Half Life Dedicated Server
Vendor:
First CVE: Dec 19, 2000 · Active for 25 years
7
Total CVEs
More Total CVEs than 85% of tracked products
1.4
Avg CVEs / Year
Higher CVE frequency than 59% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 45% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Half Life Dedicated Server over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 19, 2000
25 years ago
Most Recent CVE
Oct 30, 2007
6,846 days ago
CVE Severity & Scoring
Half Life Dedicated Server7 CVEs
43%
57%
All CVEs353,173 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown7 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown7 (100.0%)
User Interaction
None0 (0.0%)
Unknown7 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown7 (100.0%)
Top CVEs
Signals from CVEs in this product scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2000-0968HIGH Buffer overflow in Half Life dedicated server before build 3104 allows remote attackers to execute arbitrary commands via a long rcon command. | Dec 19, 2000 | 10.0 | 26 | NO | NO |
CVE-2000-0969HIGH Format string vulnerability in Half Life dedicated server build 3104 and earlier allows remote attackers to execute arbitrary commands by injecting format strings into the changele | Dec 19, 2000 | 10.0 | 25 | NO | NO |
CVE-2001-0359HIGH Format string vulnerability in Sierra Half-Life build 1573 and earlier allows a remote attacker to execute arbitrary code via the map command. | Jun 27, 2001 | 7.5 | 24 | NO | NO |
CVE-2002-0964MEDIUM Half-Life Server 1.1.1.0 and earlier allows remote attackers to cause a denial of service (resource exhaustion) via multiple responses to the initial challenge with different cd_ke | Oct 4, 2002 | 5.0 | 23 | NO | YES |
CVE-2007-5713HIGH Off-by-one error in the GeoIP module in the AMX Mod X 1.76d plugin for Half-Life Server might allow attackers to execute arbitrary code or cause a denial of service via unspecified | Oct 30, 2007 | 7.5 | 20 | NO | NO |
CVE-2004-0724MEDIUM The Half-Life engine before July 7 2004 allows remote attackers to cause a denial of service (server or client crash) via an empty fragmented packet. | Jul 27, 2004 | 5.0 | 19 | NO | NO |
CVE-2007-5477MEDIUM Cross-site scripting (XSS) vulnerability in auth.w in djeyl.net WebMod 0.48 Half-Life Dedicated Server plugin allows remote attackers to inject arbitrary web script or HTML via the | Oct 16, 2007 | 4.3 | 14 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (7 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
14.3% of CVEs· 87th percentile
Social Chatter
Signals from CVEs in this product scope (7 CVEs).
Media Mentions
Signals from CVEs in this product scope (7 CVEs).
Top CNAs Publishing CVEs For Half Life Dedicated Server
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 4.1.1.1e | 1 | 5.0 | 1.6% | 0 | 0 |
| 4.1.1.1d_beta | 1 | 5.0 | 1.6% | 0 | 0 |
| 4.1.1.1c1 | 1 | 5.0 | 1.6% | 0 | 0 |
| 4.1.1.0 | 1 | 5.0 | 1.6% | 0 | 0 |
| 4.1.0.9 | 1 | 5.0 | 1.6% | 0 | 0 |
| 4.1.0.8 | 1 | 5.0 | 1.6% | 0 | 0 |
| 4.1.0.7 | 1 | 5.0 | 1.6% | 0 | 0 |
| 4.1.0.6 | 1 | 5.0 | 1.6% | 0 | 0 |
| 4.1.0.4 | 1 | 5.0 | 1.6% | 0 | 0 |
| 3.1.3 | 3 | 6.7 | 2.8% | 0 | 1 |
| 3.1.1.1e | 1 | 5.0 | 1.6% | 0 | 0 |
| 3.1.1.1d | 1 | 5.0 | 1.6% | 0 | 0 |
| 3.1.1.1c1 | 1 | 5.0 | 1.6% | 0 | 0 |
| 3.1.1.0 | 1 | 5.0 | 1.6% | 0 | 0 |
| 3.1.0.9 | 1 | 5.0 | 1.6% | 0 | 0 |
| 3.1.0.8 | 1 | 5.0 | 1.6% | 0 | 0 |
| 3.1.0.7 | 1 | 5.0 | 1.6% | 0 | 0 |
| 3.1.0.6 | 1 | 5.0 | 1.6% | 0 | 0 |
| 3.1.0.5 | 1 | 5.0 | 1.6% | 0 | 0 |
| 3.1.0.4 | 1 | 5.0 | 1.6% | 0 | 0 |