Valvesoftware / Steam Client
9 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2021-30481 | Valve Steam before 2021-04-17, when a Source engine game is installed, allows remote authenticated users to execute arbitrary code because of a buffer overflow… | CRITICAL | 9.0 | Apr 10, 2021 |
| CVE-2020-15530 | An issue was discovered in Valve Steam Client 2.10.91.91. The installer allows local users to gain NT AUTHORITY\SYSTEM privileges because some parts of %PROGRA… | HIGH | 7.8 | Jul 5, 2020 |
| CVE-2019-17180 | Valve Steam Client before 2019-09-12 allows placing or appending partially controlled filesystem content, as demonstrated by file modifications on Windows in t… | HIGH | 7.8 | Oct 4, 2019 |
| CVE-2019-15316 | Valve Steam Client for Windows through 2019-08-20 has weak folder permissions, leading to privilege escalation (to NT AUTHORITY\SYSTEM) via crafted use of Crea… | HIGH | 7.0 | Aug 21, 2019 |
| CVE-2019-15315 | Valve Steam Client for Windows through 2019-08-16 allows privilege escalation (to NT AUTHORITY\SYSTEM) because local users can replace the current versions of… | HIGH | 7.8 | Aug 21, 2019 |
| CVE-2019-14743 | In Valve Steam Client for Windows through 2019-08-07, HKLM\SOFTWARE\Wow6432Node\Valve\Steam has explicit "Full control" for the Users group, which allows local… | MEDIUM | 6.6 | Aug 7, 2019 |
| CVE-2018-12270 | In Valve Steam 1528829181 BETA, it is possible to perform a homograph / homoglyph attack to create fake URLs in the client, which may trick users into visiting… | MEDIUM | 5.4 | May 20, 2019 |
| CVE-2015-7985 | Valve Steam 2.10.91.91 uses weak permissions (Users: read and write) for the Install folder, which allows local users to gain privileges via a Trojan horse ste… | HIGH | 7.2 | Nov 24, 2015 |
| CVE-2015-4016 | The client detection protocol in Valve Steam allows remote attackers to cause a denial of service (process crash) via a crafted response to a broadcast packet. | MEDIUM | 5.0 | May 20, 2015 |
Showing 1 to 9 of 9 CVEs