Vulnerabilities > Unity3D

DATE CVE VULNERABILITY TITLE RISK
2019-12-31 CVE-2019-9197 OS Command Injection vulnerability in Unity3D Unity Editor
The com.unity3d.kharma protocol handler in Unity Editor 2018.3 allows remote attackers to execute arbitrary code.
network
low complexity
unity3d CWE-78
8.8
2017-08-18 CVE-2017-12939 Improper Input Validation vulnerability in Unity3D Unity Editor
A Remote Code Execution vulnerability was identified in all Windows versions of Unity Editor, e.g., before 5.3.8p2, 5.4.x before 5.4.5p5, 5.5.x before 5.5.4p3, 5.6.x before 5.6.3p1, and 2017.x before 2017.1.0p4.
network
low complexity
unity3d CWE-20
critical
9.8