← Vulnerability feed

Vulnerability record · CVE-2006-3401 · published 6 July 2006

CVE-2006-3401: Id software quake 3 engine memory buffer overflow vulnerability

IId Software · Quake 3 Engine

Stack-based buffer overflow in Quake 3 Engine as used by Quake 3: Arena 1.32b and 1.32c allows remote attackers to cause a denial of service and possibly execute code via long CS_ITEMS values.

7.5 CVSS 2.0 High EPSS 5.7% · top 7.2% CWE-119 · Memory buffer overflow
7.5CVSS 2.0 base score
5.7%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
14References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in Quake 3 Engine as used by Quake 3: Arena 1.32b and 1.32c allows remote attackers to cause a denial of service and possibly execute code via long CS_ITEMS values.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2006-3401 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.6CVE-2006-2236Id software quake 3 arena vulnerabilityBuffer overflow in the Quake 3 Engine, as used by (1) ET 2.60, (2) Return to Castle Wolfenstein 1.41, and (3) Quake III Arena 1.32b allows remote att…EPSS 7.6%7.5CVE-2006-3400Id software quake 3 engine vulnerabilityStack-based buffer overflow in the CG_ServerCommand function in Quake 3 Engine as used by Soldier of Fortune 2 (SOF2MP) GOLD 1.03 allows remote attac…EPSS 4.8%7.5CVE-2006-2875Id software quake 3 engine vulnerabilityStack-based buffer overflow in the CL_ParseDownload function of Quake 3 Engine 1.32c and earlier, as used in multiple products, allows remote attacke…EPSS 6.8%7.5CVE-2006-2082Id software quake 3 engine vulnerabilityDirectory traversal vulnerability in Quake 3 engine, as used in products including Quake3 Arena, Return to Castle Wolfenstein, Wolfenstein: Enemy Ter…EPSS 2.6%5.0CVE-2006-3324Id software quake 3 engine vulnerabilityThe Automatic Downloading option in the id3 Quake 3 Engine and the Icculus Quake 3 Engine (ioquake3) before revision 804 allows remote attackers to o…EPSS 4.4%5.0CVE-2006-3325Id software quake 3 engine vulnerabilityclient/cl_parse.c in the id3 Quake 3 Engine 1.32c and the Icculus Quake 3 Engine (ioquake3) revision 810 and earlier allows remote malicious servers …EPSS 4.8%5.0CVE-2005-0983Activision call of duty vulnerabilityQuake 3 engine, as used in multiple games, allows remote attackers to cause a denial of service (client disconnect) via a long message, which is not …EPSS 2.6%5.0CVE-2005-0430Id software quake 3 engine vulnerabilityThe Quake 3 engine, as used in multiple game packages, allows remote attackers to cause a denial of service (shutdown game server) and possibly crash…EPSS 7.5%

Source: NIST National Vulnerability Database (record CVE-2006-3401), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.