← Back

Freeciv

freeciv

Vendor: Freeciv • 6 CVEs

CVEs (6)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Freeciv
1Freeciv
Jun 17, 2026
Aug 31, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Freeciv before 2.6.7 and before 3.0.3 is prone to a buffer overflow vulnerability in the Modpack Installer utility's handling of the modpack URL.
1Freeciv
1Freeciv
Nov 21, 2024
Jan 23, 2020
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Freeciv before 2.3.3 allows remote attackers to cause a denial of service via a crafted packet.
2Fedoraproject
Freeciv
2Fedora
Freeciv
Nov 21, 2024
Dec 30, 2019
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
A denial of service flaw was found in the way the server component of Freeciv before 2.3.4 processed certain packets. A remote attacker could send a specially-crafted packet that, when processed would lead to memory exha...Show more
A denial of service flaw was found in the way the server component of Freeciv before 2.3.4 processed certain packets. A remote attacker could send a specially-crafted packet that, when processed would lead to memory exhaustion or excessive CPU consumption.Show less
1Freeciv
1Freeciv
Apr 29, 2026
Jul 8, 2010
N/A· v4
N/A· v3
10.0 HIGH· v2
freeciv 2.2 before 2.2.1 and 2.3 before 2.3.0 allows attackers to read arbitrary files or execute arbitrary commands via a scenario that contains Lua functionality, related to the (1) os, (2) io, (3) package, (4) dofile,...Show more
freeciv 2.2 before 2.2.1 and 2.3 before 2.3.0 allows attackers to read arbitrary files or execute arbitrary commands via a scenario that contains Lua functionality, related to the (1) os, (2) io, (3) package, (4) dofile, (5) loadfile, (6) loadlib, (7) module, and (8) require modules or functions.Show less
1Freeciv
1Freeciv
Apr 16, 2026
Jul 28, 2006
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in Freeciv 2.1.0-beta1 and earlier, and SVN 15 Jul 2006 and earlier, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a (1) negative chunk_length or a (...Show more
Buffer overflow in Freeciv 2.1.0-beta1 and earlier, and SVN 15 Jul 2006 and earlier, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a (1) negative chunk_length or a (2) large chunk->offset value in a PACKET_PLAYER_ATTRIBUTE_CHUNK packet in the generic_handle_player_attribute_chunk function in common/packets.c, and (3) a large packet->length value in the handle_unit_orders function in server/unithand.c.Show less
1Freeciv
1Freeciv
Apr 16, 2026
Mar 7, 2006
N/A· v4
N/A· v3
5.0 MEDIUM· v2
packets.c in Freeciv 2.0 before 2.0.8 allows remote attackers to cause a denial of service (server crash) via crafted packets with negative compressed size values.