Ubi's vulnerability footprint is concentrated in a narrow set of consumer gaming and digital-distribution products, notably Uplay PC and Rayman Legends, with the durable signal centered on system-level input-handling flaws. The observed weakness classes cluster around OS command injection and memory-buffer boundary issues, which are characteristic of native code handling external or untrusted input. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ubi over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-4177HIGH The web browser plugin for Ubisoft Uplay PC before 2.0.4 allows remote attackers to execute arbitrary programs via the -orbit_exe_path command line argument. | Aug 7, 2012 | 10.0 | 79 | NO | YES |
CVE-2014-4334HIGH Stack-based buffer overflow in Ubisoft Rayman Legends before 1.3.140380 allows remote attackers to execute arbitrary code via a long string in the "second connection" to TCP port 1 | Jun 19, 2014 | 7.5 | 35 | NO | YES |
CVE-2014-5453HIGH Ubisoft Uplay PC before 4.6.1.3217 use weak permissions (Everyone: Full Control) for the program installation directory (%PROGRAMFILES%\Ubisoft Game Launcher), which allows local u | Aug 25, 2014 | 7.2 | 33 | NO | YES |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ubi.
Media articles that mention a CVE ID that affects a product developed by Ubi — matched by CVE ID, not by vendor name.