TeeworldsCVEs & Vulnerabilities

11 CVEs affecting Teeworlds products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

teeworlds 13
CVE-2023-31518MEDIUM

A heap use-after-free in the component CDataFileReader::GetItem of teeworlds v0.7.5 allows attackers to cause a Denial of Service (DoS) via a crafted map file.

23 May 2023
5.5
CVSS
CVE-2023-31517HIGH

A memory leak in the component CConsole::Chain of Teeworlds v0.7.5 allows attackers to cause a Denial of Service (DoS) via opening a crafted file.

23 May 2023
7.5
CVSS
CVE-2021-43518HIGH

Teeworlds up to and including 0.7.5 is vulnerable to Buffer Overflow. A map parser does not validate m_Channels value coming from a map file, leading to a buffer overflow. A malicious server may offer a specially crafted map that will overwrite client's stack causing denial of service or code execution.

15 Dec 2021
7.8
CVSS
CVE-2020-12066HIGH

CServer::SendMsg in engine/server/server.cpp in Teeworlds 0.7.x before 0.7.5 allows remote attackers to shut down the server.

22 Apr 2020
7.5
CVSS
CVE-2019-20787CRITICAL

Teeworlds before 0.7.4 has an integer overflow when computing a tilemap size.

22 Apr 2020
9.8
CVSS
CVE-2019-10877CRITICAL

In Teeworlds 0.7.2, there is an integer overflow in CMap::Load() in engine/shared/map.cpp that can lead to a buffer overflow, because multiplication of width and height is mishandled.

5 Apr 2019
9.8
CVSS
CVE-2019-10879CRITICAL

In Teeworlds 0.7.2, there is an integer overflow in CDataFileReader::Open() in engine/shared/datafile.cpp that can lead to a buffer overflow and possibly remote code execution, because size-related multiplications are mishandled.

5 Apr 2019
9.8
CVSS
CVE-2019-10878CRITICAL

In Teeworlds 0.7.2, there is a failed bounds check in CDataFileReader::GetData() and CDataFileReader::ReplaceData() and related functions in engine/shared/datafile.cpp that can lead to an arbitrary free and out-of-bounds pointer write, possibly resulting in remote code execution.

5 Apr 2019
9.8
CVSS
CVE-2018-18541HIGH

In Teeworlds before 0.6.5, connection packets could be forged. There was no challenge-response involved in the connection build up. A remote attacker could send connection packets from a spoofed IP address and occupy all server slots, or even use them for a reflection attack using map download packets.

21 Oct 2018
7.5
CVSS
CVE-2016-9400CRITICAL

The CClient::ProcessServerPacket method in engine/client/client.cpp in Teeworlds before 0.6.4 allows remote servers to write to arbitrary physical memory locations and possibly execute arbitrary code via vectors involving snap handling.

22 Feb 2017
9.8
CVSS
CVE-2014-9351MEDIUM

engine/server/server.cpp in Teeworlds 0.6.x before 0.6.3 allows remote attackers to read memory and cause a denial of service (crash) via unspecified vectors.

10 Dec 2014
6.4
CVSS
← PrevPage 1 / 1Next →