Half Life Dedicated Server

Vendor:

First CVE: Dec 19, 2000 · Active for 25 years

7
Total CVEs
More Total CVEs than 85% of tracked products
1.4
Avg CVEs / Year
Higher CVE frequency than 59% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 45% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Half Life Dedicated Server over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 19, 2000
25 years ago
Most Recent CVE
Oct 30, 2007
6,846 days ago

CVE Severity & Scoring

Half Life Dedicated Server7 CVEs
All CVEs353,173 CVEs
MediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown7 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown7 (100.0%)
User Interaction
None0 (0.0%)
Unknown7 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown7 (100.0%)

Top CVEs

Signals from CVEs in this product scope (7 CVEs).

7 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Buffer overflow in Half Life dedicated server before build 3104 allows remote attackers to execute arbitrary commands via a long rcon command.
Dec 19, 200010.026NONO
Format string vulnerability in Half Life dedicated server build 3104 and earlier allows remote attackers to execute arbitrary commands by injecting format strings into the changele
Dec 19, 200010.025NONO
Format string vulnerability in Sierra Half-Life build 1573 and earlier allows a remote attacker to execute arbitrary code via the map command.
Jun 27, 20017.524NONO
Half-Life Server 1.1.1.0 and earlier allows remote attackers to cause a denial of service (resource exhaustion) via multiple responses to the initial challenge with different cd_ke
Oct 4, 20025.023NOYES
Off-by-one error in the GeoIP module in the AMX Mod X 1.76d plugin for Half-Life Server might allow attackers to execute arbitrary code or cause a denial of service via unspecified
Oct 30, 20077.520NONO
The Half-Life engine before July 7 2004 allows remote attackers to cause a denial of service (server or client crash) via an empty fragmented packet.
Jul 27, 20045.019NONO
Cross-site scripting (XSS) vulnerability in auth.w in djeyl.net WebMod 0.48 Half-Life Dedicated Server plugin allows remote attackers to inject arbitrary web script or HTML via the
Oct 16, 20074.314NONO

Exploit Exposure

Signals from CVEs in this product scope (7 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
14.3% of CVEs· 87th percentile

Social Chatter

Signals from CVEs in this product scope (7 CVEs).

Media Mentions

Signals from CVEs in this product scope (7 CVEs).

Top CNAs Publishing CVEs For Half Life Dedicated Server

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
4.1.1.1e15.01.6%00
4.1.1.1d_beta15.01.6%00
4.1.1.1c115.01.6%00
4.1.1.015.01.6%00
4.1.0.915.01.6%00
4.1.0.815.01.6%00
4.1.0.715.01.6%00
4.1.0.615.01.6%00
4.1.0.415.01.6%00
3.1.336.72.8%01
3.1.1.1e15.01.6%00
3.1.1.1d15.01.6%00
3.1.1.1c115.01.6%00
3.1.1.015.01.6%00
3.1.0.915.01.6%00
3.1.0.815.01.6%00
3.1.0.715.01.6%00
3.1.0.615.01.6%00
3.1.0.515.01.6%00
3.1.0.415.01.6%00