wesnoth/wesnoth
CVE History
| CVE | Affected | Published | CVSS v3 | CVSS v2 |
|---|---|---|---|---|
| — | — | 4 MEDIUM | ||
The (1) filesystem::get_wml_location function in filesystem.cpp and (2) is_legal_file function in filesystem_boost.cpp in Battle for Wesnoth before 1.12.3 and 1.13.x before 1.13.1 allow remote attackers to obtain sensitive information via vectors related to inclusion of .pbl files from WML. | ||||
| — | — | 3.5 LOW | ||
The (1) filesystem::get_wml_location function in filesystem.cpp and (2) is_legal_file function in filesystem_boost.cpp in Battle for Wesnoth before 1.12.4 and 1.13.x before 1.13.1, when a case-insensitive filesystem is used, allow remote attackers to obtain sensitive information via vectors related to inclusion of .pbl files from WML. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-5069. | ||||
| = 1.1.11, = 1.0, = 1.5.6, = 1.4.6, = 1.1.8, = 1.2.4, = 1.5.4, = 1.5.10, = 1.1, = 1.2.7, = 1.5.3, = 1.4.5, = 1.1.3, = 1.2.2, = 1.2.5, = 1.5.8, = 1.5.7, = 1.5.0, = 1.3.16, = 1.3.17, = 1.5.5, = 1.4.1, = 1.3.10, = 1.2.1, = 1.5.9, = 1.1.14, = 1.1.6, = 1.2.6, = 1.4.3, = 1.4.4, = 1.3.12, = 1.3.13, <= 1.5.11, = 1.1.12, = 1.1.4, = 1.1.10, = 1.4, = 1.3.8, = 1.3.9, = 1.1.13, = 1.1.1, = 1.1.9, = 1.1.7, = 1.2.8, = 1.4.2, = 1.3.11, = 1.3.18, = 1.3.19, = 1.1.2, = 1.2, = 1.2.3, = 1.5.2, = 1.5.1, = 1.4.7, = 1.3.14, = 1.3.15, = 1.1.5 | — | 4.3 MEDIUM | ||
The uncompress_buffer function in src/server/simple_wml.cpp in Wesnoth before r33069 allows remote attackers to cause a denial of service via a large compressed WML document. | ||||
| = 0.8.7, = 1.1.11, = 0.4, = 1.0, = 0.8.9, = 0.7.7, = 0.5, = 0.3.2, = 0.8.4, = 1.1.8, = 1.0rcl, = 0.8.6, = 0.6.99.5, = 0.3.3, = 1.4.6, = 0.9.0, = 1.2.4, = 0.9.5, = 0.8.2, = 0.7.9, = 0.6.99.2, = 0.4.2, = 1.3.6, = 0.9.3, = 0.9.2, = 0.7.4, = 0.4.1, = 1.4.1, = 1.3.3, = 1.3.16, = 1.2.7, = 1.2.1, = 1.1.3, = 1.1, = 0.8.1, = 0.8, = 0.7.11, = 0.5.1, = 0.4.4, = 0.3.4, = 1.4.5, = 1.3.5, = 1.2.5, = 1.1.6, = 1.1.14, = 1.1.1, = 0.8.8, = 0.7, = 0.7.2, = 0.4.6, = 1.3.2, = 1.3.10, = 0.6.99.3, = 0.4.8, = 0.2.1, <= 1.4.7, = 1.4, = 1.3.17, = 1.3.1, = 1.2.2, = 0.9.6, = 0.8.11, = 0.7.5, = 1.4.2, = 1.2.8, = 1.2, = 1.1.7, = 1.1.4, = 0.8.5, = 0.6.99.1, = 0.6.99.4, = 0.4.3, = 1.3.8, = 1.3.18, = 1.3.7, = 1.3.4, = 1.3.15, = 1.2.6, = 1.1.13, = 0.9.7, = 0.9.4, = 0.9.1, = 0.8.3, = 0.7.6, = 0.4.7, = 0.3.1, = 0.3, = 1.4.4, = 1.4.3, = 1.3.19, = 1.3.11, = 1.3.12, = 1.3.13, = 1.1.9, = 1.1.2, = 1.1.5, = 0.7.8, = 0.8.10, = 0.7.3, = 1.3.9, = 1.3.14, = 1.2.3, = 1.1.12, = 1.1.10, = 0.7.10, = 0.7.1, = 0.6, = 0.6.1, = 0.4.5 | — | 5 MEDIUM | ||
The read_game_map function in src/terrain_translation.cpp in Wesnoth before r32987 allows remote attackers to cause a denial of service (memory consumption and daemon hang) via a map with a large (1) width or (2) height. | ||||
| = 1.5.6, = 1.4.6, = 1.5.4, = 1.5.10, = 1.4.5, = 1.5.3, = 1.4.1, = 1.5.7, = 1.5.8, = 1.4, = 1.4.7, = 1.5.0, = 1.5.1, = 1.5.9, = 1.5.2, = 1.4.4, = 1.4.3, = 1.5.5, = 1.4.2 | — | 9.3 HIGH | ||
The Python AI module in Wesnoth 1.4.x and 1.5 before 1.5.11 allows remote attackers to escape the sandbox and execute arbitrary code by using a whitelisted module that imports an unsafe module, then using a hierarchical module name to access the unsafe module through the whitelisted module. | ||||
| = 0.8.7, = 1.1.11, = 0.4, = 0.8.9, = 0.7.7, = 0.5, = 0.3.2, = 0.8.4, = 0.8.2, = 0.4.1, = 0.4.2, = 0.9.2, = 1.1, = 1.2.2, = 0.3.3, = 0.6.99.2, = 0.9.5, = 1.1.8, = 0.3.4, = 0.6.99.5, = 0.7.4, = 0.9.0, = 1.0rcl, = 0.7.9, = 0.8.6, = 0.9.3, = 1.2.4, = 0.2.1, = 0.5.1, = 0.7, = 0.7.1, = 0.7.6, = 1.1.1, = 1.1.10, = 1.1.4, = 1.1.5, = 1.2.3, = 0.4.5, = 0.4.6, = 0.6.99.3, = 0.7.2, = 0.7.3, = 0.8.1, = 0.8.8, = 0.9.6, = 1.1.14, = 1.2.7, = 0.4.8, = 0.7.5, = 0.8.11, = 0.9.7, = 1.1.3, = 1.2.1, = 1.2.8, = 0.3.1, = 0.4.3, = 0.4.4, = 0.7.11, = 0.7.8, = 0.8, = 0.8.5, = 1.1.6, = 1.2.5, = 0.6, = 0.8.3, = 0.9.1, = 0.4.7, = 0.8.10, = 1.1.13, = 1.1.9, = 1.2.6, = 0.6.99.4, = 1.1.2, = 1.2, = 0.3, = 0.6.1, = 0.6.99.1, = 0.7.10, = 0.9.4, = 1.1.12, = 1.1.7 | — | 9 HIGH | ||
Directory traversal vulnerability in the WML engine preprocessor for Wesnoth 1.2.x before 1.2.8, and 1.3.x before 1.3.12, allows remote attackers to read arbitrary files via ".." sequences in unknown vectors. | ||||
| = 1.2.4, = 1.3.6, = 1.2.2, = 1.3.1, = 1.3.10, = 1.2.7, = 1.3.2, = 1.2.1, = 1.3.5, = 1.2.6, = 1.2.3, = 1.3.7, = 1.2.5, = 1.3.4, = 1.2, = 1.3.11, = 1.3.3, = 1.3.9, = 1.3.8 | — | 7.5 HIGH | ||
Unspecified vulnerability in Wesnoth 1.2.x before 1.2.8, and 1.3.x before 1.3.12, allows attackers to cause a denial of service (hang) via a "faulty add-on" and possibly execute other commands via unknown vectors related to the turn_cmd option. | ||||
| = 1.2.4, = 1.3.6, = 1.2.2, = 1.3.1, = 1.3.2, = 1.2.1, = 1.3.5, = 1.3.3, = 1.2.5, = 1.2.6, = 1.3.7, = 1.2.3, = 1.3.4, = 1.2, = 1.3.8 | — | 7.8 HIGH | ||
The multiplayer engine in Wesnoth 1.2.x before 1.2.7 and 1.3.x before 1.3.9 allows remote servers to cause a denial of service (crash) via a long message with multibyte characters that can produce an invalid UTF-8 string after it is truncated, which triggers an uncaught exception, involving the truncate_message function in server/server.cpp. NOTE: this issue affects both clients and servers. | ||||