← Vulnerability feed

Vulnerability record · CVE-2006-2236 · published 8 May 2006

CVE-2006-2236: Id software quake 3 arena vulnerability

IId Software · Quake 3 Arena

Buffer overflow in the Quake 3 Engine, as used by (1) ET 2.60, (2) Return to Castle Wolfenstein 1.41, and (3) Quake III Arena 1.32b allows remote attackers to execute arbitrary commands via a long remapShader command.

7.6 CVSS 2.0 High EPSS 7.6% · top 5.7%
7.6CVSS 2.0 base score
7.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
18References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Buffer overflow in the Quake 3 Engine, as used by (1) ET 2.60, (2) Return to Castle Wolfenstein 1.41, and (3) Quake III Arena 1.32b allows remote attackers to execute arbitrary commands via a long remapShader command.

AV:N/AC:H/Au:N/C:C/I:C/A:C

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2006-2236 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2006-3400Id software quake 3 engine vulnerabilityStack-based buffer overflow in the CG_ServerCommand function in Quake 3 Engine as used by Soldier of Fortune 2 (SOF2MP) GOLD 1.03 allows remote attac…EPSS 4.8%7.5CVE-2006-3401Id software quake 3 engine memory buffer overflow vulnerabilityStack-based buffer overflow in Quake 3 Engine as used by Quake 3: Arena 1.32b and 1.32c allows remote attackers to cause a denial of service and poss…EPSS 5.7%7.5CVE-2006-2875Id software quake 3 engine vulnerabilityStack-based buffer overflow in the CL_ParseDownload function of Quake 3 Engine 1.32c and earlier, as used in multiple products, allows remote attacke…EPSS 6.8%7.5CVE-2006-2082Id software quake 3 engine vulnerabilityDirectory traversal vulnerability in Quake 3 engine, as used in products including Quake3 Arena, Return to Castle Wolfenstein, Wolfenstein: Enemy Ter…EPSS 2.6%6.4CVE-2000-0303Id software quake 3 arena vulnerabilityQuake3 Arena allows malicious server operators to read or modify files on a client via a dot dot (..) attack.EPSS 1.3%5.0CVE-2006-3324Id software quake 3 engine vulnerabilityThe Automatic Downloading option in the id3 Quake 3 Engine and the Icculus Quake 3 Engine (ioquake3) before revision 804 allows remote attackers to o…EPSS 4.4%5.0CVE-2006-3325Id software quake 3 engine vulnerabilityclient/cl_parse.c in the id3 Quake 3 Engine 1.32c and the Icculus Quake 3 Engine (ioquake3) revision 810 and earlier allows remote malicious servers …EPSS 4.8%5.0CVE-2005-0983Activision call of duty vulnerabilityQuake 3 engine, as used in multiple games, allows remote attackers to cause a denial of service (client disconnect) via a long message, which is not …EPSS 2.6%

Source: NIST National Vulnerability Database (record CVE-2006-2236), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.