Electronic Arts
Products
11- 5 CVEs
- 2 CVEs
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 0 CVEs
Recent CVEs
13| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-12828 | Hig | 0.61 | 8.8 | 0.13 | Jun 14, 2019 | An issue was discovered in Electronic Arts Origin before 10.5.39. Due to improper sanitization of the origin:// and origin2:// URI schemes, it is possible to inject additional arguments into the Origin process and ultimately leverage code execution by loading a backdoored Qt… | ||
| CVE-2019-11354 | Hig | 0.56 | 7.8 | 0.23 | Apr 19, 2019 | The client in Electronic Arts (EA) Origin 10.5.36 on Windows allows template injection in the title parameter of the Origin2 URI handler. This can be used to escape the underlying AngularJS sandbox and achieve remote code execution via an origin2://game/launch URL for… | ||
| CVE-2019-19741 | Hig | 0.51 | 7.8 | 0.01 | Feb 20, 2020 | Electronic Arts Origin 10.5.55.33574 is vulnerable to local privilege escalation due to arbitrary directory DACL manipulation, a different issue than CVE-2019-19247 and CVE-2019-19248. When Origin.exe connects to the named pipe OriginClientService, the privileged service… | ||
| CVE-2019-19248 | Hig | 0.51 | 7.8 | 0.00 | Dec 12, 2019 | Electronic Arts Origin through 10.5.x allows Elevation of Privilege (issue 2 of 2). | ||
| CVE-2019-19247 | Hig | 0.51 | 7.8 | 0.00 | Dec 12, 2019 | Electronic Arts Origin through 10.5.x allows Elevation of Privilege (issue 1 of 2). | ||
| CVE-2024-57276 | Hig | 0.47 | 7.3 | 0.00 | Jan 27, 2025 | In Electronic Arts Dragon Age Origins 1.05, the DAUpdaterSVC service contains an unquoted service path vulnerability. This service is configured with insecure permissions, allowing users to modify the executable file path used by the service. The service runs with NT… | ||
| CVE-2013-4867 | Med | 0.44 | 6.3 | 0.02 | Dec 27, 2019 | Electronic Arts Karotz Smart Rabbit 12.07.19.00 allows Python module hijacking | ||
| CVE-2004-0735 | 0.08 | — | 0.62 | Jul 27, 2004 | Buffer overflow in Medal of Honor (1) Allied Assault 1.11v9 and earlier, (2) Breakthrough 2.40b and earlier, and (3) Spearhead 2.15 and earlier, when playing on a Local Area Network (LAN), allows remote attackers to execute arbitrary code via vectors such as (1) the getinfo… | |||
| CVE-2007-4466 | 0.05 | — | 0.31 | Oct 9, 2007 | Multiple stack-based buffer overflows in Electronic Arts (EA) SnoopyCtrl ActiveX control (NPSnpy.dll) allow remote attackers to execute arbitrary code via unspecified methods and parameters. | |||
| CVE-2004-1220 | 0.03 | — | 0.03 | Jan 10, 2005 | Battlefield 1942 1.6.19 and earlier, and Battlefield Vietnam 1.2 and earlier, allows a remote master server to cause a denial of service (client crash) via a server reply that contains a large numplayers value, which triggers a null dereference. | |||
| CVE-2004-2099 | 0.03 | — | 0.04 | Dec 31, 2004 | Buffer overflow in Need for Speed Hot Pursuit 2.0 client (NFSHP2), version 242 and earlier, allows remote attackers (servers) to execute arbitrary code via long (1) gamename, (2) gamever, (3) hostname, (4) gametype, (5) mapname or (6) gamemode commands. | |||
| CVE-2003-1355 | 0.03 | — | 0.04 | Dec 31, 2003 | Buffer overflow in the remote console (rcon) in Battlefield 1942 1.2 and 1.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long user name and password. | |||
| CVE-2006-3393 | 0.00 | — | 0.02 | Jul 6, 2006 | Papyrus NASCAR Racing 4 4.1.3.1.6 and earlier, 2002 Season 1.1.0.2 and earlier, and 2003 Season 1.2.0.1 and earlier allows remote attackers to cause a denial of service (CPU consumption) by sending an empty UDP datagram, which is not properly discarded due to use of the FIONREAD… |
- risk 0.61cvss 8.8epss 0.13
An issue was discovered in Electronic Arts Origin before 10.5.39. Due to improper sanitization of the origin:// and origin2:// URI schemes, it is possible to inject additional arguments into the Origin process and ultimately leverage code execution by loading a backdoored Qt…
- risk 0.56cvss 7.8epss 0.23
The client in Electronic Arts (EA) Origin 10.5.36 on Windows allows template injection in the title parameter of the Origin2 URI handler. This can be used to escape the underlying AngularJS sandbox and achieve remote code execution via an origin2://game/launch URL for…
- risk 0.51cvss 7.8epss 0.01
Electronic Arts Origin 10.5.55.33574 is vulnerable to local privilege escalation due to arbitrary directory DACL manipulation, a different issue than CVE-2019-19247 and CVE-2019-19248. When Origin.exe connects to the named pipe OriginClientService, the privileged service…
- risk 0.51cvss 7.8epss 0.00
Electronic Arts Origin through 10.5.x allows Elevation of Privilege (issue 2 of 2).
- risk 0.51cvss 7.8epss 0.00
Electronic Arts Origin through 10.5.x allows Elevation of Privilege (issue 1 of 2).
- risk 0.47cvss 7.3epss 0.00
In Electronic Arts Dragon Age Origins 1.05, the DAUpdaterSVC service contains an unquoted service path vulnerability. This service is configured with insecure permissions, allowing users to modify the executable file path used by the service. The service runs with NT…
- risk 0.44cvss 6.3epss 0.02
Electronic Arts Karotz Smart Rabbit 12.07.19.00 allows Python module hijacking
- CVE-2004-0735Jul 27, 2004risk 0.08cvss —epss 0.62
Buffer overflow in Medal of Honor (1) Allied Assault 1.11v9 and earlier, (2) Breakthrough 2.40b and earlier, and (3) Spearhead 2.15 and earlier, when playing on a Local Area Network (LAN), allows remote attackers to execute arbitrary code via vectors such as (1) the getinfo…
- CVE-2007-4466Oct 9, 2007risk 0.05cvss —epss 0.31
Multiple stack-based buffer overflows in Electronic Arts (EA) SnoopyCtrl ActiveX control (NPSnpy.dll) allow remote attackers to execute arbitrary code via unspecified methods and parameters.
- CVE-2004-1220Jan 10, 2005risk 0.03cvss —epss 0.03
Battlefield 1942 1.6.19 and earlier, and Battlefield Vietnam 1.2 and earlier, allows a remote master server to cause a denial of service (client crash) via a server reply that contains a large numplayers value, which triggers a null dereference.
- CVE-2004-2099Dec 31, 2004risk 0.03cvss —epss 0.04
Buffer overflow in Need for Speed Hot Pursuit 2.0 client (NFSHP2), version 242 and earlier, allows remote attackers (servers) to execute arbitrary code via long (1) gamename, (2) gamever, (3) hostname, (4) gametype, (5) mapname or (6) gamemode commands.
- CVE-2003-1355Dec 31, 2003risk 0.03cvss —epss 0.04
Buffer overflow in the remote console (rcon) in Battlefield 1942 1.2 and 1.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long user name and password.
- CVE-2006-3393Jul 6, 2006risk 0.00cvss —epss 0.02
Papyrus NASCAR Racing 4 4.1.3.1.6 and earlier, 2002 Season 1.1.0.2 and earlier, and 2003 Season 1.2.0.1 and earlier allows remote attackers to cause a denial of service (CPU consumption) by sending an empty UDP datagram, which is not properly discarded due to use of the FIONREAD…