Loading...
Loading...
Multiple format string vulnerabilities in the ID Software Doom 3 engine, as used by Doom 3 1.3.1 and earlier, Quake 4 1.4.2 and earlier, and Prey 1.3 and earlier, when Punkbuster (PB) is enabled, allow remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via format string specifiers in (1) a PB_Y packet to the YPG server or (2) a PB_U packet to UCON. NOTE: this issue might be in Punkbuster itself, but there are insufficient details to be certain.
October 6, 2007
April 23, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2007-5248
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.