CVE-2015-4016: Valvesoftware Steam Client

Medium severity, CVSS 5.0. EPSS: 3% chance of exploitation in the next 30 days.

The client detection protocol in Valve Steam allows remote attackers to cause a denial of service (process crash) via a crafted response to a broadcast packet.

Affected products

  • Valvesoftware Steam Client: before 2015-05-13 (fixed in 2015-05-13)

Published 2015-05-20. Last modified 2026-06-17.