Carsten's 3D Engine suffers from a format string vulnerability that can allow an attacker to execute remote code.