CVE-2000-0969
Medium
Elevated severity or exploit probability.
CVSS base
10.0
HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS — probability of exploitation (30 days)
3.5%
88.6th percentile
CISA KEV
Not listed
Weakness / dates
—
Published 2000-12-19 · modified 2026-09-23
Description
Format string vulnerability in Half Life dedicated server build 3104 and earlier allows remote attackers to execute arbitrary commands by injecting format strings into the changelevel command, via the system console or rcon.
Affected
References
- http://archives.neohapsis.com/archives/bugtraq/2000-10/0254.html
- http://archives.neohapsis.com/archives/bugtraq/2000-10/0409.html
- http://www.osvdb.org/6983
- http://www.securityfocus.com/archive/1/141060
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5413
- http://archives.neohapsis.com/archives/bugtraq/2000-10/0254.html
- http://archives.neohapsis.com/archives/bugtraq/2000-10/0409.html
- http://www.osvdb.org/6983
- http://www.securityfocus.com/archive/1/141060
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5413