Lucene search

K
cve[email protected]CVE-2009-0176
HistoryOct 03, 2022 - 4:24 p.m.

CVE-2009-0176

2022-10-0316:24:12
CWE-119
web.nvd.nist.gov
27
cve-2009-0176
pdf distiller
blackberry enterprise server
heap-based buffer overflow
remote code execution
nvd

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.9 High

AI Score

Confidence

Low

0.013 Low

EPSS

Percentile

85.7%

Multiple heap-based buffer overflows in the PDF distiller in the Attachment Service in Research in Motion (RIM) BlackBerry Enterprise Server (BES) 4.1.3 through 4.1.6, BlackBerry Professional Software 4.1.4, and BlackBerry Unite! before 1.0.3 bundle 28 allow user-assisted remote attackers to execute arbitrary code via (1) a crafted stream in a .pdf file, related to “symWidths”; or (2) a crafted data stream in a .pdf file, related to “bitmaps.”

Affected configurations

NVD
Node
research_in_motion_limitedblackberry_enterprise_serverMatch4.1.3
OR
research_in_motion_limitedblackberry_enterprise_serverMatch4.1.4
OR
research_in_motion_limitedblackberry_enterprise_serverMatch4.1.5
OR
research_in_motion_limitedblackberry_enterprise_serverMatch4.1.6
OR
research_in_motion_limitedblackberry_professional_softwareMatch4.1.4
OR
research_in_motion_limitedblackberry_uniteRange1.0.3
OR
research_in_motion_limitedblackberry_uniteMatch1.0
OR
research_in_motion_limitedblackberry_uniteMatch1.0.1
OR
research_in_motion_limitedblackberry_uniteMatch1.0.2

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.9 High

AI Score

Confidence

Low

0.013 Low

EPSS

Percentile

85.7%

Related for CVE-2009-0176