VYPR
Vendor

Unity8

Products
1
CVEs
6
Across products
6
Status
Private

Products

1

Recent CVEs

6
  • CVE-2017-12939CriAug 18, 2017
    risk 0.64cvss 9.8epss 0.05

    A Remote Code Execution vulnerability was identified in all Windows versions of Unity Editor, e.g., before 5.3.8p2, 5.4.x before 5.4.5p5, 5.5.x before 5.5.4p3, 5.6.x before 5.6.3p1, and 2017.x before 2017.1.0p4.

  • CVE-2023-37250HigAug 20, 2023
    risk 0.46cvss 7.0epss 0.00

    Unity Parsec has a TOCTOU race condition that permits local attackers to escalate privileges to SYSTEM if Parsec was installed in "Per User" mode. The application intentionally launches DLLs from a user-owned directory but intended to always perform integrity verification of…

  • CVE-2015-9288MedJul 29, 2019
    risk 0.42cvss 6.5epss 0.01

    The Unity Web Player plugin before 4.6.6f2 and 5.x before 5.0.3f2 allows attackers to read messages or access online services via a victim's credentials

  • CVE-2018-19111MedNov 8, 2018
    risk 0.34cvss 5.3epss 0.00

    The Google Cardboard application 1.8 for Android and 1.2 for iOS sends potentially private cleartext information to the Unity 3D Stats web site, as demonstrated by device make, model, and OS.

  • CVE-2016-1584LowApr 22, 2019
    risk 0.10cvss 1.6epss 0.01

    In all versions of Unity8 a running but not active application on a large-screen device could talk with Maliit and consume keyboard input.

  • CVE-2014-3202May 6, 2014
    risk 0.00cvss epss 0.00

    Unity before 7.2.1 does not properly handle entry activation, which allows physically proximate attackers to bypass the lock screen by holding the ENTER key, which triggers the process to crash.