Vulnerability index

Browse CVEs

27 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Counter Strike HIGH 7.5
CVE-2023-38312

A directory traversal vulnerability in Valve Counter-Strike 8684 allows a client (with remote control access to a game server) to read arbitrary file…

Mitigation only
Fix from $1,950 2023-10-15
Counter Strike CRITICAL 9.8
CVE-2023-35855

A buffer overflow in Counter-Strike through 8684 allows a game server to execute arbitrary code on a remote client's machine by modifying the lserver…

Fix: after 8684
Fix from $2,300 2023-06-19
Half Life HIGH 7.3
CVE-2023-30382

A buffer overflow in the component hl.exe of Valve Half-Life up to 5433873 allows attackers to execute arbitrary code and escalate privileges by supp…

Mitigation only
Fix from $1,950 2023-05-23
Steam Client CRITICAL 9.0
CVE-2021-30481

Valve Steam before 2021-04-17, when a Source engine game is installed, allows remote authenticated users to execute arbitrary code because of a buffe…

Fix: after 2021-04-10
Fix from $2,300 2021-04-10
Game Networking Sockets CRITICAL 9.8
CVE-2020-6017

Valve's Game Networking Sockets prior to version v1.2.0 improperly handles long unreliable segments in function SNP_ReceiveUnreliableSegment() when c…

Fix: 1.2.0+
Fix from $2,300 2020-12-03
Game Networking Sockets CRITICAL 9.8
CVE-2020-6018

Valve's Game Networking Sockets prior to version v1.2.0 improperly handles long encrypted messages in function AES_GCM_DecryptContext::Decrypt() when…

Fix: 1.2.0+
Fix from $2,300 2020-12-02
Game Networking Sockets CRITICAL 9.8
CVE-2020-6016EPSS 6%

Valve's Game Networking Sockets prior to version v1.2.0 improperly handles unreliable segments with negative offsets in function SNP_ReceiveUnreliabl…

Fix: 1.2.0+
Fix from $2,300 2020-11-18
Game Networking Sockets HIGH 7.5
CVE-2020-6019

Valve's Game Networking Sockets prior to version v1.2.0 improperly handles inlined statistics messages in function CConnectionTransportUDPBase::Recei…

Fix: 1.2.0+
Fix from $1,950 2020-11-13
Steam Client HIGH 7.8
CVE-2020-15530

An issue was discovered in Valve Steam Client 2.10.91.91. The installer allows local users to gain NT AUTHORITY\SYSTEM privileges because some parts …

No fix yet
Fix from $1,950 2020-07-05
Source HIGH 7.8
CVE-2020-12242

Valve Source allows local users to gain privileges by writing to the /tmp/hl2_relaunch file, which is later executed in the context of a different us…

No fix yet
Fix from $1,950 2020-04-27
Dota 2 HIGH 7.8
CVE-2020-9005

meshsystem.dll in Valve Dota 2 through 2020-02-17 allows remote attackers to achieve code execution or denial of service by creating a gaming server …

Fix: after 2020-02-17
Fix from $1,950 2020-02-17
Dota 2 HIGH 7.8
CVE-2020-7949

schemasystem.dll in Valve Dota 2 before 7.23f allows remote attackers to achieve code execution or denial of service by creating a gaming server and …

Fix: 7.23f+
Fix from $1,950 2020-01-27
Dota 2 HIGH 7.8
CVE-2020-7950

meshsystem.dll in Valve Dota 2 before 7.23f allows remote attackers to achieve code execution or denial of service by creating a gaming server and in…

Fix: 7.23f+
Fix from $1,950 2020-01-27
Dota 2 HIGH 7.8
CVE-2020-7951

meshsystem.dll in Valve Dota 2 before 7.23e allows remote attackers to achieve code execution or denial of service by creating a gaming server and in…

Fix: 7.23e+
Fix from $1,950 2020-01-27
Dota 2 HIGH 7.8
CVE-2020-7952

rendersystemdx9.dll in Valve Dota 2 before 7.23f allows remote attackers to achieve code execution or denial of service by creating a gaming server a…

Fix: 7.23f+
Fix from $1,950 2020-01-27
Steam Client HIGH 7.8
CVE-2019-17180

Valve Steam Client before 2019-09-12 allows placing or appending partially controlled filesystem content, as demonstrated by file modifications on Wi…

Fix: 2019-09-12+
Fix from $1,950 2019-10-04
Counter Strike\ HIGH 8.8
CVE-2019-15943EPSS 9%

vphysics.dll in Counter-Strike: Global Offensive before 1.37.1.1 allows remote attackers to achieve code execution or denial of service by creating a…

Fix: 1.37.1.1+
Fix from $1,950 2019-09-19
Counter Strike\ MEDIUM 5.3
CVE-2019-15944

In Counter-Strike: Global Offensive before 8/29/2019, community game servers can display unsafe HTML in a disconnection message.

Fix: 2019-08-29+
Fix from $1,600 2019-09-05
Steam Client HIGH 7.8
CVE-2019-15315

Valve Steam Client for Windows through 2019-08-16 allows privilege escalation (to NT AUTHORITY\SYSTEM) because local users can replace the current ve…

Fix: after 2019-08-16
Fix from $1,950 2019-08-21
Steam Client HIGH 7.0
CVE-2019-15316

Valve Steam Client for Windows through 2019-08-20 has weak folder permissions, leading to privilege escalation (to NT AUTHORITY\SYSTEM) via crafted u…

Fix: after 2019-08-20
Fix from $1,950 2019-08-21
Steam Client MEDIUM 6.6
CVE-2019-14743

In Valve Steam Client for Windows through 2019-08-07, HKLM\SOFTWARE\Wow6432Node\Valve\Steam has explicit "Full control" for the Users group, which al…

Fix: after 2019-08-07
Fix from $1,600 2019-08-07
Steam Client MEDIUM 5.4
CVE-2018-12270

In Valve Steam 1528829181 BETA, it is possible to perform a homograph / homoglyph attack to create fake URLs in the client, which may trick users int…

Mitigation only
Fix from $1,600 2019-05-20
Steam Link Firmware CRITICAL 9.8
CVE-2017-17877

An issue was discovered in Valve Steam Link build 643. When the SSH daemon is enabled for local development, the device is publicly available via IPv…

Fix: 644+
Fix from $2,300 2017-12-27
Steam Link Firmware CRITICAL 9.8
CVE-2017-17878

An issue was discovered in Valve Steam Link build 643. Root passwords longer than 8 characters are truncated because of the default use of DES (aka t…

Fix: 644+
Fix from $2,300 2017-12-27
Steam Client HIGH 7.2
CVE-2015-7985

Valve Steam 2.10.91.91 uses weak permissions (Users: read and write) for the Install folder, which allows local users to gain privileges via a Trojan…

No fix yet
Fix from $1,950 2015-11-24
Steam Client MEDIUM 5.0
CVE-2015-4016

The client detection protocol in Valve Steam allows remote attackers to cause a denial of service (process crash) via a crafted response to a broadca…

Fix: 2015-05-13+
Fix from $1,600 2015-05-20
Counter Strike MEDIUM 5.0
CVE-2008-7203

Valve Software Half-Life Counter-Strike 1.6 allows remote attackers to cause a denial of service (crash) via multiple crafted login packets.

No fix yet
Fix from $1,600 2009-09-11