3 results (0.004 seconds)

CVSS: 7.8EPSS: 2%CPEs: 1EXPL: 0

20 Jul 2015 — mc_demux_mp4_ds.ax in an unspecified third-party codec demux in BlackBerry Link before 1.2.3.53 with installer before 1.1.0.22 allows remote attackers to execute arbitrary code via a crafted MP4 file. Vulnerabilidad en mc_demux_mp4_ds.ax, un códec demux de terceros no especificados en BlackBerry Link anterior a la versión 1.2.3.53 con instalador anterior a 1.1.0.22, permite a los atacantes remotos ejecutar código arbitrario a través de un archivo MP4 manipulado. • http://www.blackberry.com/btsc/KB37207 • CWE-20: Improper Input Validation •

CVSS: 9.1EPSS: 0%CPEs: 9EXPL: 0

16 Nov 2013 — BlackBerry Link before 1.2.1.31 on Windows and before 1.1.1 build 39 on Mac OS X does not properly determine the user account for execution of Peer Manager in certain situations involving successive logins with different accounts, which allows context-dependent attackers to bypass intended restrictions on remote file-access folders via IPv6 WebDAV requests, a different vulnerability than CVE-2013-3694. BlackBerry Link anterior a la versión 1.2.1.31 en Windows y anteriores a 1.1.1 build 39 en Mac OS X no det... • http://www.blackberry.com/btsc/KB35315 • CWE-264: Permissions, Privileges, and Access Controls •

CVSS: 8.1EPSS: 0%CPEs: 9EXPL: 1

16 Nov 2013 — BlackBerry Link before 1.2.1.31 on Windows and before 1.1.1 build 39 on Mac OS X does not require authentication for remote file-access folders, which allows remote attackers to read or create arbitrary files via IPv6 WebDAV requests, as demonstrated by a CSRF attack involving DNS rebinding. BlackBerry Link anterior a la versión 1.2.1.31 en Windows y anterior a 1.1.1 build 39 en Mac OS X no requiere autenticación para carpetas file-access remotas, lo que permite a atacantes remotos leer o crear archivos arb... • http://blog.cmpxchg8b.com/2013/11/qnx.html • CWE-352: Cross-Site Request Forgery (CSRF) •