← Vulnerability feed

Vulnerability record · CVE-2006-3325 · published 30 June 2006

CVE-2006-3325: Id software quake 3 engine vulnerability

IId Software · Quake 3 Engine

client/cl_parse.c in the id3 Quake 3 Engine 1.32c and the Icculus Quake 3 Engine (ioquake3) revision 810 and earlier allows remote malicious servers to overwrite arbitrary write-protected cvars variables on the client, such as cl_allowdownload for Automatic Downloading and fs_homepath for the quake3 path, via a string of cvar names and values sent from the server. NOTE: this can be combined with another vulnerability to overwrite arbitrary files.

5.0 CVSS 2.0 Medium EPSS 4.8% · top 8.4%
5.0CVSS 2.0 base score
4.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
20References, 4 tagged exploit
16 Jun 2026Last modified by NVD

Description

client/cl_parse.c in the id3 Quake 3 Engine 1.32c and the Icculus Quake 3 Engine (ioquake3) revision 810 and earlier allows remote malicious servers to overwrite arbitrary write-protected cvars variables on the client, such as cl_allowdownload for Automatic Downloading and fs_homepath for the quake3 path, via a string of cvar names and values sent from the server. NOTE: this can be combined with another vulnerability to overwrite arbitrary files.

AV:N/AC:L/Au:N/C:N/I:P/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2006-3325 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.6CVE-2006-2236Id software quake 3 arena vulnerabilityBuffer overflow in the Quake 3 Engine, as used by (1) ET 2.60, (2) Return to Castle Wolfenstein 1.41, and (3) Quake III Arena 1.32b allows remote att…EPSS 7.6%7.5CVE-2006-3400Id software quake 3 engine vulnerabilityStack-based buffer overflow in the CG_ServerCommand function in Quake 3 Engine as used by Soldier of Fortune 2 (SOF2MP) GOLD 1.03 allows remote attac…EPSS 4.8%7.5CVE-2006-3401Id software quake 3 engine memory buffer overflow vulnerabilityStack-based buffer overflow in Quake 3 Engine as used by Quake 3: Arena 1.32b and 1.32c allows remote attackers to cause a denial of service and poss…EPSS 5.7%7.5CVE-2006-2875Id software quake 3 engine vulnerabilityStack-based buffer overflow in the CL_ParseDownload function of Quake 3 Engine 1.32c and earlier, as used in multiple products, allows remote attacke…EPSS 6.8%7.5CVE-2006-2082Id software quake 3 engine vulnerabilityDirectory traversal vulnerability in Quake 3 engine, as used in products including Quake3 Arena, Return to Castle Wolfenstein, Wolfenstein: Enemy Ter…EPSS 2.6%5.0CVE-2006-3324Id software quake 3 engine vulnerabilityThe Automatic Downloading option in the id3 Quake 3 Engine and the Icculus Quake 3 Engine (ioquake3) before revision 804 allows remote attackers to o…EPSS 4.4%5.0CVE-2005-0983Activision call of duty vulnerabilityQuake 3 engine, as used in multiple games, allows remote attackers to cause a denial of service (client disconnect) via a long message, which is not …EPSS 2.6%5.0CVE-2005-0430Id software quake 3 engine vulnerabilityThe Quake 3 engine, as used in multiple game packages, allows remote attackers to cause a denial of service (shutdown game server) and possibly crash…EPSS 7.5%

Source: NIST National Vulnerability Database (record CVE-2006-3325), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.