Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Electronic Arts, Inc.

First CVE: Apr 10, 2009Active for: 17 yearsTotal CVEs: 12
47.4
VTI Score
High

Electronic Arts' vulnerability portfolio spans consumer gaming platforms and game-distribution services, including the Origin launcher and flagship game titles such as Battlefield and Crysis, alongside smart-device products. Disclosures cluster around information-exposure, path-traversal, and cross-site scripting weaknesses typical of web-facing services and game-client architectures, and the vendor's vulnerabilities frequently acquire public exploit code. Live severity, exploitation activity, and detailed exposure counts are shown alongside this summary.

FAUCET AI Generated
12
Total CVEs
More Total CVEs than 93% of tracked vendors
0.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 3% of tracked vendors
7.0
Avg CVSS Score
Higher Avg CVSS Score than 50% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Electronic Arts, Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 10, 2009
17 years ago
Most Recent CVE
Nov 2, 2020
2,091 days ago

Self-Reporting Analysis

Of all the CVEs published by Electronic Arts, Inc. as a CNA, 100.0% affect products that Electronic Arts, Inc. develops as a vendor.

100.0%
Self-reported: 1 (100.0%)
Third-party: 0 (0.0%)

Of all the CVEs published that affect products developed by Electronic Arts, Inc., 8.3% are self-published by Electronic Arts, Inc. as a CNA.

91.7%
Self-published: 1 (8.3%)
Other CNAs: 11 (91.7%)

Products(8 total)

Top CVEs

Signals from CVEs in this vendor scope (12 CVEs).

12 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-11354HIGH
The client in Electronic Arts (EA) Origin 10.5.36 on Windows allows template injection in the title parameter of the Origin2 URI handler. This can be used to escape the underlying
Apr 19, 20197.849NOYES
CVE-2019-12828HIGH
An issue was discovered in Electronic Arts Origin before 10.5.39. Due to improper sanitization of the origin:// and origin2:// URI schemes, it is possible to inject additional argu
Jun 14, 20198.846NOYES
CVE-2010-2627MEDIUM
Multiple directory traversal vulnerabilities in the Refractor 2 engine, as used in Battlefield 2 1.50 (1.5.3153-802.0) and earlier, and Battlefield 2142 (1.10.48.0) and earlier, al
Jul 2, 20106.832NOYES
CVE-2008-6737HIGH
Crysis 1.21 and earlier allows remote attackers to obtain sensitive player information such as real IP addresses by sending a keyexchange packet without a previous join packet, whi
Apr 21, 20097.831NOYES
CVE-2020-27708HIGH
A vulnerability exists in the Origin Client that could allow a non-Administrative user to elevate their access to either Administrator or System. Once the user has obtained elevate
Nov 2, 20207.825NONO
CVE-2013-4867MEDIUM
Electronic Arts Karotz Smart Rabbit 12.07.19.00 allows Python module hijacking
Dec 27, 20196.325NOYES
CVE-2019-19248HIGH
Electronic Arts Origin through 10.5.x allows Elevation of Privilege (issue 2 of 2).
Dec 12, 20197.825NONO
CVE-2019-19247HIGH
Electronic Arts Origin through 10.5.x allows Elevation of Privilege (issue 1 of 2).
Dec 12, 20197.825NONO
CVE-2008-6712MEDIUM
The HTTP/XML-RPC service in Crysis 1.21 (game version 1.1.1.6156) and earlier allows remote attackers to cause a denial of service (crash) via a long HTTP request, which triggers a
Apr 10, 20095.025NOYES
CVE-2019-19741HIGH
Electronic Arts Origin 10.5.55.33574 is vulnerable to local privilege escalation due to arbitrary directory DACL manipulation, a different issue than CVE-2019-19247 and CVE-2019-19
Feb 20, 20207.823NONO
View all 12 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products12 CVEs
42%
58%
Severity distribution among all CVEs352,708 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local5 (41.7%)
Network2 (16.7%)
Unknown4 (33.3%)
Physical1 (8.3%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (58.3%)
High1 (8.3%)
Unknown4 (33.3%)
User Interaction
None4 (33.3%)
Unknown4 (33.3%)
Required4 (33.3%)
Privileges Required
Low5 (41.7%)
High0 (0.0%)
None3 (25.0%)
Unknown4 (33.3%)

Exploit Exposure

Signals from CVEs in this vendor scope (12 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
6 CVEs
50.0% of CVEs· 81st percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Electronic Arts, Inc..

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Electronic Arts, Inc. — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Electronic Arts, Inc.'s Products

View all 3 CNAs →

Top CWEs