Valve Software's vulnerability exposure centers on its legacy game server and engine products, particularly the Half-Life dedicated server and related titles, which are narrowly scoped but retain a meaningful presence among long-running online gaming infrastructure. The recurring weakness classes span buffer boundary violations and cross-site scripting issues that arise from the age and architecture of these applications. Live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Valve Software over time
Signals from CVEs in this vendor scope (40 CVEs).
40 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-15943HIGH vphysics.dll in Counter-Strike: Global Offensive before 1.37.1.1 allows remote attackers to achieve code execution or denial of service by creating a gaming server and inviting a v | Sep 19, 2019 | 8.8 | 43 | NO | YES |
CVE-2020-7949HIGH schemasystem.dll in Valve Dota 2 before 7.23f allows remote attackers to achieve code execution or denial of service by creating a gaming server and inviting a victim to this serve | Jan 27, 2020 | 7.8 | 36 | NO | YES |
CVE-2015-7985HIGH Valve Steam 2.10.91.91 uses weak permissions (Users: read and write) for the Install folder, which allows local users to gain privileges via a Trojan horse steam.exe file. | Nov 24, 2015 | 7.2 | 35 | NO | YES |
CVE-2021-30481CRITICAL Valve Steam before 2021-04-17, when a Source engine game is installed, allows remote authenticated users to execute arbitrary code because of a buffer overflow that occurs for a St | Apr 10, 2021 | 9.0 | 31 | NO | NO |
CVE-2023-35855CRITICAL A buffer overflow in Counter-Strike through 8684 allows a game server to execute arbitrary code on a remote client's machine by modifying the lservercfgfile console variable. | Jun 19, 2023 | 9.8 | 30 | NO | NO |
CVE-2017-17877CRITICAL An issue was discovered in Valve Steam Link build 643. When the SSH daemon is enabled for local development, the device is publicly available via IPv6 TCP port 22 over the internet | Dec 27, 2017 | 9.8 | 30 | NO | NO |
CVE-2020-6017CRITICAL Valve's Game Networking Sockets prior to version v1.2.0 improperly handles long unreliable segments in function SNP_ReceiveUnreliableSegment() when configured to support plain-text | Dec 3, 2020 | 9.8 | 29 | NO | NO |
CVE-2020-12242HIGH Valve Source allows local users to gain privileges by writing to the /tmp/hl2_relaunch file, which is later executed in the context of a different user account. | Apr 27, 2020 | 7.8 | 29 | NO | YES |
CVE-2003-1325MEDIUM The SV_CheckForDuplicateNames function in Valve Software Half-Life CSTRIKE Dedicated Server 1.1.1.0 and earlier allows remote authenticated users to cause a denial of service (infi | Dec 31, 2003 | 5.2 | 29 | NO | YES |
CVE-2017-17878CRITICAL An issue was discovered in Valve Steam Link build 643. Root passwords longer than 8 characters are truncated because of the default use of DES (aka the CONFIG_FEATURE_DEFAULT_PASSW | Dec 27, 2017 | 9.8 | 28 | NO | NO |
Signals from CVEs in this vendor scope (40 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Valve Software.
Media articles that mention a CVE ID that affects a product developed by Valve Software — matched by CVE ID, not by vendor name.