Skip to content
Noroxi

ea records

12 published records for vendor ea.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

12 records
  • An issue was discovered in Electronic Arts Origin before 10.5.39.

    HighCVSS 8.8Proof of conceptEPSS 13%

    ea · originJun 14, 2019

  • The client in Electronic Arts (EA) Origin 10.5.36 on Windows allows template injection in the title parameter of the Origin2 URI handler.

    HighCVSS 7.8Proof of conceptEPSS 23%

    ea · originApr 19, 2019

  • CVE-2008-6737
    32Monitor

    Crysis 1.21 and earlier allows remote attackers to obtain sensitive player information such as real IP addresses by sending a keyexchange pa

    HighCVSS 7.8Proof of conceptEPSS 3%

    ea · crysisApr 21, 2009

  • Electronic Arts Origin 10.5.55.33574 is vulnerable to local privilege escalation due to arbitrary directory DACL manipulation, a different i

    HighCVSS 7.8No exploitEPSS 1%

    ea · originFeb 20, 2020

  • A vulnerability exists in the Origin Client that could allow a non-Administrative user to elevate their access to either Administrator or Sy

    HighCVSS 7.8No exploitEPSS 1%

    ea · originNov 2, 2020

  • Electronic Arts Origin through 10.5.x allows Elevation of Privilege (issue 2 of 2).

    HighCVSS 7.8No exploitEPSS 0%

    ea · originDec 12, 2019

  • Electronic Arts Origin through 10.5.x allows Elevation of Privilege (issue 1 of 2).

    HighCVSS 7.8No exploitEPSS 0%

    ea · originDec 12, 2019

  • CVE-2010-2627
    28Monitor

    Multiple directory traversal vulnerabilities in the Refractor 2 engine, as used in Battlefield 2 1.50 (1.5.3153-802.0) and earlier, and Batt

    MediumCVSS 6.8Proof of conceptEPSS 4%

    ea · battlefield 2Jul 2, 2010

  • CVE-2013-4867
    25Monitor

    Electronic Arts Karotz Smart Rabbit 12.07.19.00 allows Python module hijacking

    MediumCVSS 6.3Proof of conceptEPSS 2%

    ea · karotz smart rabbit firmwareDec 27, 2019

  • CVE-2008-6712
    22Monitor

    The HTTP/XML-RPC service in Crysis 1.21 (game version 1.1.1.6156) and earlier allows remote attackers to cause a denial of service (crash) v

    MediumCVSS 5.0Proof of conceptEPSS 7%

    ea · crysisApr 10, 2009

  • A cross-site scripting (XSS) vulnerability exists in the Origin Client for Mac and PC 10.5.86 or earlier that could allow a remote attacker

    MediumCVSS 5.4No exploitEPSS 1%

    ea · origin clientNov 2, 2020

  • CVE-2014-5921
    21Monitor

    The Need for Speed Network (aka com.ea.nfsautolog.bv) application 1.0.1 for Android does not verify X.509 certificates from SSL servers, whi

    MediumCVSS 5.4No exploitEPSS 0%

    ea · need for speed networkSep 18, 2014