ea records
12 published records for vendor ea.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-19 Data Processing Errors1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-269 Improper Privilege Management1
- CWE-310 Cryptographic Issues1
- CWE-427 Uncontrolled Search Path Element1
The weakness classes this vendor ships most often: where to look.
CWEAll records
12 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2019-12828Proof of concept | An issue was discovered in Electronic Arts Origin before 10.5.39.ea · origin · CWE-19 | High8.8 | — | 13.3% | Jun 14, 2019 |
38Monitor | CVE-2019-11354Proof of concept | The client in Electronic Arts (EA) Origin 10.5.36 on Windows allows template injection in the title parameter of the Origin2 URI handler.ea · origin · CWE-74 | High7.8 | — | 23.1% | Apr 19, 2019 |
32Monitor | CVE-2008-6737Proof of concept | Crysis 1.21 and earlier allows remote attackers to obtain sensitive player information such as real IP addresses by sending a keyexchange paea · crysis · CWE-200 | High7.8 | — | 2.7% | Apr 21, 2009 |
31Monitor | CVE-2019-19741No exploit | Electronic Arts Origin 10.5.55.33574 is vulnerable to local privilege escalation due to arbitrary directory DACL manipulation, a different iea · origin | High7.8 | — | 0.7% | Feb 20, 2020 |
31Monitor | CVE-2020-27708No exploit | A vulnerability exists in the Origin Client that could allow a non-Administrative user to elevate their access to either Administrator or Syea · origin · CWE-427 | High7.8 | — | 0.6% | Nov 2, 2020 |
31Monitor | CVE-2019-19248No exploit | Electronic Arts Origin through 10.5.x allows Elevation of Privilege (issue 2 of 2).ea · origin | High7.8 | — | 0.4% | Dec 12, 2019 |
31Monitor | CVE-2019-19247No exploit | Electronic Arts Origin through 10.5.x allows Elevation of Privilege (issue 1 of 2).ea · origin | High7.8 | — | 0.4% | Dec 12, 2019 |
28Monitor | CVE-2010-2627Proof of concept | Multiple directory traversal vulnerabilities in the Refractor 2 engine, as used in Battlefield 2 1.50 (1.5.3153-802.0) and earlier, and Battea · battlefield 2 · CWE-22 | Medium6.8 | — | 3.7% | Jul 2, 2010 |
25Monitor | CVE-2013-4867Proof of concept | Electronic Arts Karotz Smart Rabbit 12.07.19.00 allows Python module hijackingea · karotz smart rabbit firmware · CWE-269 | Medium6.3 | — | 1.6% | Dec 27, 2019 |
22Monitor | CVE-2008-6712Proof of concept | The HTTP/XML-RPC service in Crysis 1.21 (game version 1.1.1.6156) and earlier allows remote attackers to cause a denial of service (crash) vea · crysis | Medium5.0 | — | 7.4% | Apr 10, 2009 |
21Monitor | CVE-2020-15914No exploit | A cross-site scripting (XSS) vulnerability exists in the Origin Client for Mac and PC 10.5.86 or earlier that could allow a remote attacker ea · origin client · CWE-79 | Medium5.4 | — | 0.6% | Nov 2, 2020 |
21Monitor | CVE-2014-5921No exploit | The Need for Speed Network (aka com.ea.nfsautolog.bv) application 1.0.1 for Android does not verify X.509 certificates from SSL servers, whiea · need for speed network · CWE-310 | Medium5.4 | — | 0.3% | Sep 18, 2014 |
- CVE-2019-1282839Monitor
An issue was discovered in Electronic Arts Origin before 10.5.39.
HighCVSS 8.8Proof of conceptEPSS 13%ea · originJun 14, 2019
- CVE-2019-1135438Monitor
The client in Electronic Arts (EA) Origin 10.5.36 on Windows allows template injection in the title parameter of the Origin2 URI handler.
HighCVSS 7.8Proof of conceptEPSS 23%ea · originApr 19, 2019
- CVE-2008-673732Monitor
Crysis 1.21 and earlier allows remote attackers to obtain sensitive player information such as real IP addresses by sending a keyexchange pa
HighCVSS 7.8Proof of conceptEPSS 3%ea · crysisApr 21, 2009
- CVE-2019-1974131Monitor
Electronic Arts Origin 10.5.55.33574 is vulnerable to local privilege escalation due to arbitrary directory DACL manipulation, a different i
HighCVSS 7.8No exploitEPSS 1%ea · originFeb 20, 2020
- CVE-2020-2770831Monitor
A vulnerability exists in the Origin Client that could allow a non-Administrative user to elevate their access to either Administrator or Sy
HighCVSS 7.8No exploitEPSS 1%ea · originNov 2, 2020
- CVE-2019-1924831Monitor
Electronic Arts Origin through 10.5.x allows Elevation of Privilege (issue 2 of 2).
HighCVSS 7.8No exploitEPSS 0%ea · originDec 12, 2019
- CVE-2019-1924731Monitor
Electronic Arts Origin through 10.5.x allows Elevation of Privilege (issue 1 of 2).
HighCVSS 7.8No exploitEPSS 0%ea · originDec 12, 2019
- CVE-2010-262728Monitor
Multiple directory traversal vulnerabilities in the Refractor 2 engine, as used in Battlefield 2 1.50 (1.5.3153-802.0) and earlier, and Batt
MediumCVSS 6.8Proof of conceptEPSS 4%ea · battlefield 2Jul 2, 2010
- CVE-2013-486725Monitor
Electronic Arts Karotz Smart Rabbit 12.07.19.00 allows Python module hijacking
MediumCVSS 6.3Proof of conceptEPSS 2%ea · karotz smart rabbit firmwareDec 27, 2019
- CVE-2008-671222Monitor
The HTTP/XML-RPC service in Crysis 1.21 (game version 1.1.1.6156) and earlier allows remote attackers to cause a denial of service (crash) v
MediumCVSS 5.0Proof of conceptEPSS 7%ea · crysisApr 10, 2009
- CVE-2020-1591421Monitor
A cross-site scripting (XSS) vulnerability exists in the Origin Client for Mac and PC 10.5.86 or earlier that could allow a remote attacker
MediumCVSS 5.4No exploitEPSS 1%ea · origin clientNov 2, 2020
- CVE-2014-592121Monitor
The Need for Speed Network (aka com.ea.nfsautolog.bv) application 1.0.1 for Android does not verify X.509 certificates from SSL servers, whi
MediumCVSS 5.4No exploitEPSS 0%ea · need for speed networkSep 18, 2014