Show filters
80 Total Results
Displaying 61-70 of 80
Sort by:
Attacker Value
Unknown

CVE-2016-1918

Disclosure Date: April 22, 2016 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in the Management Console in BlackBerry Enterprise Server (BES) 12 before 12.4.1 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2016-1917.
0
Attacker Value
Unknown

CVE-2015-4112

Disclosure Date: November 19, 2015 (last updated October 05, 2023)
The Management Console in BlackBerry Enterprise Server (BES) 12 before 12.2 does not properly restrict use of FRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web site, related to a "cross frame scripting" issue.
0
Attacker Value
Unknown

CVE-2015-4111

Disclosure Date: July 20, 2015 (last updated October 05, 2023)
mc_demux_mp4_ds.ax in an unspecified third-party codec demux in BlackBerry Link before 1.2.3.53 with installer before 1.1.0.22 allows remote attackers to execute arbitrary code via a crafted MP4 file.
0
Attacker Value
Unknown

CVE-2014-6611

Disclosure Date: October 25, 2014 (last updated October 05, 2023)
The BlackBerry World app before 5.0.0.262 on BlackBerry 10 OS 10.2.0, before 5.0.0.263 on BlackBerry 10 OS 10.2.1, and before 5.1.0.53 on BlackBerry 10 OS 10.3.0 does not properly validate download/update requests, which allows user-assisted man-in-the-middle attackers to spoof servers and trigger the download of a crafted app by modifying the client-server data stream.
0
Attacker Value
Unknown

CVE-2014-2388

Disclosure Date: August 18, 2014 (last updated October 05, 2023)
The Storage and Access service in BlackBerry OS 10.x before 10.2.1.1925 on Q5, Q10, Z10, and Z30 devices does not enforce the password requirement for SMB filesystem access, which allows context-dependent attackers to read arbitrary files via (1) a session over a Wi-Fi network or (2) a session over a USB connection in Development Mode.
0
Attacker Value
Unknown

CVE-2014-1469

Disclosure Date: August 18, 2014 (last updated October 05, 2023)
BlackBerry Enterprise Server 5.x before 5.0.4 MR7 and Enterprise Service 10.x before 10.2.2 log cleartext credentials during exception handling, which allows local users to obtain sensitive information by reading the exception log file.
0
Attacker Value
Unknown

CVE-2014-2389

Disclosure Date: April 12, 2014 (last updated October 05, 2023)
Stack-based buffer overflow in a certain decryption function in qconnDoor on BlackBerry Z10 devices with software 10.1.0.2312, when developer-mode has been previously enabled, allows remote attackers to execute arbitrary code via a crafted packet in a TCP session on a wireless network.
0
Attacker Value
Unknown

CVE-2014-2533

Disclosure Date: March 18, 2014 (last updated October 05, 2023)
/sbin/ifwatchd in BlackBerry QNX Neutrino RTOS 6.4.x and 6.5.x allows local users to gain privileges by providing an arbitrary program name as a command-line argument.
0
Attacker Value
Unknown

CVE-2014-2534

Disclosure Date: March 18, 2014 (last updated October 05, 2023)
/sbin/pppoectl in BlackBerry QNX Neutrino RTOS 6.4.x and 6.5.x allows local users to obtain sensitive information by reading "bad parameter" lines in error messages, as demonstrated by reading the root password hash in /etc/shadow.
0
Attacker Value
Unknown

CVE-2014-1467

Disclosure Date: February 14, 2014 (last updated October 05, 2023)
BlackBerry Enterprise Service 10 before 10.2.1, Universal Device Service 6, Enterprise Server Express for Domino through 5.0.4, Enterprise Server Express for Exchange through 5.0.4, Enterprise Server for Domino through 5.0.4 MR6, Enterprise Server for Exchange through 5.0.4 MR6, and Enterprise Server for GroupWise through 5.0.4 MR6 log cleartext credentials during exception handling, which might allow context-dependent attackers to obtain sensitive information by reading a log file.
0