Back

CVE-2004-1805

Format string vulnerability in games using the Epic Games Unreal Engine 436 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in class names.

Published: Dec 31, 2004 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (3)

Vendor Product Version
epic_games unreal_engine 226f
epic_games unreal_engine 433
epic_games unreal_engine 436

GitHub Security Advisory GHSA-48p4-c835-2pjf

Format string vulnerability in games using the Epic Games Unreal Engine 436 allows remote...

Risk Scores

CVSS Score 5.0 / 10
EPSS Score 6.45%

Top 7% most likely to be exploited

Threat Score 21.9 / 100

Data Sources

NVD EPSS GitHub