{"id":"CVE-2020-15007","details":"A buffer overflow in the M_LoadDefaults function in m_misc.c in id Tech 1 (aka Doom engine) allows arbitrary code execution via an unsafe usage of fscanf, because it does not limit the number of characters to be read in a format argument.","modified":"2026-07-08T17:56:04.670871Z","published":"2020-06-24T11:15:12.090Z","references":[{"type":"ADVISORY","url":"https://twitter.com/notrevenant/status/1268654123903340544"},{"type":"FIX","url":"https://github.com/AXDOOMER/doom-vanille/commit/8a6d9a02fa991a91ff90ccdc73b5ceabaa6cb9ec"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/axdoomer/doom-vanille","events":[{"introduced":"0"},{"fixed":"8a6d9a02fa991a91ff90ccdc73b5ceabaa6cb9ec"}],"database_specific":{"cpe":"cpe:2.3:a:doom_vanille_project:doom_vanille:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"671"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["670","669","668","667","666"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-15007.json","vanir_signatures_modified":"2026-07-08T17:56:04Z","vanir_signatures":[{"signature_version":"v1","source":"https://github.com/axdoomer/doom-vanille/commit/8a6d9a02fa991a91ff90ccdc73b5ceabaa6cb9ec","target":{"file":"m_misc.c"},"deprecated":false,"digest":{"line_hashes":["85293061293636805416231508029694615802","71369627972608954247231714336559116903","46547365666147558129742222755009198095","78024321302976833542863994243450130317"],"threshold":0.9},"id":"CVE-2020-15007-65cbcd42","signature_type":"Line"},{"source":"https://github.com/axdoomer/doom-vanille/commit/8a6d9a02fa991a91ff90ccdc73b5ceabaa6cb9ec","target":{"file":"m_misc.c","function":"M_LoadDefaults"},"deprecated":false,"digest":{"length":1402,"function_hash":"237249339936689033424449235672978159146"},"id":"CVE-2020-15007-c63ceb02","signature_type":"Function","signature_version":"v1"}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}