CVE Browser

More filters (active)
CVE-2020-15914 MEDIUM

A cross-site scripting (XSS) vulnerability exists in the Origin Client for Mac and PC 10.5.86 or earlier that could allow a remote attacker to execute arbitrar…

CVSS 5.4 EPSS 0.64% Oct 30, 2020
CVE-2020-27708 HIGH

A vulnerability exists in the Origin Client that could allow a non-Administrative user to elevate their access to either Administrator or System. Once the user…

CVSS 7.8 EPSS 0.59% Oct 30, 2020
CVE-2019-19741 HIGH

Electronic Arts Origin 10.5.55.33574 is vulnerable to local privilege escalation due to arbitrary directory DACL manipulation, a different issue than CVE-2019-…

CVSS 7.8 EPSS 0.72% Feb 20, 2020
CVE-2013-4867 MEDIUM

Electronic Arts Karotz Smart Rabbit 12.07.19.00 allows Python module hijacking

CVSS 6.3 EPSS 1.56% Dec 27, 2019
CVE-2019-19248 HIGH

Electronic Arts Origin through 10.5.x allows Elevation of Privilege (issue 2 of 2).

CVSS 7.8 EPSS 0.39% Dec 12, 2019
CVE-2019-19247 HIGH

Electronic Arts Origin through 10.5.x allows Elevation of Privilege (issue 1 of 2).

CVSS 7.8 EPSS 0.36% Dec 12, 2019
CVE-2019-12828 HIGH

An issue was discovered in Electronic Arts Origin before 10.5.39. Due to improper sanitization of the origin:// and origin2:// URI schemes, it is possible to i…

CVSS 8.8 EPSS 13.27% Jun 14, 2019
CVE-2019-11354 HIGH

The client in Electronic Arts (EA) Origin 10.5.36 on Windows allows template injection in the title parameter of the Origin2 URI handler. This can be used to e…

CVSS 7.8 EPSS 23.13% Apr 19, 2019
CVE-2014-5921 MEDIUM

The Need for Speed Network (aka com.ea.nfsautolog.bv) application 1.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-th…

CVSS 5.4 EPSS 0.27% Sep 18, 2014
CVE-2010-2627 MEDIUM

Multiple directory traversal vulnerabilities in the Refractor 2 engine, as used in Battlefield 2 1.50 (1.5.3153-802.0) and earlier, and Battlefield 2142 (1.10.…

CVSS 6.8 EPSS 3.66% Jul 2, 2010
CVE-2008-6737 HIGH

Crysis 1.21 and earlier allows remote attackers to obtain sensitive player information such as real IP addresses by sending a keyexchange packet without a prev…

CVSS 7.8 EPSS 2.67% Apr 21, 2009
CVE-2008-6712 MEDIUM

The HTTP/XML-RPC service in Crysis 1.21 (game version 1.1.1.6156) and earlier allows remote attackers to cause a denial of service (crash) via a long HTTP requ…

CVSS 5.0 EPSS 7.40% Apr 10, 2009

Showing 1 to 12 CVEs · page 1