Show filters
29 Total Results
Displaying 11-20 of 29
Sort by:
Attacker Value
Unknown
CVE-2020-9005
Disclosure Date: February 17, 2020 (last updated February 21, 2025)
meshsystem.dll in Valve Dota 2 through 2020-02-17 allows remote attackers to achieve code execution or denial of service by creating a gaming server with a crafted map, and inviting a victim to this server. A GetValue call is mishandled.
0
Attacker Value
Unknown
CVE-2020-7949
Disclosure Date: January 27, 2020 (last updated November 27, 2024)
schemasystem.dll in Valve Dota 2 before 7.23f allows remote attackers to achieve code execution or denial of service by creating a gaming server and inviting a victim to this server, because a crafted map is mishandled during a GetValue call.
0
Attacker Value
Unknown
CVE-2020-7952
Disclosure Date: January 27, 2020 (last updated November 27, 2024)
rendersystemdx9.dll in Valve Dota 2 before 7.23f allows remote attackers to achieve code execution or denial of service by creating a gaming server and inviting a victim to this server, because a crafted map is affected by memory corruption.
0
Attacker Value
Unknown
CVE-2020-7951
Disclosure Date: January 27, 2020 (last updated February 21, 2025)
meshsystem.dll in Valve Dota 2 before 7.23e allows remote attackers to achieve code execution or denial of service by creating a gaming server and inviting a victim to this server, because a crafted map is affected by memory corruption.
0
Attacker Value
Unknown
CVE-2020-7950
Disclosure Date: January 27, 2020 (last updated November 27, 2024)
meshsystem.dll in Valve Dota 2 before 7.23f allows remote attackers to achieve code execution or denial of service by creating a gaming server and inviting a victim to this server, because a crafted map is mishandled during a vulnerable function call.
0
Attacker Value
Unknown
CVE-2019-15943
Disclosure Date: September 19, 2019 (last updated November 27, 2024)
vphysics.dll in Counter-Strike: Global Offensive before 1.37.1.1 allows remote attackers to achieve code execution or denial of service by creating a gaming server and inviting a victim to this server, because a crafted map is mishandled during a memset call.
0
Attacker Value
Unknown
CVE-2019-15944
Disclosure Date: September 05, 2019 (last updated November 27, 2024)
In Counter-Strike: Global Offensive before 8/29/2019, community game servers can display unsafe HTML in a disconnection message.
0
Attacker Value
Unknown
CVE-2019-15316
Disclosure Date: August 21, 2019 (last updated November 27, 2024)
Valve Steam Client for Windows through 2019-08-20 has weak folder permissions, leading to privilege escalation (to NT AUTHORITY\SYSTEM) via crafted use of CreateMountPoint.exe and SetOpLock.exe to leverage a TOCTOU race condition.
0
Attacker Value
Unknown
CVE-2019-15315
Disclosure Date: August 21, 2019 (last updated November 27, 2024)
Valve Steam Client for Windows through 2019-08-16 allows privilege escalation (to NT AUTHORITY\SYSTEM) because local users can replace the current versions of SteamService.exe and SteamService.dll with older versions that lack the CVE-2019-14743 patch.
0
Attacker Value
Unknown
CVE-2019-14743
Disclosure Date: August 07, 2019 (last updated November 27, 2024)
In Valve Steam Client for Windows through 2019-08-07, HKLM\SOFTWARE\Wow6432Node\Valve\Steam has explicit "Full control" for the Users group, which allows local users to gain NT AUTHORITY\SYSTEM access.
0