Lucene search

K
cve[email protected]CVE-2009-4778
HistoryOct 03, 2022 - 4:24 p.m.

CVE-2009-4778

2022-10-0316:24:02
web.nvd.nist.gov
20
rim
blackberry enterprise server
pdf distiller
attachment service
bes software
denial of service
memory corruption
arbitrary code
cve-2009-4778

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

8 High

AI Score

Confidence

High

0.284 Low

EPSS

Percentile

96.9%

Multiple unspecified vulnerabilities in the PDF distiller in the Attachment Service component in Research In Motion (RIM) BlackBerry Enterprise Server (BES) software 4.1.3 through 4.1.7 and 5.0.0, and BlackBerry Professional Software 4.1.4, allow user-assisted remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted .pdf file attachment, a different vulnerability than CVE-2008-3246, CVE-2009-0176, CVE-2009-0219, CVE-2009-2643, and CVE-2009-2646.

Affected configurations

NVD
Node
rimblackberry_enterprise_serverMatch4.1.3
OR
rimblackberry_enterprise_serverMatch4.1.4
OR
rimblackberry_enterprise_serverMatch4.1.5
OR
rimblackberry_enterprise_serverMatch4.1.6
OR
rimblackberry_enterprise_serverMatch4.1.7
OR
rimblackberry_enterprise_serverMatch5.0.0
Node
rimblackberry_professional_softwareMatch4.1.4

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

8 High

AI Score

Confidence

High

0.284 Low

EPSS

Percentile

96.9%

Related for CVE-2009-4778