CVE-2010-2602
Multiple buffer overflows in the PDF distiller component in the BlackBerry Attachment Service in BlackBerry Enterprise Server 5.0.0 through 5.0.2, 4.1.6, and 4.1.7 allow remote attackers to cause a denial of service (crash) and possibly execute…
Does this matter?
Lower severity and a low EPSS score (2.92%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple buffer overflows in the PDF distiller component in the BlackBerry Attachment Service in BlackBerry Enterprise Server 5.0.0 through 5.0.2, 4.1.6, and 4.1.7 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PDF document.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 2.92% probability · 86th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- rim/blackberry enterprise server
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/35632Vendor Advisory
- http://www.blackberry.com/btsc/search.do?cmd=displayKC&docType=kc&externalId=KB24761Vendor Advisory
- http://www.securityfocus.com/bid/45392
- http://www.securitytracker.com/id?1024891
- http://www.vupen.com/english/advisories/2010/3237Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/64066
- http://secunia.com/advisories/35632Vendor Advisory
- http://www.blackberry.com/btsc/search.do?cmd=displayKC&docType=kc&externalId=KB24761Vendor Advisory
- http://www.securityfocus.com/bid/45392
- http://www.securitytracker.com/id?1024891
- http://www.vupen.com/english/advisories/2010/3237Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/64066
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.