Vulnerabilities
Vulnerable Software
Id Software:  Security Vulnerabilities
Quake 1 and NetQuake servers allow remote attackers to cause a denial of service (resource exhaustion or forced disconnection) via a flood of spoofed UDP connection packets, which exceeds the server's player limit.
CVSS Score
5.0
EPSS Score
0.013
Published
2001-07-17
Quake 1 (quake1) and ProQuake 1.01 and earlier allow remote attackers to cause a denial of service via a malformed (empty) UDP packet.
CVSS Score
5.0
EPSS Score
0.008
Published
2000-11-01
Quake3 Arena allows malicious server operators to read or modify files on a client via a dot dot (..) attack.
CVSS Score
6.4
EPSS Score
0.005
Published
2000-05-03
Buffer overflows in Quake 1.9 client allows remote malicious servers to execute arbitrary commands via long (1) precache paths, (2) server name, (3) server address, or (4) argument to the map console command.
CVSS Score
7.5
EPSS Score
0.008
Published
1998-04-08
Buffer overflow in QuakeWorld 2.10 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary commands via a long initial connect packet.
CVSS Score
7.5
EPSS Score
0.01
Published
1998-04-07
Quake 2 server 3.13 on Linux does not properly check file permissions for the config.cfg configuration file, which allows local users to read arbitrary files via a symlink from config.cfg to the target file.
CVSS Score
2.1
EPSS Score
0.001
Published
1998-02-25
Quake 2 server allows remote attackers to cause a denial of service via a spoofed UDP packet with a source address of 127.0.0.1, which causes the server to attempt to connect to itself.
CVSS Score
5.0
EPSS Score
0.007
Published
1997-12-24


Contact Us

Shodan ® - All rights reserved