Vavoom is a niche, open-source game engine with a focused product footprint centered on its core engine implementation. Observed disclosures cluster around generalized weakness categories; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Vavoom over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-4534HIGH Buffer overflow in the VThinker::BroadcastPrintf function in p_thinker.cpp in Vavoom 1.24 and earlier allows remote attackers to execute arbitrary code via (1) a long string in a c | Aug 25, 2007 | 7.5 | 35 | NO | YES |
CVE-2007-4533MEDIUM Format string vulnerability in the Say command in sv_main.cpp in Vavoom 1.24 and earlier allows remote attackers to execute arbitrary code via format string specifiers in a chat me | Aug 25, 2007 | 6.8 | 30 | NO | YES |
CVE-2007-4535MEDIUM The VStr::Resize function in str.cpp in Vavoom 1.24 and earlier allows remote attackers to cause a denial of service (daemon crash) via a string with a negative NewLen value within | Aug 25, 2007 | 4.3 | 22 | NO | YES |
CVE-2006-1408MEDIUM Vavoom 1.19.1 and earlier allows remote attackers to cause a denial of service (infinite loop) via (1) a packet with no data or (2) a large packet, which prevents Vavoom from disca | Mar 28, 2006 | 5.0 | 16 | NO | NO |
CVE-2006-1409MEDIUM Buffer overflow in Vavoom 1.19.1 and earlier allows remote attackers to cause a denial of service (application crash) via an invalid comprLength value in a compressed packet. | Mar 28, 2006 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Vavoom.
Media articles that mention a CVE ID that affects a product developed by Vavoom — matched by CVE ID, not by vendor name.