Valvesoftware's vulnerability footprint spans gaming platforms and networked entertainment services, most prominently the Steam client, game servers including Counter-Strike and Dota 2, and underlying game-networking infrastructure. The vendor's disclosures skew toward serious outcomes, with a notable share reaching critical severity and a strong tendency to acquire public exploit code, reflecting the memory-safety and input-handling demands of native game clients and network services exposed to untrusted user input. The exposure recurs through weakness classes including out-of-bounds writes, classic buffer overflows, and improper input validation—patterns typical of performance-critical gaming codebases—as well as permission and privilege management gaps in server and client access control. Defenders should prioritize patches for the widely installed Steam client and treat exposed game servers as bearing elevated risk; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Valvesoftware over time
Signals from CVEs in this vendor scope (40 CVEs).
40 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-15943HIGH vphysics.dll in Counter-Strike: Global Offensive before 1.37.1.1 allows remote attackers to achieve code execution or denial of service by creating a gaming server and inviting a v | Sep 19, 2019 | 8.8 | 43 | NO | YES |
CVE-2020-7949HIGH schemasystem.dll in Valve Dota 2 before 7.23f allows remote attackers to achieve code execution or denial of service by creating a gaming server and inviting a victim to this serve | Jan 27, 2020 | 7.8 | 36 | NO | YES |
CVE-2015-7985HIGH Valve Steam 2.10.91.91 uses weak permissions (Users: read and write) for the Install folder, which allows local users to gain privileges via a Trojan horse steam.exe file. | Nov 24, 2015 | 7.2 | 35 | NO | YES |
CVE-2021-30481CRITICAL Valve Steam before 2021-04-17, when a Source engine game is installed, allows remote authenticated users to execute arbitrary code because of a buffer overflow that occurs for a St | Apr 10, 2021 | 9.0 | 31 | NO | NO |
CVE-2023-35855CRITICAL A buffer overflow in Counter-Strike through 8684 allows a game server to execute arbitrary code on a remote client's machine by modifying the lservercfgfile console variable. | Jun 19, 2023 | 9.8 | 30 | NO | NO |
CVE-2017-17877CRITICAL An issue was discovered in Valve Steam Link build 643. When the SSH daemon is enabled for local development, the device is publicly available via IPv6 TCP port 22 over the internet | Dec 27, 2017 | 9.8 | 30 | NO | NO |
CVE-2020-6017CRITICAL Valve's Game Networking Sockets prior to version v1.2.0 improperly handles long unreliable segments in function SNP_ReceiveUnreliableSegment() when configured to support plain-text | Dec 3, 2020 | 9.8 | 29 | NO | NO |
CVE-2020-12242HIGH Valve Source allows local users to gain privileges by writing to the /tmp/hl2_relaunch file, which is later executed in the context of a different user account. | Apr 27, 2020 | 7.8 | 29 | NO | YES |
CVE-2003-1325MEDIUM The SV_CheckForDuplicateNames function in Valve Software Half-Life CSTRIKE Dedicated Server 1.1.1.0 and earlier allows remote authenticated users to cause a denial of service (infi | Dec 31, 2003 | 5.2 | 29 | NO | YES |
CVE-2017-17878CRITICAL An issue was discovered in Valve Steam Link build 643. Root passwords longer than 8 characters are truncated because of the default use of DES (aka the CONFIG_FEATURE_DEFAULT_PASSW | Dec 27, 2017 | 9.8 | 28 | NO | NO |
Signals from CVEs in this vendor scope (40 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Valvesoftware.
Media articles that mention a CVE ID that affects a product developed by Valvesoftware — matched by CVE ID, not by vendor name.