CVE-2009-0305
Multiple stack-based buffer overflows in the Research in Motion RIM AxLoader ActiveX control in AxLoader.ocx and AxLoader.dll in BlackBerry Application Web Loader 1.0 allow remote attackers to execute arbitrary code via unspecified use of the (1) load…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 16.9%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
Multiple stack-based buffer overflows in the Research in Motion RIM AxLoader ActiveX control in AxLoader.ocx and AxLoader.dll in BlackBerry Application Web Loader 1.0 allow remote attackers to execute arbitrary code via unspecified use of the (1) load or (2) loadJad method.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 16.92% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- research in motion limited/blackberry application web loader
- Source
- cve@mitre.org
References
- http://blackberry.com/btsc/KB16248Patch, Vendor Advisory
- http://osvdb.org/51833
- http://secunia.com/advisories/33847Vendor Advisory
- http://www.kb.cert.org/vuls/id/131100US Government Resource
- http://www.microsoft.com/technet/security/advisory/960715.mspx
- http://www.securityfocus.com/bid/33663
- http://blackberry.com/btsc/KB16248Patch, Vendor Advisory
- http://osvdb.org/51833
- http://secunia.com/advisories/33847Vendor Advisory
- http://www.kb.cert.org/vuls/id/131100US Government Resource
- http://www.microsoft.com/technet/security/advisory/960715.mspx
- http://www.securityfocus.com/bid/33663
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.