Show filters
80 Total Results
Displaying 71-80 of 80
Sort by:
Attacker Value
Unknown
CVE-2013-3694
Disclosure Date: November 18, 2013 (last updated October 05, 2023)
BlackBerry Link before 1.2.1.31 on Windows and before 1.1.1 build 39 on Mac OS X does not require authentication for remote file-access folders, which allows remote attackers to read or create arbitrary files via IPv6 WebDAV requests, as demonstrated by a CSRF attack involving DNS rebinding.
0
Attacker Value
Unknown
CVE-2013-6798
Disclosure Date: November 18, 2013 (last updated October 05, 2023)
BlackBerry Link before 1.2.1.31 on Windows and before 1.1.1 build 39 on Mac OS X does not properly determine the user account for execution of Peer Manager in certain situations involving successive logins with different accounts, which allows context-dependent attackers to bypass intended restrictions on remote file-access folders via IPv6 WebDAV requests, a different vulnerability than CVE-2013-3694.
0
Attacker Value
Unknown
CVE-2013-3693
Disclosure Date: October 11, 2013 (last updated October 05, 2023)
The BlackBerry Universal Device Service in BlackBerry Enterprise Service (BES) 10.0 through 10.1.2 does not properly restrict access to the JBoss Remote Method Invocation (RMI) interface, which allows remote attackers to upload and execute arbitrary packages via a request to port 1098.
0
Attacker Value
Unknown
CVE-2013-3692
Disclosure Date: July 13, 2013 (last updated October 05, 2023)
BlackBerry 10 OS before 10.0.10.648 on BlackBerry Z10 smartphones uses weak permissions for a BlackBerry Protect object, which allows physically proximate attackers to bypass intended access restrictions by leveraging a user's BlackBerry Protect password-reset request and a user's installation of a crafted application.
0
Attacker Value
Unknown
CVE-2013-2688
Disclosure Date: July 12, 2013 (last updated October 05, 2023)
Buffer overflow in phrelay in BlackBerry QNX Neutrino RTOS through 6.5.0 SP1 in the QNX Software Development Platform allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted packets to TCP port 4868 that leverage improper handling of the /dev/photon device file.
0
Attacker Value
Unknown
CVE-2013-2687
Disclosure Date: July 12, 2013 (last updated October 05, 2023)
Stack-based buffer overflow in the bpe_decompress function in (1) BlackBerry QNX Neutrino RTOS through 6.5.0 SP1 and (2) QNX Momentics Tool Suite through 6.5.0 SP1 in the QNX Software Development Platform allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted packets to TCP port 4868.
0
Attacker Value
Unknown
CVE-2011-0291
Disclosure Date: December 08, 2011 (last updated October 04, 2023)
The BlackBerry PlayBook service on the Research In Motion (RIM) BlackBerry PlayBook tablet with software before 1.0.8.6067 allows local users to gain privileges via a crafted configuration file in a backup archive.
0
Attacker Value
Unknown
CVE-2008-3246
Disclosure Date: July 21, 2008 (last updated October 04, 2023)
Unspecified vulnerability in the PDF distiller component in the BlackBerry Attachment Service in BlackBerry Unite! 1.0 SP1 (1.0.1) before bundle 36 and BlackBerry Enterprise Server 4.1 SP3 (4.1.3) through 4.1 SP5 (4.1.5) allows user-assisted remote attackers to execute arbitrary code via a crafted PDF file attachment.
0
Attacker Value
Unknown
CVE-2008-3024
Disclosure Date: July 07, 2008 (last updated October 04, 2023)
Stack-based buffer overflow in phgrafx in QNX Momentics (aka RTOS) 6.3.2 and earlier allows local users to gain privileges via a long .pal filename in palette/.
0
Attacker Value
Unknown
CVE-2002-0793
Disclosure Date: August 12, 2002 (last updated February 22, 2025)
Hard link and possibly symbolic link following vulnerabilities in QNX RTOS 4.25 (aka QNX4) allow local users to overwrite arbitrary files via (1) the -f argument to the monitor utility, (2) the -d argument to dumper, (3) the -c argument to crttrap, or (4) using the Watcom sample utility.
0