CVE-2008-3396 – Unreal Tournament 2004 - Null Pointer Remote Denial of Service
https://notcve.org/view.php?id=CVE-2008-3396
Unreal Tournament 2004 (UT2004) 3369 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a certain sequence of malformed packets. Juego Unreal Tournament 2004 (UT2004) 3369 y anteriores, permite a atacantes remotos provocar una denegación de servicio (referencia a puntero nulo o caída de demonio) a través de ciertas secuencias de paquetes mal formados. • https://www.exploit-db.com/exploits/32125 http://aluigi.altervista.org/adv/ut2004null-adv.txt http://aluigi.org/poc/ut2004null.zip http://secunia.com/advisories/31266 http://www.securityfocus.com/archive/1/494935/100/0/threaded http://www.securityfocus.com/bid/30427 http://www.vupen.com/english/advisories/2008/2259/references https://exchange.xforce.ibmcloud.com/vulnerabilities/44107 • CWE-20: Improper Input Validation •
CVE-2007-4443
https://notcve.org/view.php?id=CVE-2007-4443
The UCC dedicated server for the Unreal engine, possibly 2003 and 2004, on Windows allows remote attackers to cause a denial of service (continuous beep and server slowdown) via a string containing many 0x07 characters in (1) a request to the images/ directory, (2) the Content-Type field, (3) a HEAD request, and possibly other unspecified vectors. El servidor dedicado UCC para el Unreal engine, posiblemente 2003 y 2004, sobre Windows permite a atacantes remotos provocar denegación de servicio (continuos pitidos y disminución de servidor) a través de una cadena que contiene varios caracteres 0x07 en (1) una respuesta en el directorio images/, (2) el campo Content-Type, (3) una respuesta HEAD, y posiblemente otros vectores no especificados. • http://aluigi.org/adv/unrwebdos-adv.txt http://aluigi.org/poc/unrwebdos.zip http://secunia.com/advisories/26506 http://securityreason.com/securityalert/3039 http://www.securityfocus.com/archive/1/477026/100/0/threaded http://www.securityfocus.com/archive/1/478053/100/200/threaded http://www.securityfocus.com/archive/1/478064/100/200/threaded https://exchange.xforce.ibmcloud.com/vulnerabilities/36103 •
CVE-2007-4442 – Epic Games Unreal Engine Logging Function - Remote Denial of Service
https://notcve.org/view.php?id=CVE-2007-4442
Stack-based buffer overflow in the logging function in the Unreal engine, possibly 2003 and 2004, as used in the internal web server, allows remote attackers to cause a denial of service (application crash) via a request for a long .gif filename in the images/ directory, related to conversion from Unicode to ASCII. Desbordamiento de búfer basado en pila en la función logging en Unreal engine, posiblemente 2003 y 2004, utilizado en los servidores web internos permite a atacantes remotos provocar denegación de servicio (caida de aplicación) a través de una respuesta para un nombre de archivo largo .gif en el directorio images/, relacionado con la conversión de Unicode a ASCII. • https://www.exploit-db.com/exploits/30513 http://aluigi.org/adv/unrwebdos-adv.txt http://aluigi.org/poc/unrwebdos.zip http://secunia.com/advisories/26506 http://securityreason.com/securityalert/3039 http://www.securityfocus.com/archive/1/477026/100/0/threaded http://www.securityfocus.com/bid/25374 https://exchange.xforce.ibmcloud.com/vulnerabilities/36102 •
CVE-2004-1805 – Epic Games Unreal Tournament Server 436.0 - Engine Remote Format String
https://notcve.org/view.php?id=CVE-2004-1805
Format string vulnerability in games using the Epic Games Unreal Engine 436 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in class names. • https://www.exploit-db.com/exploits/23799 http://aluigi.altervista.org/adv/unrfs-adv.txt http://marc.info/?l=bugtraq&m=107893764406905&w=2 http://marc.info/?l=bugtraq&m=107902755204583&w=2 http://secunia.com/advisories/11108 http://www.securityfocus.com/bid/9840 https://exchange.xforce.ibmcloud.com/vulnerabilities/15430 •
CVE-2004-1958 – Epic Games Unreal Tournament Engine 3 - UMOD Manifest.INI Arbitrary File Overwrite
https://notcve.org/view.php?id=CVE-2004-1958
Directory traversal vulnerability in manifest.ini in Unreal engine allows remote attackers to overwrite arbitrary files via .. (dot dot) sequences in a UMOD (Unreal MOD) file. • https://www.exploit-db.com/exploits/24041 http://aluigi.altervista.org/adv/umod-adv.txt http://marc.info/?l=bugtraq&m=108267310519459&w=2 http://www.securityfocus.com/bid/10196 https://exchange.xforce.ibmcloud.com/vulnerabilities/15942 •