Aggregates CVE and security vulnerability intelligence across all teamspeak-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.
Historical issues mainly involve vendor risk buffer overflow and vendor risk input validation and related problems; some flaws may lead to vendor impact application crash and vendor impact memory corruption.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2022-50931 | TeamSpeak 3.5.6 contains an insecure file permissions vulnerability that allows local attackers to replace executable files with malicious binaries. Attackers can replace system executables like ts3client_win32.exe with custom files to potentially gain SYSTEM or Administrator-level access. | [email protected] | 8.5 | 0.19% | 2026-01-13 | 2026-06-17 |
| CVE-2019-15502 | The TeamSpeak client before 3.3.2 allows remote servers to trigger a crash via the 0xe2 0x81 0xa8 0xe2 0x81 0xa7 byte sequence, aka Unicode characters U+2068 (FIRST STRONG ISOLATE) and U+2067 (RIGHT-TO-LEFT ISOLATE). | [email protected] | 7.5 | 1.73% | 2019-08-29 | 2026-06-16 |
| CVE-2019-11351 | TeamSpeak 3 Client before 3.2.5 allows remote code execution in the Qt framework. | [email protected] | 8.8 | 3.90% | 2019-04-19 | 2026-06-16 |
| CVE-2014-7222 | Buffer overflow in TeamSpeak Client 3.0.14 and earlier allows remote authenticated users to cause a denial of service (application crash) by connecting to a channel with a different client instance, and placing crafted data in the Chat/Server tab with two \\ (backslash) characters, a digit, a \ (backslash) character, and "z" in a series of nested img BBCODE tags. | [email protected] | 6.5 | 10.97% | 2018-01-08 | 2026-06-16 |
| CVE-2014-7221 | TeamSpeak Client 3.0.14 and earlier allows remote authenticated users to cause a denial of service (buffer overflow and application crash) by connecting to a channel with a different client instance, and placing crafted data in the Chat/Server tab containing [img]//http:// substrings. | [email protected] | 6.5 | 10.97% | 2018-01-08 | 2026-06-16 |
| CVE-2017-8290 | A potential Buffer Overflow Vulnerability (from a BB Code handling issue) has been identified in TeamSpeak Server version 3.0.13.6 (08/11/2016 09:48:33), it enables the users to Crash any WINDOWS Client that clicked into a Vulnerable Channel of a TeamSpeak Server. | [email protected] | 7.5 | 1.41% | 2017-07-06 | 2026-06-16 |
| CVE-2017-9982 | TeamSpeak Client 3.0.19 allows remote attackers to cause a denial of service (application crash) via the ᗪ Unicode character followed by the ༿ Unicode character. | [email protected] | 7.5 | 2.54% | 2017-06-27 | 2026-06-16 |
| CVE-2010-3383 | The (1) teamspeak and (2) teamspeak-server scripts in TeamSpeak 2.0.32 place a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory. | [email protected] | 6.9 | 0.38% | 2010-10-20 | 2026-06-16 |
| CVE-2007-4530 | Multiple cross-site scripting (XSS) vulnerabilities in TeamSpeak Server 2.0.20.1 allow remote attackers to inject arbitrary web script or HTML via (1) the error_text parameter to error_box.html or (2) the ok_title parameter to ok_box.html. | [email protected] | 4.3 | 1.31% | 2007-08-24 | 2026-06-16 |
| CVE-2007-4529 | The WebAdmin interface in TeamSpeak Server 2.0.20.1 allows remote authenticated users with the ServerAdmin flag to assign Registered users certain privileges, resulting in a privilege set that extends beyond that ServerAdmin's own servers, as demonstrated by the (1) AdminAddServer, (2) AdminDeleteServer, (3) AdminStartServer, and (4) AdminStopServer privileges; and administration of arbitrary virtual servers via a request to a .tscmd URI with a modified serverid parameter, as demonstrated by (a) | [email protected] | 8.5 | 2.01% | 2007-08-24 | 2026-06-16 |
| CVE-2007-3956 | TeamSpeak WebServer 2.0 for Windows does not validate parameter value lengths and does not expire TCP sessions, which allows remote attackers to cause a denial of service (CPU and memory consumption) via long username and password parameters in a request to login.tscmd on TCP port 14534. | [email protected] | 7.8 | 8.14% | 2007-07-24 | 2026-06-16 |