Electronic Arts maintains a portfolio spanning multiplayer gaming titles and racing simulations, including franchises such as Battlefield, Medal of Honor, Need for Speed, and NASCAR Racing. Its vulnerability disclosures cluster around memory-safety issues and code-injection weaknesses characteristic of large native-code game engines and networked client applications. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Electronic Arts over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2004-0735HIGH Buffer overflow in Medal of Honor (1) Allied Assault 1.11v9 and earlier, (2) Breakthrough 2.40b and earlier, and (3) Spearhead 2.15 and earlier, when playing on a Local Area Networ | Jul 27, 2004 | 7.5 | 70 | NO | YES |
CVE-2007-4466MEDIUM Multiple stack-based buffer overflows in Electronic Arts (EA) SnoopyCtrl ActiveX control (NPSnpy.dll) allow remote attackers to execute arbitrary code via unspecified methods and p | Oct 9, 2007 | 6.8 | 51 | NO | YES |
CVE-2003-1355HIGH Buffer overflow in the remote console (rcon) in Battlefield 1942 1.2 and 1.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a | Dec 31, 2003 | 7.5 | 29 | NO | YES |
CVE-2004-2099MEDIUM Buffer overflow in Need for Speed Hot Pursuit 2.0 client (NFSHP2), version 242 and earlier, allows remote attackers (servers) to execute arbitrary code via long (1) gamename, (2) g | Dec 31, 2004 | 5.1 | 24 | NO | YES |
CVE-2006-3393HIGH Papyrus NASCAR Racing 4 4.1.3.1.6 and earlier, 2002 Season 1.1.0.2 and earlier, and 2003 Season 1.2.0.1 and earlier allows remote attackers to cause a denial of service (CPU consum | Jul 6, 2006 | 7.8 | 20 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Electronic Arts.
Media articles that mention a CVE ID that affects a product developed by Electronic Arts — matched by CVE ID, not by vendor name.