CVE-2010-2604
Multiple buffer overflows in the PDF Distiller in the BlackBerry Attachment Service component in Research In Motion (RIM) BlackBerry Enterprise Server 4.1.3 through 5.0.2, and Enterprise Server Express 5.0.1 and 5.0.2, allow remote attackers to execute…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (5.72%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple buffer overflows in the PDF Distiller in the BlackBerry Attachment Service component in Research In Motion (RIM) BlackBerry Enterprise Server 4.1.3 through 5.0.2, and Enterprise Server Express 5.0.1 and 5.0.2, allow remote attackers to execute arbitrary code via a crafted PDF file.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 5.72% probability · 93th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- rim/blackberry enterprise server · rim/blackberry enterprise server express
- Source
- cve@mitre.org
References
- http://osvdb.org/70393
- http://secunia.com/advisories/42882Vendor Advisory
- http://www.blackberry.com/btsc/KB25382Vendor Advisory
- http://www.securityfocus.com/bid/45753
- http://www.securitytracker.com/id?1024953
- http://www.vupen.com/english/advisories/2011/0081Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/64621
- http://osvdb.org/70393
- http://secunia.com/advisories/42882Vendor Advisory
- http://www.blackberry.com/btsc/KB25382Vendor Advisory
- http://www.securityfocus.com/bid/45753
- http://www.securitytracker.com/id?1024953
- http://www.vupen.com/english/advisories/2011/0081Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/64621
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.