Electronic Arts' vulnerability portfolio spans consumer gaming platforms and game-distribution services, including the Origin launcher and flagship game titles such as Battlefield and Crysis, alongside smart-device products. Disclosures cluster around information-exposure, path-traversal, and cross-site scripting weaknesses typical of web-facing services and game-client architectures, and the vendor's vulnerabilities frequently acquire public exploit code. Live severity, exploitation activity, and detailed exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Electronic Arts, Inc. over time
Of all the CVEs published by Electronic Arts, Inc. as a CNA, 100.0% affect products that Electronic Arts, Inc. develops as a vendor.
Of all the CVEs published that affect products developed by Electronic Arts, Inc., 8.3% are self-published by Electronic Arts, Inc. as a CNA.
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-11354HIGH The client in Electronic Arts (EA) Origin 10.5.36 on Windows allows template injection in the title parameter of the Origin2 URI handler. This can be used to escape the underlying | Apr 19, 2019 | 7.8 | 49 | NO | YES |
CVE-2019-12828HIGH An issue was discovered in Electronic Arts Origin before 10.5.39. Due to improper sanitization of the origin:// and origin2:// URI schemes, it is possible to inject additional argu | Jun 14, 2019 | 8.8 | 46 | NO | YES |
CVE-2010-2627MEDIUM Multiple directory traversal vulnerabilities in the Refractor 2 engine, as used in Battlefield 2 1.50 (1.5.3153-802.0) and earlier, and Battlefield 2142 (1.10.48.0) and earlier, al | Jul 2, 2010 | 6.8 | 32 | NO | YES |
CVE-2008-6737HIGH Crysis 1.21 and earlier allows remote attackers to obtain sensitive player information such as real IP addresses by sending a keyexchange packet without a previous join packet, whi | Apr 21, 2009 | 7.8 | 31 | NO | YES |
CVE-2020-27708HIGH A vulnerability exists in the Origin Client that could allow a non-Administrative user to elevate their access to either Administrator or System. Once the user has obtained elevate | Nov 2, 2020 | 7.8 | 25 | NO | NO |
CVE-2013-4867MEDIUM Electronic Arts Karotz Smart Rabbit 12.07.19.00 allows Python module hijacking | Dec 27, 2019 | 6.3 | 25 | NO | YES |
CVE-2019-19248HIGH Electronic Arts Origin through 10.5.x allows Elevation of Privilege (issue 2 of 2). | Dec 12, 2019 | 7.8 | 25 | NO | NO |
CVE-2019-19247HIGH Electronic Arts Origin through 10.5.x allows Elevation of Privilege (issue 1 of 2). | Dec 12, 2019 | 7.8 | 25 | NO | NO |
CVE-2008-6712MEDIUM The HTTP/XML-RPC service in Crysis 1.21 (game version 1.1.1.6156) and earlier allows remote attackers to cause a denial of service (crash) via a long HTTP request, which triggers a | Apr 10, 2009 | 5.0 | 25 | NO | YES |
CVE-2019-19741HIGH Electronic Arts Origin 10.5.55.33574 is vulnerable to local privilege escalation due to arbitrary directory DACL manipulation, a different issue than CVE-2019-19247 and CVE-2019-19 | Feb 20, 2020 | 7.8 | 23 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Electronic Arts, Inc..
Media articles that mention a CVE ID that affects a product developed by Electronic Arts, Inc. — matched by CVE ID, not by vendor name.