VYPR
Vendor

Ea

Products
4
CVEs
5
Across products
6
Status
Private

Products

4

Recent CVEs

5
  • CVE-2008-1127Mar 3, 2008
    risk 0.04cvss epss 0.13

    Format string vulnerability in the cryactio function in Crysis 1.1.1.5879 allows remote authenticated users to execute arbitrary code via format string specifiers in the user name, which is triggered when the game character is killed.

  • CVE-2010-2627Jul 2, 2010
    risk 0.03cvss epss 0.01

    Multiple directory traversal vulnerabilities in the Refractor 2 engine, as used in Battlefield 2 1.50 (1.5.3153-802.0) and earlier, and Battlefield 2142 (1.10.48.0) and earlier, allow remote servers to overwrite arbitrary files on the client via "..\" (dot dot backslash) sequences in URLs for the (1) sponsor or (2) community logos, and other URLs related to (3) DemoDownloadURL, (4) DemoIndexURL and (5) CustomMapsURL.

  • CVE-2008-6737Apr 21, 2009
    risk 0.03cvss epss 0.05

    Crysis 1.21 and earlier allows remote attackers to obtain sensitive player information such as real IP addresses by sending a keyexchange packet without a previous join packet, which causes Crysis to send a disconnect packet that includes unrelated log information.

  • CVE-2008-6712Apr 10, 2009
    risk 0.03cvss epss 0.06

    The HTTP/XML-RPC service in Crysis 1.21 (game version 1.1.1.6156) and earlier allows remote attackers to cause a denial of service (crash) via a long HTTP request, which triggers a NULL pointer dereference.

  • CVE-2014-5921Sep 18, 2014
    risk 0.00cvss epss 0.00

    The Need for Speed Network (aka com.ea.nfsautolog.bv) application 1.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.