for UFO2000 svn 1057 allows remote attackers to cause a denial of service (daemon termination) via a large keysize or valsize, | Jul 24, 2006 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ufo2000.
Media articles that mention a CVE ID that affects a product developed by Ufo2000 — matched by CVE ID, not by vendor name.