CVE Tools

Id-software

23 CVEs tracked since 2000. Since Jul 2000, none of them reached CISA KEV.

Id-software CVEs per month

Jul 2000 to Jul 2006. Point at a month, or focus the strip and use the arrow keys.
Id-software CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2000-0710
2000-08null or fewer
2000-09null or fewer
2000-10null or fewer
2000-11null or fewer
2000-12null or fewer
2001-0110
2001-02null or fewer
2001-03null or fewer
2001-04null or fewer
2001-05null or fewer
2001-06null or fewer
2001-07null or fewer
2001-08null or fewer
2001-0940
2001-10null or fewer
2001-11null or fewer
2001-12null or fewer
2002-01null or fewer
2002-02null or fewer
2002-03null or fewer
2002-04null or fewer
2002-0510
2002-06null or fewer
2002-0710
2002-0810
2002-09null or fewer
2002-10null or fewer
2002-11null or fewer
2002-12null or fewer
2003-01null or fewer
2003-02null or fewer
2003-03null or fewer
2003-04null or fewer
2003-05null or fewer
2003-06null or fewer
2003-07null or fewer
2003-08null or fewer
2003-09null or fewer
2003-10null or fewer
2003-11null or fewer
2003-12null or fewer
2004-01null or fewer
2004-02null or fewer
2004-03null or fewer
2004-04null or fewer
2004-05null or fewer
2004-06null or fewer
2004-07null or fewer
2004-08null or fewer
2004-09null or fewer
2004-10null or fewer
2004-11null or fewer
2004-12null or fewer
2005-01null or fewer
2005-02null or fewer
2005-03null or fewer
2005-0410
2005-05null or fewer
2005-06null or fewer
2005-07null or fewer
2005-08null or fewer
2005-09null or fewer
2005-10null or fewer
2005-1160
2005-12null or fewer
2006-01null or fewer
2006-02null or fewer
2006-03null or fewer
2006-04null or fewer
2006-0520
2006-0630
2006-0720

Products

The products that kept showing up in Id-software's monthly top three, with their CVEs summed over those months.

  1. Quake 3 Engine84 months
  2. Quake 3 Arena44 months
  3. Quake Ii Server41 month
  4. Quake33 months
  5. Quake 211 month
  6. Quake 2 Server11 month
  7. Quake 2i Server11 month
  8. Quake 3 Arena Server11 month
  9. Quake Ii Server Linux11 month
  10. Quake Ii Server Windows11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Id-software.

  1. CVE-2007-5248Multiple format string vulnerabilities in the ID Software Doom 3 engine, as used by Doom 3 1.3.1 and earlier, Quake 4 1.4.2 and earlier, and Prey 1.3 and earlier, when Punkbuster (PB) is enabled, a...9.3
  2. CVE-2006-3400Stack-based buffer overflow in the CG_ServerCommand function in Quake 3 Engine as used by Soldier of Fortune 2 (SOF2MP) GOLD 1.03 allows remote attackers to cause a denial of service and possibly e...7.5
  3. CVE-2006-3401Stack-based buffer overflow in Quake 3 Engine as used by Quake 3: Arena 1.32b and 1.32c allows remote attackers to cause a denial of service and possibly execute code via long CS_ITEMS values.7.5
  4. CVE-2006-3324The Automatic Downloading option in the id3 Quake 3 Engine and the Icculus Quake 3 Engine (ioquake3) before revision 804 allows remote attackers to overwrite arbitrary files in the quake3 directory...5.0
  5. CVE-2006-3325client/cl_parse.c in the id3 Quake 3 Engine 1.32c and the Icculus Quake 3 Engine (ioquake3) revision 810 and earlier allows remote malicious servers to overwrite arbitrary write-protected cvars var...5.0
  6. CVE-2006-2875Stack-based buffer overflow in the CL_ParseDownload function of Quake 3 Engine 1.32c and earlier, as used in multiple products, allows remote attackers to execute arbitrary code via a svc_download ...7.5
  7. CVE-2006-2082Directory traversal vulnerability in Quake 3 engine, as used in products including Quake3 Arena, Return to Castle Wolfenstein, Wolfenstein: Enemy Territory, and Star Trek Voyager: Elite Force, when...7.5
  8. CVE-2006-2236Buffer overflow in the Quake 3 Engine, as used by (1) ET 2.60, (2) Return to Castle Wolfenstein 1.41, and (3) Quake III Arena 1.32b allows remote attackers to execute arbitrary commands via a long ...7.6
  9. CVE-2004-2597Quake II server before R1Q2, as used in multiple products, allows remote attackers to bypass IP-based access control rules via a userinfo string that already contains an "ip" key/value pair but is ...5.0
  10. CVE-2004-2594Absolute path traversal vulnerability in Quake II server before R1Q2 on Windows, as used in multiple products, allows remote attackers to read arbitrary files via a "\/" in a pathname argument, as ...5.0
  11. CVE-2004-2592Quake II server before R1Q2, as used in multiple products, allows remote attackers to cause a denial of service (application crash) via a modified client that asks the server to send data stored at...5.0
  12. CVE-2004-2595Absolute path traversal vulnerability in Quake II server before R1Q2 on Linux, as used in multiple products, allows remote attackers to cause a denial of service (application crash) via a download ...5.0
  13. CVE-2004-2596Quake II server before R1Q2, as used in multiple products, allows remote attackers to cause a denial of service (exhaustion of connection slots) via a large number of connections from the same IP a...5.0
  14. CVE-2004-2593Buffer overflow in command-packet processing of Quake II server before R1Q2, as used in multiple products, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrar...7.5
  15. CVE-2005-0983Quake 3 engine, as used in multiple games, allows remote attackers to cause a denial of service (client disconnect) via a long message, which is not properly truncated and causes the engine to proc...5.0

The record

Peak rank
#18 in Nov 2005
Busiest month shown
Nov 2005, 6 CVEs
Months with a KEV entry
0 since Jul 2000
Monthly snapshots
11 since 2000
Id-software's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store