Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2023-38312
A directory traversal vulnerability in Valve Counter-Strike 8684 allows a client (with remote control access to a game server) to read arbitrary file…
Counter Strike
Mitigation only
CRITICAL 9.8
CVE-2023-35855
A buffer overflow in Counter-Strike through 8684 allows a game server to execute arbitrary code on a remote client's machine by modifying the lserver…
Counter Strike
after 8684
HIGH 7.3
CVE-2023-30382
A buffer overflow in the component hl.exe of Valve Half-Life up to 5433873 allows attackers to execute arbitrary code and escalate privileges by supp…
Half Life
Mitigation only
CRITICAL 9.0
CVE-2021-30481
Valve Steam before 2021-04-17, when a Source engine game is installed, allows remote authenticated users to execute arbitrary code because of a buffe…
Steam Client
after 2021-04-10
CRITICAL 9.8
CVE-2020-6017
Valve's Game Networking Sockets prior to version v1.2.0 improperly handles long unreliable segments in function SNP_ReceiveUnreliableSegment() when c…
Game Networking Sockets
1.2.0+
CRITICAL 9.8
CVE-2020-6018
Valve's Game Networking Sockets prior to version v1.2.0 improperly handles long encrypted messages in function AES_GCM_DecryptContext::Decrypt() when…
Game Networking Sockets
1.2.0+
CRITICAL 9.8
CVE-2020-6016EPSS 6%
Valve's Game Networking Sockets prior to version v1.2.0 improperly handles unreliable segments with negative offsets in function SNP_ReceiveUnreliabl…
Game Networking Sockets
1.2.0+
HIGH 7.5
CVE-2020-6019
Valve's Game Networking Sockets prior to version v1.2.0 improperly handles inlined statistics messages in function CConnectionTransportUDPBase::Recei…
Game Networking Sockets
1.2.0+
HIGH 7.8
CVE-2020-15530
An issue was discovered in Valve Steam Client 2.10.91.91. The installer allows local users to gain NT AUTHORITY\SYSTEM privileges because some parts …
Steam Client
No fix yet
HIGH 7.8
CVE-2020-12242
Valve Source allows local users to gain privileges by writing to the /tmp/hl2_relaunch file, which is later executed in the context of a different us…
Source
No fix yet
HIGH 7.8
CVE-2020-9005
meshsystem.dll in Valve Dota 2 through 2020-02-17 allows remote attackers to achieve code execution or denial of service by creating a gaming server …
Dota 2
after 2020-02-17
HIGH 7.8
CVE-2020-7949
schemasystem.dll in Valve Dota 2 before 7.23f allows remote attackers to achieve code execution or denial of service by creating a gaming server and …
Dota 2
7.23f+
HIGH 7.8
CVE-2020-7950
meshsystem.dll in Valve Dota 2 before 7.23f allows remote attackers to achieve code execution or denial of service by creating a gaming server and in…
Dota 2
7.23f+
HIGH 7.8
CVE-2020-7951
meshsystem.dll in Valve Dota 2 before 7.23e allows remote attackers to achieve code execution or denial of service by creating a gaming server and in…
Dota 2
7.23e+
HIGH 7.8
CVE-2020-7952
rendersystemdx9.dll in Valve Dota 2 before 7.23f allows remote attackers to achieve code execution or denial of service by creating a gaming server a…
Dota 2
7.23f+
HIGH 7.8
CVE-2019-17180
Valve Steam Client before 2019-09-12 allows placing or appending partially controlled filesystem content, as demonstrated by file modifications on Wi…
Steam Client
2019-09-12+
HIGH 8.8
CVE-2019-15943EPSS 9%
vphysics.dll in Counter-Strike: Global Offensive before 1.37.1.1 allows remote attackers to achieve code execution or denial of service by creating a…
Counter Strike\
1.37.1.1+
MEDIUM 5.3
CVE-2019-15944
In Counter-Strike: Global Offensive before 8/29/2019, community game servers can display unsafe HTML in a disconnection message.
Counter Strike\
2019-08-29+
HIGH 7.8
CVE-2019-15315
Valve Steam Client for Windows through 2019-08-16 allows privilege escalation (to NT AUTHORITY\SYSTEM) because local users can replace the current ve…
Steam Client
after 2019-08-16
HIGH 7.0
CVE-2019-15316
Valve Steam Client for Windows through 2019-08-20 has weak folder permissions, leading to privilege escalation (to NT AUTHORITY\SYSTEM) via crafted u…
Steam Client
after 2019-08-20
MEDIUM 6.6
CVE-2019-14743
In Valve Steam Client for Windows through 2019-08-07, HKLM\SOFTWARE\Wow6432Node\Valve\Steam has explicit "Full control" for the Users group, which al…
Steam Client
after 2019-08-07
MEDIUM 5.4
CVE-2018-12270
In Valve Steam 1528829181 BETA, it is possible to perform a homograph / homoglyph attack to create fake URLs in the client, which may trick users int…
Steam Client
Mitigation only
CRITICAL 9.8
CVE-2017-17877
An issue was discovered in Valve Steam Link build 643. When the SSH daemon is enabled for local development, the device is publicly available via IPv…
Steam Link Firmware
644+
CRITICAL 9.8
CVE-2017-17878
An issue was discovered in Valve Steam Link build 643. Root passwords longer than 8 characters are truncated because of the default use of DES (aka t…
Steam Link Firmware
644+
HIGH 7.2
CVE-2015-7985
Valve Steam 2.10.91.91 uses weak permissions (Users: read and write) for the Install folder, which allows local users to gain privileges via a Trojan…
Steam Client
No fix yet
MEDIUM 5.0
CVE-2015-4016
The client detection protocol in Valve Steam allows remote attackers to cause a denial of service (process crash) via a crafted response to a broadca…
Steam Client
2015-05-13+
MEDIUM 5.0
CVE-2008-7203
Valve Software Half-Life Counter-Strike 1.6 allows remote attackers to cause a denial of service (crash) via multiple crafted login packets.
Counter Strike
No fix yet