← Vulnerability feed

Vulnerability record · CVE-2006-2082 · published 10 May 2006

CVE-2006-2082: Id software quake 3 engine vulnerability

IId Software · Quake 3 Engine

Directory traversal vulnerability in Quake 3 engine, as used in products including Quake3 Arena, Return to Castle Wolfenstein, Wolfenstein: Enemy Territory, and Star Trek Voyager: Elite Force, when the sv_allowdownload cvar is enabled, allows remote attackers to read arbitrary files from the server via ".." sequences in a .pk3 file request.

7.5 CVSS 2.0 High EPSS 2.6% · top 15.1%
7.5CVSS 2.0 base score
2.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References
16 Jun 2026Last modified by NVD

Description

Directory traversal vulnerability in Quake 3 engine, as used in products including Quake3 Arena, Return to Castle Wolfenstein, Wolfenstein: Enemy Territory, and Star Trek Voyager: Elite Force, when the sv_allowdownload cvar is enabled, allows remote attackers to read arbitrary files from the server via ".." sequences in a .pk3 file request.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2006-2082 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.6CVE-2006-2236Id software quake 3 arena vulnerabilityBuffer overflow in the Quake 3 Engine, as used by (1) ET 2.60, (2) Return to Castle Wolfenstein 1.41, and (3) Quake III Arena 1.32b allows remote att…EPSS 7.6%7.5CVE-2006-3400Id software quake 3 engine vulnerabilityStack-based buffer overflow in the CG_ServerCommand function in Quake 3 Engine as used by Soldier of Fortune 2 (SOF2MP) GOLD 1.03 allows remote attac…EPSS 4.8%7.5CVE-2006-3401Id software quake 3 engine memory buffer overflow vulnerabilityStack-based buffer overflow in Quake 3 Engine as used by Quake 3: Arena 1.32b and 1.32c allows remote attackers to cause a denial of service and poss…EPSS 5.7%7.5CVE-2006-2875Id software quake 3 engine vulnerabilityStack-based buffer overflow in the CL_ParseDownload function of Quake 3 Engine 1.32c and earlier, as used in multiple products, allows remote attacke…EPSS 6.8%5.0CVE-2006-3324Id software quake 3 engine vulnerabilityThe Automatic Downloading option in the id3 Quake 3 Engine and the Icculus Quake 3 Engine (ioquake3) before revision 804 allows remote attackers to o…EPSS 4.4%5.0CVE-2006-3325Id software quake 3 engine vulnerabilityclient/cl_parse.c in the id3 Quake 3 Engine 1.32c and the Icculus Quake 3 Engine (ioquake3) revision 810 and earlier allows remote malicious servers …EPSS 4.8%5.0CVE-2005-0983Activision call of duty vulnerabilityQuake 3 engine, as used in multiple games, allows remote attackers to cause a denial of service (client disconnect) via a long message, which is not …EPSS 2.6%5.0CVE-2005-0430Id software quake 3 engine vulnerabilityThe Quake 3 engine, as used in multiple game packages, allows remote attackers to cause a denial of service (shutdown game server) and possibly crash…EPSS 7.5%

Source: NIST National Vulnerability Database (record CVE-2006-2082), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.