Known Vulnerabilities for products from Epic Games

Listed below are 16 of the newest known vulnerabilities associated with the vendor "Epic Games".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2008-7015 json Unreal engine 3, as used in Unreal Tournament 3 1.3, Frontlines: Fuel of War 1.1.1, and other products, allows remote attacke... Not Provided 2009-08-19 2026-04-23
CVE-2008-7011 json The Unreal engine, as used in Unreal Tournament 3 1.3, Unreal Tournament 2003 and 2004, Dead Man's Hand, Pariah, WarPath, Pos... Not Provided 2009-08-19 2026-04-23
CVE-2008-4243 json Directory traversal vulnerability in ImageServer (aka UTImageServer) in WebAdmin before 1.7 for Epic Games Unreal Tournament ... Not Provided 2008-09-25 2026-04-23
CVE-2008-3410 json Unreal Tournament 3 1.3beta4 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and d... Not Provided 2008-07-31 2026-04-23
CVE-2008-3409 json Buffer overflow in Unreal Tournament 3 1.3beta4 and earlier allows remote attackers to cause a denial of service (memory corr... Not Provided 2008-07-31 2026-04-23
CVE-2008-3396 json Unreal Tournament 2004 (UT2004) 3369 and earlier allows remote attackers to cause a denial of service (NULL pointer dereferen... Not Provided 2008-07-31 2026-04-23
CVE-2007-4443 json The UCC dedicated server for the Unreal engine, possibly 2003 and 2004, on Windows allows remote attackers to cause a denial ... Not Provided 2007-08-21 2026-04-23
CVE-2007-4442 json Stack-based buffer overflow in the logging function in the Unreal engine, possibly 2003 and 2004, as used in the internal web... Not Provided 2007-08-21 2026-04-23
CVE-2004-1958 json Directory traversal vulnerability in manifest.ini in Unreal engine allows remote attackers to overwrite arbitrary files via .... Not Provided 2004-12-31 2025-04-03
CVE-2004-1805 json Format string vulnerability in games using the Epic Games Unreal Engine 436 allows remote attackers to cause a denial of serv... Not Provided 2004-12-31 2025-04-03
CVE-2004-0608 json The Unreal Engine, as used in DeusEx 1.112fm and earlier, Devastation 390 and earlier, Mobile Forces 20000 and earlier, Nerf ... Not Provided 2004-12-06 2025-04-03
CVE-2003-1433 json Epic Games Unreal Engine 226f through 436 does not validate the challenge key, which allows remote attackers to exhaust the p... Not Provided 2003-12-31 2025-04-03
CVE-2003-1432 json Epic Games Unreal Engine 226f through 436 allows remote attackers to cause a denial of service (CPU consumption or crash) and... Not Provided 2003-12-31 2025-04-03
CVE-2003-1431 json Buffer overflow in Epic Games Unreal Engine 226f through 436 allows remote attackers to cause a denial of service (crash) via... Not Provided 2003-12-31 2025-04-03
CVE-2003-1430 json Directory traversal vulnerability in Unreal Tournament Server 436 and earlier allows remote attackers to access known files v... Not Provided 2003-12-31 2025-04-03
CVE-2002-1507 json Unreal Tournament 2003 (ut2003) clients and servers allow remote attackers to cause a denial of service via malformed message... Not Provided 2003-04-02 2025-04-03

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report