List Of Video Game Vulnerabilities & Exploits
This is meant to serve as an archive for vulnerabilites related to video games. I had trouble finding a central place for vulnerabilites related to video games (besides looking at cvedetails and exploitdb), so I decided to create a page that does so. I will add to this as go, so feel free to send me a message if you feel that I am missing something!
Table Of Contents
- Blogs & Articles
- BattlEye Anti-Cheat
- Logitech
- Call Of Duty
- Unity
- Consoles (PlayStation, Xbox, Wii)
- Ubisoft
- Epic Games & Unreal Engine/Tournament
- Electronic Arts (EA) & Origin Client
- Valve & Counter-Strike
- Hackerone Reports (thank you reddelexc)
Blogs & Articles
- How a PNG became a $20,000 Hytale RCE
- Cross Site Scripting (XSS) in CS2
- Source engine remote code execution via game invites
- Exploiting the Source Engine (Part 1)
- Exploiting the Source Engine (Part 2) - Full-Chain Client RCE in Source using Frida
- Code execution exploit for Tony Hawk’s video game series (TonyHawksProStrcpy)
- Game Hacking reinvented? - A COD Exploit
- Fun With Custom URI Schemes (Origin Client)
BattlEye Anti-Cheat
- CVE-2022-27095
- BattlEye v0.9 contains an unquoted service path which allows attackers to escalate privileges to the system level.
Logitech
- CVE-2018-0620
- Untrusted search path vulnerability in LOGICOOL Game Software versions before 8.87.116 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
Call Of Duty
Unity
- CVE-2026-54424
- An Incorrect Use of Privileged APIs vulnerability in Unity Parsec on Windows hosts leads to a potential Elevation of Privilege. This issue affects Parsec through v2026-05-04.0. The patched version is Parsec for Windows version 150-104a. A user can generate a situation where there is an instance of
parsecd.exerunning asNT AUTHORITY\SYSTEMwith a user-controlled value of theAppDataenvironment variable.
- An Incorrect Use of Privileged APIs vulnerability in Unity Parsec on Windows hosts leads to a potential Elevation of Privilege. This issue affects Parsec through v2026-05-04.0. The patched version is Parsec for Windows version 150-104a. A user can generate a situation where there is an instance of
- CVE-2025-59489
- Unity Runtime before 2025-10-02 on Android, Windows, macOS, and Linux allows argument injection that can result in loading of library code from an unintended location. If an application was built with a version of Unity Editor that had the vulnerable Unity Runtime code, then an adversary may be able to execute code on, and exfiltrate confidential information from, the machine on which that application is running. NOTE: product status is provided for Unity Editor because that is the information available from the Supplier. However, updating Unity Editor typically does not address the effects of the vulnerability; instead, it is necessary to rebuild and redeploy all affected applications.
- CVE-2023-37250
- Unity Parsec has a time of check, time of use (TOCTOU) race condition that permits local attackers to escalate privileges to SYSTEM if Parsec was installed in “Per User” mode. The application intentionally launches DLLs from a user-owned directory but intended to always perform integrity verification of those DLLs. This affects Parsec Loader versions through 8. Parsec Loader 9 is a fixed version.
- CVE-2015-9288
- The Unity Web Player plugin before 4.6.6f2 and 5.x before 5.0.3f2 allows attackers to read messages or access online services via a victim’s credentials
Consoles (PlayStation, Xbox, Wii)
PlayStation (Portable, 3, 4 and 5)
- CVE-2022-3349
- A vulnerability was found in Sony PS4 and PS5. It has been classified as critical. This affects the function UVFAT_readupcasetable of the component exFAT Handler. The manipulation of the argument dataLength leads to heap-based buffer overflow. It is possible to launch the attack on the physical device. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-209679.
- CVE-2009-2541
- The web browser on the Sony PLAYSTATION 3 (PS3) allows remote attackers to cause a denial of service (memory consumption and console hang) via a large integer value for the length property of a Select object, a related issue to
CVE-2009-1692.
- The web browser on the Sony PLAYSTATION 3 (PS3) allows remote attackers to cause a denial of service (memory consumption and console hang) via a large integer value for the length property of a Select object, a related issue to
- CVE-2007-1728
- The Remote Play feature in Sony Playstation 3 (PS3) 1.60 and Playstation Portable (PSP) 3.10 OE-A allows remote attackers to cause a denial of service via a flood of UDP packets.
- CVE-2006-4507
- Unspecified vulnerability in the TIFF viewer (possibly libTIFF) in the Photo Viewer in the Sony PlaystationPortable (PSP) 2.00 through 2.80 allows local users to execute arbitrary code via crafted TIFF images. NOTE: due to lack of details, it is not clear whether this is related to other issues such as CVE-2006-3464 or CVE-2006-3465.
- CVE-2005-3084
- Buffer overflow in the TIFF library in the Photo Viewer for Sony PSP 2.0 firmware allows remote attackers to cause a denial of service via a crafted TIFF image.
Xbox (360 & One)
- CVE-2020-12695
- The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment than the fully qualified event-subscription URL, aka the CallStranger issue.
- CVE-2007-1221
- The Hypervisor in Microsoft Xbox 360 kernel 4532 and 4548 allows attackers with physical access to force execution of the hypervisor syscall with a certain register set, which bypasses intended code protection.
- CVE-2007-1220
- The Hypervisor in Microsoft Xbox 360 kernel 4532 and 4548 does not properly verify the parameters passed to the syscall dispatcher, which allows attackers with physical access to bypass code-signing requirements and execute arbitrary code.
Wii Exploits & Vulns
- CVE-2024-34454
- Nintendo Wii U OS 5.5.5 allows man-in-the-middle attackers to forge SSL certificates as though they came from a Root CA, because there is a secondary verification mechanism that only checks whether a CA is known and ignores the CA details and signature (and because * is accepted as a Common Name).
- BlueBomb
- BlueBomb is an exploit that takes advantage of a flaw in the Wii and Wii mini’s Bluetooth libraries. Although it is the only exploit that works for the Wii mini, BlueBomb can run on the original Wii as well. This exploit also enables recovery from certain bricks in the event of no other brick protection, such as banner bricks and (some) theme bricks
- FlashHax
- FlashHax is an exploit for the Wii that is triggered by using the Internet Channel. Unlike other exploits, this doesn’t require an SD card.
- letterbomb
- LetterBomb is an exploit for the Wii that is triggered using the Wii Message Board.
- wilbrand
- Wilbrand is an exploit for the Wii that is triggered using the Wii Message Board.
- str2hax
- str2hax is an exploit for the Wii that is triggered by loading the Wii’s End User License Agreement. It requires nothing but an Internet connection that lets you change the DNS on your Wii.
- szsHaxx
- Overflows the Mario Kart Wii competition data output buffer, resulting in the ability to execute arbitrary code.
- Return of the Jodi
- Loads a hacked game save on the Wii System Memory through LEGO Star Wars: The Complete Saga.
- Bathaxx
- Loads a hacked game save on the Wii System Memory through LEGO Batman.
- Indiana Pwns
- Loads a hacked game save on the Wii System Memory through LEGO Indiana Jones.
- Twilight Hack
- Loads a hacked game save on the Wii System Memory through The Legend of Zelda: Twilight Princess.
Ubisoft
- CVE-2019-14737
- Ubisoft Uplay 92.0.0.6280 has Insecure Permissions.
- CVE-2018-15832
upc.exein Ubisoft Uplay Desktop Client versions 63.0.5699.0 allows remote attackers to execute arbitrary code. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of URI handlers. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code under the context of the current process.
Epic Games & Unreal Engine/Tournament
- CVE-2008-7015
- Unreal engine 3, as used in Unreal Tournament 3 1.3, Frontlines: Fuel of War 1.1.1, and other products, allows remote attackers to cause a denial of service (server exit) via a packet with a large length value that triggers a memory allocation failure.
- CVE-2008-7011
- The Unreal engine, as used in Unreal Tournament 3 1.3, Unreal Tournament 2003 and 2004, Dead Man’s Hand, Pariah, WarPath, Postal2, and Shadow Ops, allows remote authenticated users to cause a denial of service (server exit) via multiple file downloads from the server, which triggers an assertion failure when the Closing flag in
UnChan.cppis set.
- The Unreal engine, as used in Unreal Tournament 3 1.3, Unreal Tournament 2003 and 2004, Dead Man’s Hand, Pariah, WarPath, Postal2, and Shadow Ops, allows remote authenticated users to cause a denial of service (server exit) via multiple file downloads from the server, which triggers an assertion failure when the Closing flag in
- CVE-2008-4243
- Directory traversal vulnerability in ImageServer (aka
UTImageServer) in WebAdmin before 1.7 for Epic Games Unreal Tournament 3 (UT3) 1.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.
- Directory traversal vulnerability in ImageServer (aka
- CVE-2008-3410
- Unreal Tournament 3 1.3beta4 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a UDP packet in which the value of a certain size field is greater than the total packet length, aka attack 2 in
ut3mendo.c.
- Unreal Tournament 3 1.3beta4 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a UDP packet in which the value of a certain size field is greater than the total packet length, aka attack 2 in
- CVE-2008-3409
- Buffer overflow in Unreal Tournament 3 1.3beta4 and earlier allows remote attackers to cause a denial of service (memory corruption and daemon crash) or possibly execute arbitrary code via a UDP packet containing a large value in a certain size field, followed by a data string of that size, aka attack 1 in
ut3mendo.c.
- Buffer overflow in Unreal Tournament 3 1.3beta4 and earlier allows remote attackers to cause a denial of service (memory corruption and daemon crash) or possibly execute arbitrary code via a UDP packet containing a large value in a certain size field, followed by a data string of that size, aka attack 1 in
- CVE-2008-3396
- Unreal Tournament 2004 (UT2004) 3369 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a certain sequence of malformed packets.
- CVE-2007-4443
- The UCC dedicated server for the Unreal engine, possibly 2003 and 2004, on Windows allows remote attackers to cause a denial of service (continuous beep and server slowdown) via a string containing many 0x07 characters in (1) a request to the images/ directory, (2) the Content-Type field, (3) a HEAD request, and possibly other unspecified vectors.
- CVE-2007-4442
- Stack-based buffer overflow in the logging function in the Unreal engine, possibly 2003 and 2004, as used in the internal web server, allows remote attackers to cause a denial of service (application crash) via a request for a long .gif filename in the images/ directory, related to conversion from Unicode to ASCII.
- CVE-2004-1958
- Directory traversal vulnerability in manifest.ini in Unreal engine allows remote attackers to overwrite arbitrary files via .. (dot dot) sequences in a UMOD (Unreal MOD) file.
- CVE-2004-1805
- Format string vulnerability in games using the Epic Games Unreal Engine 436 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in class names.
- CVE-2004-0608
- The Unreal Engine, as used in DeusEx 1.112fm and earlier, Devastation 390 and earlier, Mobile Forces 20000 and earlier, Nerf Arena Blast 1.2 and earlier, Postal 2 1337 and earlier, Rune 107 and earlier, Tactical Ops 3.4.0 and earlier, Unreal 1 226f and earlier, Unreal II XMP 7710 and earlier, Unreal Tournament 451b and earlier, Unreal Tournament 2003 2225 and earlier, Unreal Tournament 2004 before 3236, Wheel of Time 333b and earlier, and X-com Enforcer, allows remote attackers to execute arbitrary code via a UDP packet containing a secure query with a long value, which overwrites memory.
- CVE-2003-1433
- Epic Games Unreal Engine 226f through 436 does not validate the challenge key, which allows remote attackers to exhaust the player limit by joining the game multiple times.
- CVE-2003-1432
- Epic Games Unreal Engine 226f through 436 allows remote attackers to cause a denial of service (CPU consumption or crash) and possibly execute arbitrary code via (1) a packet with a negative size value, which is treated as a large positive number during memory allocation, or (2) a negative size value in a package file.
- CVE-2003-1431
- Buffer overflow in Epic Games Unreal Engine 226f through 436 allows remote attackers to cause a denial of service (crash) via a long host string in the Unreal URL.
- CVE-2003-1430
- Directory traversal vulnerability in Unreal Tournament Server 436 and earlier allows remote attackers to access known files via a “..” (dot dot) in an
unreal://URL.
- Directory traversal vulnerability in Unreal Tournament Server 436 and earlier allows remote attackers to access known files via a “..” (dot dot) in an
- CVE-2002-1507
- Unreal Tournament 2003 (ut2003) clients and servers allow remote attackers to cause a denial of service via malformed messages containing a small number of characters to UDP ports
7778or10777.
- Unreal Tournament 2003 (ut2003) clients and servers allow remote attackers to cause a denial of service via malformed messages containing a small number of characters to UDP ports
Origin Client & Electronic Arts (EA)
- CVE-2020-15914
- A cross-site scripting (XSS) vulnerability exists in the Origin Client for Mac and PC 10.5.86 or earlier that could allow a remote attacker to execute arbitrary Javascript in a target user’s Origin client. An attacker could use this vulnerability to access sensitive data related to the target user’s Origin account, or to control or monitor the Origin text chat window.
- CVE-2020-27708
- A vulnerability exists in the Origin Client that could allow a non-Administrative user to elevate their access to either Administrator or System.
- CVE-2019-19741
- Electronic Arts Origin 10.5.55.33574 is vulnerable to local privilege escalation due to arbitrary directory DACL manipulation, a different issue than CVE-2019-19247 and CVE-2019-19248. When
Origin.execonnects to the named pipeOriginClientService, the privileged service verifies the client’s executable file instead of its in-memory process (which can be significantly different from the executable file due to, for example, DLL injection). Data transmitted over the pipe is encrypted using a static key. Instead of hooking the pipe communication directly via WriteFileEx(), this can be bypassed by hooking theEVP_EncryptUpdate()function oflibeay32.dll. The pipe takes the commandCreateDirectoryto create a directory and adjust the directory DACL. Calls to this function can be intercepted, the directory and the DACL can be replaced, and the manipulated DACL is written. Arbitrary DACL write is further achieved by creating a hardlink in a user-controlled directory that points to (for example) a service binary. The DACL is then written to this service binary, which results in escalation of privileges.
- Electronic Arts Origin 10.5.55.33574 is vulnerable to local privilege escalation due to arbitrary directory DACL manipulation, a different issue than CVE-2019-19247 and CVE-2019-19248. When
- CVE-2019-19247 & CVE-2019-19248
- Electronic Arts Origin through 10.5.x allows Elevation of Privilege
- CVE-2019-12828
- An issue was discovered in Electronic Arts Origin before 10.5.39. Due to improper sanitization of the
origin://andorigin2://URI schemes, it is possible to inject additional arguments into the Origin process and ultimately leverage code execution by loading a backdoored Qt plugin remotely via theplatformpluginpathargument supplied with a Windows network share.
- An issue was discovered in Electronic Arts Origin before 10.5.39. Due to improper sanitization of the
- CVE-2019-11354
- The client in Electronic Arts (EA) Origin 10.5.36 on Windows allows template injection in the title parameter of the Origin2 URI handler. This can be used to escape the underlying AngularJS sandbox and achieve remote code execution via an origin2://game/launch URL for QtApplication QDesktopServices communication.
- CVE-2010-2627
- Multiple directory traversal vulnerabilities in the Refractor 2 engine, as used in Battlefield 2 1.50 (1.5.3153-802.0) and earlier, and Battlefield 2142 (1.10.48.0) and earlier, allow remote servers to overwrite arbitrary files on the client via “.." (dot dot backslash) sequences in URLs for the (1) sponsor or (2) community logos, and other URLs related to (3) DemoDownloadURL, (4) DemoIndexURL and (5) CustomMapsURL.
Counter-Strike & Valve
- CVE-2023-38312
- A directory traversal vulnerability in Valve Counter-Strike 8684 allows a client (with remote control access to a game server) to read arbitrary files from the underlying server via the
motdfileconsole variable.
- A directory traversal vulnerability in Valve Counter-Strike 8684 allows a client (with remote control access to a game server) to read arbitrary files from the underlying server via the
- CVE-2023-35855
- A buffer overflow in Counter-Strike through 8684 allows a game server to execute arbitrary code on a remote client’s machine by modifying the
lservercfgfileconsole variable.
- A buffer overflow in Counter-Strike through 8684 allows a game server to execute arbitrary code on a remote client’s machine by modifying the
- CVE-2023-30382
- A buffer overflow in the component
hl.exeof Valve Half-Life up to 5433873 allows attackers to execute arbitrary code and escalate privileges by supplying crafted parameters.
- A buffer overflow in the component
- CVE-2021-30481
- Valve Steam before 2021-04-17, when a Source engine game is installed, allows remote authenticated users to execute arbitrary code because of a buffer overflow that occurs for a Steam invite after one click.
- CVE-2020-15530
- An issue was discovered in Valve Steam Client 2.10.91.91. The installer allows local users to gain
NT AUTHORITY\SYSTEMprivileges because some parts of%PROGRAMFILES(X86)%\Steamand/or%COMMONPROGRAMFILES(X86)%\Steamhave weak permissions during a critical time window. An attacker can make this time window arbitrarily long by using opportunistic locks.
- An issue was discovered in Valve Steam Client 2.10.91.91. The installer allows local users to gain
- CVE-2020-12242
- Valve Source allows local users to gain privileges by writing to the
/tmp/hl2_relaunchfile, which is later executed in the context of a different user account.
- Valve Source allows local users to gain privileges by writing to the
- CVE-2020-9005
meshsystem.dllin Valve Dota 2 through 2020-02-17 allows remote attackers to achieve code execution or denial of service by creating a gaming server with a crafted map and inviting a victim to this server. AGetValuecall is mishandled.
- CVE-2020-7952
rendersystemdx9.dllin Valve Dota 2 before 7.23f allows remote attackers to achieve code execution or denial of service by creating a gaming server and inviting a victim to this server, because a crafted map is affected by memory corruption.
- CVE-2020-7951
meshsystem.dllin Valve Dota 2 before 7.23e allows remote attackers to achieve code execution or denial of service by creating a gaming server and inviting a victim to this server, because a crafted map is affected by memory corruption.
- CVE-2020-7950
meshsystem.dllin Valve Dota 2 before 7.23f allows remote attackers to achieve code execution or denial of service by creating a gaming server and inviting a victim to this server, because a crafted map is mishandled during a vulnerable function call.
- CVE-2020-7949
schemasystem.dllin Valve Dota 2 before 7.23f allows remote attackers to achieve code execution or denial of service by creating a gaming server and inviting a victim to this server, because a crafted map is mishandled during aGetValuecall.
- CVE-2020-6019
- Valve’s Game Networking Sockets prior to version v1.2.0 improperly handles inlined statistics messages in function
CConnectionTransportUDPBase::Received_Data(), leading to an exception thrown fromlibprotobufand resulting in a crash.
- Valve’s Game Networking Sockets prior to version v1.2.0 improperly handles inlined statistics messages in function
- CVE-2020-6018
- Valve’s Game Networking Sockets prior to version v1.2.0 improperly handles long encrypted messages in function
AES_GCM_DecryptContext::Decrypt()when compiled usinglibsodium, leading to a stack-based buffer overflow and resulting in memory corruption and possibly remote code execution.
- Valve’s Game Networking Sockets prior to version v1.2.0 improperly handles long encrypted messages in function
- CVE-2020-6017
- Valve’s Game Networking Sockets prior to version v1.2.0 improperly handles long unreliable segments in function
SNP_ReceiveUnreliableSegment()when configured to support plain-text messages, leading to a heap-based buffer overflow and resulting in memory corruption and possibly remote code execution.
- Valve’s Game Networking Sockets prior to version v1.2.0 improperly handles long unreliable segments in function
- CVE-2020-6016
- Valve’s Game Networking Sockets prior to version v1.2.0 improperly handles unreliable segments with negative offsets in function
SNP_ReceiveUnreliableSegment(), leading to a heap-based buffer underflow and afree()of memory not from the heap, resulting in memory corruption and probably remote code execution.
- Valve’s Game Networking Sockets prior to version v1.2.0 improperly handles unreliable segments with negative offsets in function
- CVE-2019-17180
- Valve Steam Client before 2019-09-12 allows placing or appending partially controlled filesystem content, as demonstrated by file modifications on Windows in the context of
NT AUTHORITY\SYSTEM. This could lead to denial of service, elevation of privilege, or unspecified other impact.
- Valve Steam Client before 2019-09-12 allows placing or appending partially controlled filesystem content, as demonstrated by file modifications on Windows in the context of
- CVE-2019-15944
- In Counter-Strike: Global Offensive before 8/29/2019, community game servers can display unsafe HTML in a disconnection message.
- CVE-2019-15943
vphysics.dllin Counter-Strike: Global Offensive before 1.37.1.1 allows remote attackers to achieve code execution or denial of service by creating a gaming server and inviting a victim to this server, because a crafted map is mishandled during amemsetcall.
- CVE-2019-15316
- Valve Steam Client for Windows through 2019-08-20 has weak folder permissions, leading to privilege escalation to
NT AUTHORITY\SYSTEMvia crafted use ofCreateMountPoint.exeandSetOpLock.exeto leverage a TOCTOU race condition.
- Valve Steam Client for Windows through 2019-08-20 has weak folder permissions, leading to privilege escalation to
- CVE-2019-15315
- Valve Steam Client for Windows through 2019-08-16 allows privilege escalation to
NT AUTHORITY\SYSTEMbecause local users can replace the current versions ofSteamService.exeandSteamService.dllwith older versions that lack the CVE-2019-14743 patch.
- Valve Steam Client for Windows through 2019-08-16 allows privilege escalation to
- CVE-2019-14743
- In Valve Steam Client for Windows through 2019-08-07,
HKLM\SOFTWARE\Wow6432Node\Valve\Steamhas explicit “Full control” for the Users group, which allows local users to gainNT AUTHORITY\SYSTEMaccess.
- In Valve Steam Client for Windows through 2019-08-07,
- CVE-2018-12270
- In Valve Steam beta, it is possible to perform a homograph or homoglyph attack to create fake URLs in the client, which may trick users into visiting unintended websites.
- CVE-2017-17878
- An issue in Valve Steam Link build 643 causes root passwords longer than 8 characters to be truncated due to the default use of DES.
- CVE-2017-17877
- An issue in Valve Steam Link build 643 exposes the SSH daemon publicly over IPv6, making it easier for remote attackers to attempt root login, especially when combined with CVE-2017-17878.
- CVE-2016-5237
- Valve Steam uses weak permissions for files in the program directory, allowing local users to modify files and potentially gain privileges via a Trojan horse
Steam.exe.
- Valve Steam uses weak permissions for files in the program directory, allowing local users to modify files and potentially gain privileges via a Trojan horse
- CVE-2015-7985
- Valve Steam uses weak permissions for the Install folder, allowing local users to gain privileges via a Trojan horse
steam.exefile.
- Valve Steam uses weak permissions for the Install folder, allowing local users to gain privileges via a Trojan horse
- CVE-2015-4016
- The client detection protocol in Valve Steam allows remote attackers to cause a denial of service via a crafted response to a broadcast packet.
- CVE-2013-7128
- Valve Bug Reporter in SteamOS stores cleartext credentials in a configuration file, allowing local users to obtain sensitive information.
- CVE-2008-7203
- Valve Software Half-Life Counter-Strike 1.6 allows remote attackers to cause a denial of service (crash) via multiple crafted login packets.
Hackerone Reports
Razer
- 🐞 OS Command Injection at https://sea-web.gold.razer.com/lab/ws-lookup via IP parameter to Razer - 676 upvotes, $2000
- 🐞 OS Command Injection at https://sea-web.gold.razer.com/lab/ws-lookup via IP parameter to Razer - 676 upvotes, $2000
- SQL injection at https://sea-web.gold.razer.com/ajax-get-status.php via txid parameter to Razer - 580 upvotes, $2000
- SQL Injection in https://api-my.pay.razer.com/inviteFriend/getInviteHistoryLog to Razer - 528 upvotes, $2000
- OTP token bypass in accessing user settings to Razer - 339 upvotes, $1000
- [Razer Pay Mobile App] Broken access control allowing other user’s bank account to be deleted to Razer - 311 upvotes, $1000
- [Razer Pay Mobile App] Broken access control allowing other user’s bank account to be deleted to Razer - 311 upvotes, $1000
- Reflected XSS at https://pay.gold.razer.com escalated to account takeover to Razer - 287 upvotes, $750
- SQL Injection at https://sea-web.gold.razer.com/lab/cash-card-incomplete-translog-resend via period-hour Parameter to Razer - 240 upvotes, $2000
- [api.easy2pay.co] SQL Injection at fortumo via TransID parameter [Bypassing Signature Validation🔥] to Razer - 232 upvotes, $4000
- [api.easy2pay.co] SQL Injection at fortumo via TransID parameter [Bypassing Signature Validation🔥] to Razer - 232 upvotes, $4000
- Admin Management - Login Using Default Password - Leads to Image Upload Backdoor/Shell to Razer - 199 upvotes, $200
- Through blocking the redirect in /* the attacker able to bypass Authentication To see Sensitive Data sush as Game Keys , Emails ,.. to Razer - 196 upvotes, $1000
- Through blocking the redirect in /* the attacker able to bypass Authentication To see Sensitive Data sush as Game Keys , Emails ,.. to Razer - 196 upvotes, $1000
- Unauthenticated access to sensitive user information to Razer - 184 upvotes, $500
- SQLi at https://sea-web.gold.razer.com/demo-th/purchase-result.php via orderid Parameter to Razer - 183 upvotes, $2000
- [IDOR] API endpoint leaking sensitive user information to Razer - 172 upvotes, $375
- Misconfigured s3 Bucket exposure to Razer - 168 upvotes, $500
- Accessible Druid Monitor console on https://api.pay-staging.razer.com/ to Razer - 126 upvotes, $1500
- SQL injection in Razer Gold List Admin at /lists/index.php via the
list[]parameter. to Razer - 122 upvotes, $2000 - SQL Injection at api.easy2pay.co/add-on/get-sig.php via partner_id Parameter to Razer - 119 upvotes, $2000
- HTML injection in support.razer.com [IE only] to Razer - 109 upvotes, $250
- DOM XSS at https://www.thx.com in IE/Edge browser to Razer - 102 upvotes, $250
- [Razer Pay Android App] Multiple vulnerabilities chained to allow “RedPacket” money to be stolen by a 3rd party to Razer - 84 upvotes, $1000
- [pay.gold.razer.com] Stored XSS - Order payment to Razer - 81 upvotes, $1500
- Blind SQL Injection at http://easytopup.in.th/es-services/mps.php via serial_no parameter to Razer - 80 upvotes, $1000
- 2FA doesn’t work in “https://insider.razer.com” to Razer - 72 upvotes, $200
- SQL injection at https://sea-web.gold.razer.com/demo-th/goto-e2p-web-api.php via Multiple Parameters to Razer - 71 upvotes, $2000
- Blind SQL Injection(Time Based Payload) in https://www.easytopup.in.th/store/game/digimon-master via CheckuserForm[user_id] to Razer - 68 upvotes, $1000
- [SSRF] Server-Side Request Forgery at https://sea-web.gold.razer.com/dev/simulator via notify_url Parameter to Razer - 60 upvotes, $2000
- Payment PIN Verification Bypass to Razer - 57 upvotes, $1000
- Reflected XSS at http://promotion.molthailand.com/index.php via promotion_id parameter to Razer - 55 upvotes, $250
- Insecure Logging - OWASP (2016-M2) to Razer - 45 upvotes, $400
- Improper access control on easytopup.in.th transaction page leads to user’s information disclosure and may lead to account hijacking to Razer - 41 upvotes, $1000
- Improper access control on easytopup.in.th transaction page leads to user’s information disclosure and may lead to account hijacking to Razer - 41 upvotes, $1000
- Improper Authorization at https://api-my.pay.razer.com/v1/trxDetail?trxId=[Id] allowing unauthorised access to other user’s transaction details to Razer - 40 upvotes, $500
- dom based xss on [hello.merchant.razer.com] to Razer - 36 upvotes, $500
- Cookie based XSS on http://ftp1.thx.com to Razer - 31 upvotes, $375
- [razer-assets2] Listing of Amazon S3 Bucket accessible to any AWS cli to Razer - 27 upvotes, $250
- DLL Hijacking in Synapse 2 CrashSender1402.exe via version.dll to Razer - 26 upvotes, $750
- Expired reCAPTCHA site key leads to Rate Limit Bypass and Email Enumeration to Razer - 26 upvotes, $200
- IDOR in eform.molpay.com leads to see other users application forms with private data to Razer - 21 upvotes, $500
- Insecure Processing of XML leads to Denial of Service through Billion Laughs Attack to Razer - 21 upvotes, $375
- Insecure Processing of XML leads to Denial of Service through Billion Laughs Attack to Razer - 21 upvotes, $375
- Insecure HostnameVerifier within WebView of Razer Pay Android (TLS Vulnerability) to Razer - 20 upvotes, $750
- Request Smuggling vulnerability due a vulnerable skipper reverse proxy running in the environment. to Razer - 18 upvotes, $375
- Subdomain takeover at iosota.razersynapse.com via Amazon S3 to Razer - 18 upvotes, $200
- Reflected XSS on molpay.com with cloudflare bypass to Razer - 17 upvotes, $375
- Reflected XSS on https://www.easytopup.in.th/store/product/return on parameter mref_id to Razer - 17 upvotes, $250
- [press.razer.com] Origin IP found, Cloudflare bypassed to Razer - 17 upvotes, $200
- PHPInfo Page on www.razer.ru to Razer - 17 upvotes, $0
- Access to support tickets and payment history, impersonate razer support staff to Razer - 16 upvotes, $1500
- Reflected XSS at https://sea-web.gold.razer.com/cash-card/verify via channel parameter to Razer - 15 upvotes, $500
- Subdomain takeover at ftp.thx.com to Razer - 15 upvotes, $250
- AWS subdomain Takeover at estore.razersynapse.com to Razer - 15 upvotes, $250
- https://zest.co.th/zestlinepay/checkproduct API endpoint suffers from Boolean-based SQL injection to Razer - 15 upvotes, $0
- Leftover back-end system on www.zest.co.th allows an unauthorized attacker to generate Razer Gold Pin for free to Razer - 14 upvotes, $375
- Leftover back-end system on www.zest.co.th allows an unauthorized attacker to generate Razer Gold Pin for free to Razer - 14 upvotes, $375
- [api.easy2pay.co] SQL Injection in cashcard via card_no parameter ⭐️Bypassing IP whitelist⭐️ to Razer - 14 upvotes, $0
- [Razer Pay Mobile App] IDOR within /v1_IM/friends/queryDrawRedLog allowed unauthorised access to read logs to Razer - 12 upvotes, $500
- Post Based Reflected XSS on [https://investor.razer.com/s/ir_contact.php] to Razer - 12 upvotes, $375
- Helpdesk takeover (subdomain takeover) in razerzone.com domain via unclaimed Zendesk instance to Razer - 12 upvotes, $250
- Source Code Disclosure to Razer - 12 upvotes, $200
- THX Tuneup Survey feedback disclosure via Google cached content for apps.thx.com to Razer - 12 upvotes, $200
- DOM-based XSS on https://zest.co.th/zestlinepay/ to Razer - 10 upvotes, $200
- Reflected XSS in eform.molpay.com to Razer - 9 upvotes, $375
- Aws bucket writable mobile.razer.com to Razer - 9 upvotes, $250
- Misconfigured Bucket [razer-assets2] https://assets2.razerzone.com/ to Razer - 9 upvotes, $250
- Information disclosure at http://sea-s2s.molthailand.com/status.php to Razer - 8 upvotes, $375
- Race Condition in Oauth 2.0 flow can lead to malicious applications create multiple valid sessions to Razer - 8 upvotes, $250
- [Razer Pay] Broken Access Control at /v1/verifyPhone/ allows enumeration of usernames and ID information to Razer - 6 upvotes, $500
- Store Cross-Site Scripting - www.razer.ru to Razer - 5 upvotes, $200
- User Access Control Bypass Via Razer elevated service ( RzKLService.exe ) which loads exe in misconfigured way. to Razer - 3 upvotes, $750
- RXSS at https://api.easy2pay.co/inquiry.php via txid parameter. to Razer - 2 upvotes, $250
Valve
- RCE on Steam Client via buffer overflow in Server Info to Valve - 1251 upvotes, $18000
- Getting all the CD keys of any game to Valve - 598 upvotes, $20000
- XSS in steam react chat client to Valve - 448 upvotes, $7500
- Panorama UI XSS leads to Remote Code Execution via Kick/Disconnect Message to Valve - 406 upvotes, $9000
- Modify in-flight data to payment provider Smart2Pay to Valve - 374 upvotes, $7500
- SQL Injection in report_xml.php through countryFilter[] parameter to Valve - 344 upvotes, $25000
- Malformed .BMP file in Counter-Strike 1.6 may cause shellcode injection to Valve - 317 upvotes, $2000
- Malformed NAV file leads to buffer overflow and code execution in Left4Dead2.exe to Valve - 261 upvotes, $10000
- Unchecked weapon id in WeaponList message parser on client leads to RCE to Valve - 224 upvotes, $3000
- OOB reads in network message handlers leads to RCE to Valve - 203 upvotes, $7500
- RCE on CS:GO client using unsanitized entity ID in EntityMsg message to Valve - 197 upvotes, $9000
- Buffer overrun in Steam SILK voice decoder to Valve - 177 upvotes, $7500
- [Portal 2] Remote Code Execution via voice packets to Valve - 165 upvotes, $5000
- [Half-Life 1] Malformed map name leads to memory corruption and code execution to Valve - 162 upvotes, $1500
- Malformed .BSP Access Violation in CS:GO can lead to Remote Code Execution to Valve - 149 upvotes, $12500
- ISteamAssets gives partners control over unrelated community market transactions to Valve - 105 upvotes, $5000
- MySQL username and password leaked in developer.valvesoftware.com via source code dislosure to Valve - 105 upvotes, $1000
- Specially Crafted Closed Captions File can lead to Remote Code Execution in CS:GO and other Source Games to Valve - 104 upvotes, $7500
- [help.steampowered.com] Account takeover bruteforcing SteamGuard to Valve - 104 upvotes, $2500
- Malformed save files (.sav) allow to write files with arbitrary extensions and content in GoldSrc-based games. to Valve - 99 upvotes, $1500
- Malformed .MDL triggers an Access Violation on GoldSRC (hl.exe) to Valve - 89 upvotes, $2000
- ImageMagick GIF coder vulnerability leading to memory disclosure to Valve - 85 upvotes, $1000
- Access to microtransaction sales data for lots of apps from 2014 to present at /valvefinance/sanity/ to Valve - 80 upvotes, $9000
- [steam client] Opening a specific steam:// url overwrites files at an arbitrary location to Valve - 78 upvotes, $750
- Arbitrary File Write as SYSTEM from unprivileged user to Valve - 70 upvotes, $1250
- Malformed playlist.txt in GoldSrc games leads to Access Violation & arbitrary code execution to Valve - 62 upvotes, $1000
- CS:GO Server -> Client RCE through OOB access in CSVCMsg_SplitScreen + Info leak in HTTP download to Valve - 60 upvotes, $7500
- [Source Engine] Material path truncation leads to Remote Code Execution to Valve - 56 upvotes, $2500
- Steam chat - trade offer presentation vulnerability to Valve - 56 upvotes, $750
- Buffer overflow In hl.exe’s launch -game argument allows an attacker to execute arbitrary code locally or from browser to Valve - 54 upvotes, $1150
- Big Picture web browser leaks login cookies and discloses sensitive information (may lead to account takeover) to Valve - 52 upvotes, $2500
- Link filter protection bypass to Valve - 50 upvotes, $750
- [CS:GO] Unchecked texture file name with TEXTUREFLAGS_DEPTHRENDERTARGET can lead to Remote Code Execution to Valve - 46 upvotes, $2500
- Arbitrary file creation with semi-controlled content (leads to DoS, EoP and others) at Steam Windows Client to Valve - 41 upvotes, $1250
- Stored XXS @ https://steamcommunity.com/search/users/#text= via Profile Name to Valve - 36 upvotes, $750
- Stored XSS in the guide’s GameplayVersion (www.dota2.com) to Valve - 34 upvotes, $750
- Signedness issue in ClassInfo message handler leads to RCE on CS:GO client to Valve - 33 upvotes, $7500
- Buffer overflows in demo parsing to Valve - 33 upvotes, $750
- Hidden scheduled partner events are propagated to Steam clients in CMsgClientClanState to Valve - 31 upvotes, $750
- Xss was found by exploiting the URL markdown on http://store.steampowered.com to Valve - 30 upvotes, $1000
- Malformed Skybox .TGA in Half-Life (GoldSRC) leads to Access Violation to Valve - 30 upvotes, $1000
- Reflected XSS in www.dota2.com to Valve - 28 upvotes, $350
- Malformed map detailed texture files in GoldSrc games lead to Remote Code Execution to Valve - 28 upvotes, $350
- LFI in pChart php library to Valve - 27 upvotes, $1000
- GoldSrc: Buffer Overflow in DELTA_ParseDelta function leads to RCE to Valve - 25 upvotes, $3000
- code injection, steam chat client to Valve - 25 upvotes, $750
- [GoldSrc] RCE via malformed BSP file to Valve - 24 upvotes, $450
- unlock self-lock by brute force to Valve - 23 upvotes, $900
- Read Access to all comments on unauthorized forums’ discussions! IDOR! to Valve - 23 upvotes, $500
- Deleting other people’s comments on ModeratorMessages to Valve - 23 upvotes, $500
- [GoldSrc] RCE via ‘spk’ Console Command to Valve - 23 upvotes, $350
- GetReports works for hubs you don’t have access to to Valve - 22 upvotes, $750
- Malformed BSP in GoldSrc Engine may cause shellcode injection to Valve - 21 upvotes, $1750
- GetGlobalAchievementPercentagesForApp is missing the same release checks as GetSchemaForGame to Valve - 21 upvotes, $1650
- Unauthorized updates to extended_info properties in /store/ajaxpackagesave to Valve - 20 upvotes, $2500
- [CS 1.6] Map cycle abuse allows arbitrary file read/write to Valve - 20 upvotes, $750
- Suspended users can bypass UGC upload ban to Valve - 19 upvotes, $500
- Privilege Escalation vulnerability in steam’s Remote Play feature leads to arbitrary kernel-mode driver installation to Valve - 17 upvotes, $750
- resetreportedcount & updatetags doesn’t verify appid param to Valve - 16 upvotes, $750
- Potential buffer overflow in demoplayer module of GoldSource Engine to Valve - 16 upvotes, $200
- Aapp name leakage on economy history page to Valve - 15 upvotes, $500
- Malformed .WAV triggers an Access Violation on GoldSRC (hl.exe) to Valve - 14 upvotes, $200
- Reflected XSS on help.steampowered.com to Valve - 13 upvotes, $750
- ajaxgetachievementsforgame is not guarded for unreleased apps to Valve - 13 upvotes, $750
- Comment restriction in subsection “Workshop” of domain “steamcommunity.com” can be bypassed using IDOR to Valve - 13 upvotes, $200
- XSS @ store.steampowered.com via agecheck path name to Valve - 12 upvotes, $750
- Add apps to packages 0, 61, 62 with /store/ajaxpackagemerge to Valve - 11 upvotes, $2500
- Vulnerability in GoldSource Engine allows to upload and run an arbitrary DLL on client to Valve - 11 upvotes, $1000
- Unfiltered input allows for XSS in “Playtime Item Grants” fields to Valve - 11 upvotes, $750
- [GoldSrc] Remote Code Execution using malicious WAD list in BSP file to Valve - 11 upvotes, $750
- CSRF Ban or unban users in broadcast’s chat to Valve - 9 upvotes, $500
Rockstar Games
- The return of the < to Rockstar Games - 569 upvotes, $1000
- Account Takeover using Linked Accounts due to lack of CSRF protection to Rockstar Games - 237 upvotes, $0
- Stealing Facebook OAuth Code Through Screenshot viewer to Rockstar Games - 200 upvotes, $0
- XSS STORED AT socialclub.rockstargames.com (add friend request from profile attacker) to Rockstar Games - 194 upvotes, $0
- xss on https://www.rockstargames.com/GTAOnline/jp/screens/ to Rockstar Games - 159 upvotes, $0
- Access to the business emails of Rockstar Support agents through the support platform to Rockstar Games - 148 upvotes, $550
- Unserialize leading to arbitrary PHP function invoke to Rockstar Games - 118 upvotes, $0
- Stored XSS in Snapmatic + R★Editor comments to Rockstar Games - 118 upvotes, $0
- SocialClub Account Take Over Through Import Friends feature to Rockstar Games - 116 upvotes, $0
- Referer Leakage Vulnerability in socialclub.rockstargames.com/crew/ leads to FB’S OAuth token theft. to Rockstar Games - 112 upvotes, $0
- CSRF Vulnerability on https://signin.rockstargames.com/tpa/facebook/link/ to Rockstar Games - 104 upvotes, $0
- Password and mail address stored unencrypted in memory - Rockstar Game Launcher to Rockstar Games - 88 upvotes, $750
- Open redirect vulnerability to Rockstar Games - 83 upvotes, $250
- Blind SSRF in emblem editor (2) to Rockstar Games - 81 upvotes, $1500
- LFI and SSRF via XXE in emblem editor to Rockstar Games - 79 upvotes, $1500
- Cache Poisoning DoS on updates.rockstargames.com to Rockstar Games - 77 upvotes, $0
- XSS on rockstargames.com to Rockstar Games - 74 upvotes, $500
- Facebook OAuth Code Theft through referer leakage on support.rockstargames.com to Rockstar Games - 71 upvotes, $0
- Insecure Direct Object Reference allows Crew Invite deletion to Rockstar Games - 66 upvotes, $0
- Unquoted Service Path in “Rockstar Game Library Service” to Rockstar Games - 60 upvotes, $0
- Social Club Account Takeover Via RGL And Steam/Epic Linked Account to Rockstar Games - 54 upvotes, $0
- Brute Force against VMware Horizon to Rockstar Games - 53 upvotes, $250
- SMB SSRF in emblem editor exposes taketwo domain credentials, may lead to RCE to Rockstar Games - 51 upvotes, $1500
- Improper Authentication inside the Rockstar Games Launcher which leads to Account takeover to some extend to Rockstar Games - 50 upvotes, $750
- Bypass CAPTCHA protection to Rockstar Games - 50 upvotes, $0
- Stored XSS on support.rockstargames.com to Rockstar Games - 49 upvotes, $1000
- full path disclosure on www.rockstargames.com via apache filename brute forcing to Rockstar Games - 48 upvotes, $0
- Open Redirection effects autodiscover.rockstargames.com to Rockstar Games - 48 upvotes, $0
- DOM XSS on https://www.rockstargames.com/GTAOnline/feedback to Rockstar Games - 46 upvotes, $0
- DOM based XSS on /GTAOnline/tw/starterpack/ to Rockstar Games - 46 upvotes, $0
- Stored XSS in profile activity feed messages to Rockstar Games - 44 upvotes, $1000
- CSRF in ‘set.php’ via age causes stored XSS on ‘get.php’ - http://www.rockstargames.com/php/videoplayer_cache/get.php’ to Rockstar Games - 40 upvotes, $0
- Exposed CDN access token allows modification of all newly uploaded Snapmatic photos to Rockstar Games - 40 upvotes, $0
- Smuggle SocialClub’s Facebook OAuth Code via Referer Leakage to Rockstar Games - 39 upvotes, $750
- <- Critical IDOR vulnerability in socialclub allow to insert and delete comments as another user and it discloses sensitive information -> to Rockstar Games - 39 upvotes, $0
- Image Injection vulnerability on screenshot-viewer/responsive/image may allow Facebook OAuth token theft. to Rockstar Games - 36 upvotes, $0
- Stored XSS on profile page via Steam display name to Rockstar Games - 35 upvotes, $1250
- Exploiting Misconfigured CORS to Steal User Information to Rockstar Games - 35 upvotes, $500
- DOM Based xss on https://www.rockstargames.com/ ( 1 ) to Rockstar Games - 34 upvotes, $0
- stored XSS (angular injection) in support.rockstargames.com using zendesk register form via name parameter to Rockstar Games - 31 upvotes, $1000
- Stored XSS in snapmatic comments to Rockstar Games - 30 upvotes, $1000
- Image Injection/XSS vulnerability affecting https://www.rockstargames.com/newswire/article to Rockstar Games - 29 upvotes, $0
- CSRF Vulnerability on post creation page /community/create-post.json to Rockstar Games - 29 upvotes, $0
- Uninstalling Rockstar Games Launcher for Windows (64-bit), then reinstalling keeps you logged in without authentication to Rockstar Games - 28 upvotes, $250
- XSS in http://www.rockstargames.com/theballadofgaytony/js/jquery.base.js to Rockstar Games - 28 upvotes, $0
- CSRF Vulnerability allows attackers to steal SocialClub private token. to Rockstar Games - 28 upvotes, $0
- DOM based reflected XSS in rockstargames.com/newswire/tags through cross domain ajax request to Rockstar Games - 27 upvotes, $0
- Reflected XSS in /Videos/ via calling a callback http://www.rockstargames.com/videos/#/?lb= to Rockstar Games - 27 upvotes, $0
- Reflected XSS via #tags= while using a callback in newswire http://www.rockstargames.com/newswire to Rockstar Games - 26 upvotes, $0
- Stored XSS on member post feed to Rockstar Games - 25 upvotes, $1000
- Login form on non-HTTPS page to Rockstar Games - 24 upvotes, $350
- use of unsafe host header leads to open redirect to Rockstar Games - 23 upvotes, $0
- Open redirect in https://www.rockstargames.com/GTAOnline/restricted-content/agegate/form may lead to Facebook OAuth token theft to Rockstar Games - 23 upvotes, $0
- Race condition vulnerability on “This Rocks” button. to Rockstar Games - 23 upvotes, $0
- Open redirect on https://signin.rockstargames.com/connect/authorize/rsg to Rockstar Games - 23 upvotes, $0
- Reflected XSS via Double Encoding to Rockstar Games - 22 upvotes, $500
- Information Disclosure in https://www.rockstargames.com/search to Rockstar Games - 22 upvotes, $0
- Minor Account Privacy can Set to Everyone. to Rockstar Games - 21 upvotes, $0
- [IMP] - Blind XSS in the admin panel for reviewing comments to Rockstar Games - 20 upvotes, $650
- phpinfo() on graph.rockstargames.com exposes sensitive information to Rockstar Games - 20 upvotes, $0
- Comments Denial of Service in socialclub.rockstargames.com to Rockstar Games - 19 upvotes, $0
- Stored XSS with CRLF injection via post message to user feed to Rockstar Games - 19 upvotes, $0
- Table and Column Exposure to Rockstar Games - 18 upvotes, $150
- Stored XSS via Send crew invite to Rockstar Games - 18 upvotes, $0
- Reflected XSS in reddeadredemption Site located at www.rockstargames.com/reddeadredemption to Rockstar Games - 17 upvotes, $0
- SocialClub’s Facebook OAuth Theft through Warehouse XSS. to Rockstar Games - 17 upvotes, $0
- Dom based xss on https://www.rockstargames.com/ via
returnUrlparameter to Rockstar Games - 17 upvotes, $0 - Open redirect affecting m.rockstargames.com/ to Rockstar Games - 16 upvotes, $0
- Dom based xss on /reddeadredemption2/br/videos to Rockstar Games - 16 upvotes, $0
- Control Character Injection In Messages to Rockstar Games - 15 upvotes, $0
- Client-side Template Injection in Search, user email/token leak and maybe sandbox escape to Rockstar Games - 15 upvotes, $0
- Image Injection on www.rockstargames.com/screenshot-viewer/responsive/image may allow facebook oauth token theft. to Rockstar Games - 14 upvotes, $0
- Image Injection vulnerability in www.rockstargames.com/IV/screens/1280x720Image.html to Rockstar Games - 14 upvotes, $0
- csrf in https://www.rockstargames.com/reddeadonline/feedback/submit.json to Rockstar Games - 14 upvotes, $0
- Source Code Disclosure (CGI) to Rockstar Games - 13 upvotes, $150
- Full path Disclosure in Rockstargames.com to Rockstar Games - 13 upvotes, $0
- Warehouse dom based xss may lead to Social Club Account Taker Over. to Rockstar Games - 13 upvotes, $0
- DOM BASED XSS ON https://www.rockstargames.com/GTAOnline/features to Rockstar Games - 13 upvotes, $0
- dom based xss in http://www.rockstargames.com/GTAOnline/ (Fix bypass) to Rockstar Games - 12 upvotes, $0
- Stored XSS on support.rockstargames.com to Rockstar Games - 11 upvotes, $1000
- Found CSRF Vulnerability in https://support.rockstargames.com/ to Rockstar Games - 11 upvotes, $150
- Leak IP internal to Rockstar Games - 11 upvotes, $0
- Flash injection vulnerability on /IV/imgPlayer/imageEmbed.swf to Rockstar Games - 11 upvotes, $0
- Your support community suffers from angularjs injection and must be fixed immediately [CRITICAL] to Rockstar Games - 10 upvotes, $0
- Referer Leakge in language changer may lead to FB token theft. to Rockstar Games - 10 upvotes, $0
- RDR2 game service method allows adding any player to a new Posse without consent to Rockstar Games - 10 upvotes, $0
- dom based xss in https://www.rockstargames.com/GTAOnline/ to Rockstar Games - 9 upvotes, $0
- Image Injection on
/bully/anniversaryeditionmay lead to FB’s OAuth Token Theft. to Rockstar Games - 9 upvotes, $0 - Modifying Sprunk vs eCola crew data to Rockstar Games - 9 upvotes, $0
- Profile bio at rockstar is accepting control characters to Rockstar Games - 8 upvotes, $0
- flash injection in http://www.rockstargames.com/IV/imgPlayer/imageEmbed.swf to Rockstar Games - 8 upvotes, $0
- Image Injection on /bully/anniversaryedition may lead to OAuth token theft. to Rockstar Games - 8 upvotes, $0
- Control characters incorrectly handled on Crew Status Update to Rockstar Games - 7 upvotes, $250
- insecure redirect in https://www.rockstargames.com to Rockstar Games - 7 upvotes, $0
- Image Injection vulnerability affecting www.rockstargames.com/careers may lead to Facebook OAuth Theft to Rockstar Games - 7 upvotes, $0
- Ability to post comments to a crew even after getting kicked out to Rockstar Games - 6 upvotes, $500
- SSLv3 POODLE Vulnerability to Rockstar Games - 6 upvotes, $0
- DOM based XSS on /GTAOnline/de/news/article via “returnUrl” parameter to Rockstar Games - 6 upvotes, $0
- CSRF Vulnerabiliy on Facebook Linkage Page Allows Full Account takerover of Socialclub Accounts. to Rockstar Games - 6 upvotes, $0
- Image injection on /screenshot-viewer/responsive/image ( FIX BYPASS) to Rockstar Games - 6 upvotes, $0
- image injection /screenshot-viewer/responsive/image (ANOTHER FIX BYPASS) to Rockstar Games - 6 upvotes, $0
- Dom based XSS on www.rockstargames.com/GTAOnline/features/freemode to Rockstar Games - 5 upvotes, $0
- Image injection /br/games/info may lead to phishing attacks or FB OAuth theft. to Rockstar Games - 5 upvotes, $0
- Referer Referer Header Leakage in language changer may lead to FB token theft to Rockstar Games - 3 upvotes, $0
- Image Injection Vulnerability on /bully/screens to Rockstar Games - 3 upvotes, $0