The Half-Life engine before July 7 2004 allows remote attackers to cause a denial of service (server or client crash) via an empty fragmented packet.
https://exchange.xforce.ibmcloud.com/vulnerabilities/16674
https://euvd.enisa.europa.eu/vulnerability/EUVD-2004-0722