VYPR

Sauerbraten

by Sauerbraten

CVEs (4)

  • CVE-2006-1101Mar 9, 2006
    risk 0.06cvss epss 0.44

    The (1) sgetstr and (2) getint functions in Sauerbraten 2006_02_28, as derived from the Cube engine, allow remote attackers to cause a denial of service (segmentation fault) via long streams of input data that trigger an out-of-bounds read, as demonstrated using SV_EXT tag data in the Cube engine, which is not properly handled by getint.

  • CVE-2006-1100Mar 9, 2006
    risk 0.05cvss epss 0.26

    Buffer overflow in the sgetstr function in shared/cube.h in Sauerbraten 2006_02_28 and earlier, as derived from the Cube engine, allows remote attackers to execute arbitrary code via long streams of input data.

  • CVE-2006-1102Mar 9, 2006
    risk 0.05cvss epss 0.21

    Sauerbraten 2006_02_28, as derived from the Cube engine, allows remote attackers to cause a denial of service (client exit) by forcing the server to change to a map (ogz) file whose name contains ".." sequences and has a certain length that prevents the addition of the ".ogz" extension.

  • CVE-2006-1103Mar 9, 2006
    risk 0.03cvss epss 0.06

    engine/server.cpp in Sauerbraten 2006_02_28, as derived from the Cube engine, allows remote attackers to cause a denial of service (segmentation fault) via a client that does not completely join the game and times out, which results in a null pointer dereference.