A buffer overflow in the MLoadDefaults function in mmisc.c in id Tech 1 (aka Doom engine) allows arbitrary code execution via an unsafe usage of fscanf, because it does not limit the number of characters to be read in a format argument.
{
"cpe": "cpe:2.3:a:doom_vanille_project:doom_vanille:*:*:*:*:*:*:*:*",
"source": [
"CPE_RANGE",
"REFERENCES"
],
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "671"
}
]
}[
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"85293061293636805416231508029694615802",
"71369627972608954247231714336559116903",
"46547365666147558129742222755009198095",
"78024321302976833542863994243450130317"
]
},
"signature_version": "v1",
"source": "https://github.com/axdoomer/doom-vanille/commit/8a6d9a02fa991a91ff90ccdc73b5ceabaa6cb9ec",
"signature_type": "Line",
"target": {
"file": "m_misc.c"
},
"id": "CVE-2020-15007-65cbcd42",
"deprecated": false
},
{
"digest": {
"length": 1402.0,
"function_hash": "237249339936689033424449235672978159146"
},
"signature_version": "v1",
"source": "https://github.com/axdoomer/doom-vanille/commit/8a6d9a02fa991a91ff90ccdc73b5ceabaa6cb9ec",
"signature_type": "Function",
"target": {
"function": "M_LoadDefaults",
"file": "m_misc.c"
},
"id": "CVE-2020-15007-c63ceb02",
"deprecated": false
}
]
"2026-07-08T17:56:04Z"
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-15007.json"