
CVE-2020-36486
https://notcve.org/view.php?id=CVE-2020-36486
22 Oct 2021 — Swift File Transfer Mobile v1.1.2 and below was discovered to contain a cross-site scripting (XSS) vulnerability via the 'path' parameter of the 'list' and 'download' exception-handling. Se ha detectado que Swift File Transfer Mobile versión v1.1.2 y por debajo, contienen una vulnerabilidad de tipo cross-site scripting (XSS) por medio del parámetro "path" del manejo de excepciones "list" y "download" • https://www.vulnerability-lab.com/get_content.php?id=2205 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2019-9506 – Blutooth BR/EDR specification does not specify sufficient encryption key length and allows an attacker to influence key length negotiation
https://notcve.org/view.php?id=CVE-2019-9506
14 Aug 2019 — The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does not prevent an attacker from influencing the key length negotiation. This allows practical brute-force attacks (aka "KNOB") that can decrypt traffic and inject arbitrary ciphertext without the victim noticing. La especificación de Bluetooth BR/EDR incluyendo versión 5.1, permite una longitud de clave de cifrado suficientemente baja y no impide que un atacante influya en la negociación d... • https://github.com/francozappa/knob • CWE-310: Cryptographic Issues CWE-327: Use of a Broken or Risky Cryptographic Algorithm •

CVE-2016-1914 – BlackBerry Enterprise Service < 12.4 (BES12) Self-Service - Multiple Vulnerabilities
https://notcve.org/view.php?id=CVE-2016-1914
21 Feb 2016 — Multiple SQL injection vulnerabilities in the com.rim.mdm.ui.server.ImageServlet servlet in BlackBerry Enterprise Server 12 (BES12) Self-Service before 12.4 allow remote attackers to execute arbitrary SQL commands via the imageName parameter to (1) mydevice/client/image, (2) admin/client/image, (3) myapps/client/image, (4) ssam/client/image, or (5) all/client/image. Varias vulnerabilidades de inyección de SQL en el servlet com.rim.mdm.ui.server.ImageServlet en BlackBerry Enterprise Server 12 (BES12) Self-Se... • https://packetstorm.news/files/id/135860 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2016-1915 – BlackBerry Enterprise Service < 12.4 (BES12) Self-Service - Multiple Vulnerabilities
https://notcve.org/view.php?id=CVE-2016-1915
21 Feb 2016 — Multiple cross-site scripting (XSS) vulnerabilities in BlackBerry Enterprise Server 12 (BES12) Self-Service before 12.4 allow remote attackers to inject arbitrary web script or HTML via the locale parameter to (1) mydevice/index.jsp or (2) mydevice/loggedOut.jsp. Varias vulnerabilidades de XSS en BlackBerry Enterprise Server 12 Self-Service en versiones anteriores a 12.4 permiten a los atacantes remotos inyectar secuencias de comandos web o HTML a través del parámetro local en mydevice/ndex.jsp o (2) mydevi... • https://packetstorm.news/files/id/135860 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2015-4111
https://notcve.org/view.php?id=CVE-2015-4111
20 Jul 2015 — mc_demux_mp4_ds.ax in an unspecified third-party codec demux in BlackBerry Link before 1.2.3.53 with installer before 1.1.0.22 allows remote attackers to execute arbitrary code via a crafted MP4 file. Vulnerabilidad en mc_demux_mp4_ds.ax, un códec demux de terceros no especificados en BlackBerry Link anterior a la versión 1.2.3.53 con instalador anterior a 1.1.0.22, permite a los atacantes remotos ejecutar código arbitrario a través de un archivo MP4 manipulado. • http://www.blackberry.com/btsc/KB37207 • CWE-20: Improper Input Validation •

CVE-2014-6611
https://notcve.org/view.php?id=CVE-2014-6611
25 Oct 2014 — The BlackBerry World app before 5.0.0.262 on BlackBerry 10 OS 10.2.0, before 5.0.0.263 on BlackBerry 10 OS 10.2.1, and before 5.1.0.53 on BlackBerry 10 OS 10.3.0 does not properly validate download/update requests, which allows user-assisted man-in-the-middle attackers to spoof servers and trigger the download of a crafted app by modifying the client-server data stream. La aplicación BlackBerry World anterior a 5.0.0.262 en BlackBerry 10 OS 10.2.0, anterior a 5.0.0.263 en BlackBerry 10 OS 10.2.1, y anterior... • http://secunia.com/advisories/61013 • CWE-20: Improper Input Validation •

CVE-2014-1469
https://notcve.org/view.php?id=CVE-2014-1469
18 Aug 2014 — BlackBerry Enterprise Server 5.x before 5.0.4 MR7 and Enterprise Service 10.x before 10.2.2 log cleartext credentials during exception handling, which allows local users to obtain sensitive information by reading the exception log file. BlackBerry Enterprise Server 5.x anterior a 5.0.4 MR7 y Enterprise Service 10.x anterior a 10.2.2 registran las credenciales en texto plano durante el manejo de excepciones, lo que permite a usuarios locales obtener información sensible mediante la lectura del fichero del re... • http://secunia.com/advisories/60154 • CWE-310: Cryptographic Issues •

CVE-2014-2388 – BlackBerry Z10 Authentication Bypass
https://notcve.org/view.php?id=CVE-2014-2388
13 Aug 2014 — The Storage and Access service in BlackBerry OS 10.x before 10.2.1.1925 on Q5, Q10, Z10, and Z30 devices does not enforce the password requirement for SMB filesystem access, which allows context-dependent attackers to read arbitrary files via (1) a session over a Wi-Fi network or (2) a session over a USB connection in Development Mode. El servicio de almacenamiento y acceso en BlackBerry OS 10.x anterior a 10.2.1.1925 en los dispositivos Q5, Q10, Z10, y Z30 no aplica el requisito de contraseñas para el acce... • https://packetstorm.news/files/id/127850 • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2014-2389 – BlackBerry Z 10 Buffer Overflow
https://notcve.org/view.php?id=CVE-2014-2389
08 Apr 2014 — Stack-based buffer overflow in a certain decryption function in qconnDoor on BlackBerry Z10 devices with software 10.1.0.2312, when developer-mode has been previously enabled, allows remote attackers to execute arbitrary code via a crafted packet in a TCP session on a wireless network. Desbordamiento de búfer basado en pila en una cierta función de descifrado en qconnDoor en dispositivos BlackBerry Z10 con software 10.1.0.2312, cuando el modo desarrollador ha sido habilitado previamente, permite a atacantes... • https://packetstorm.news/files/id/126061 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2014-1467
https://notcve.org/view.php?id=CVE-2014-1467
14 Feb 2014 — BlackBerry Enterprise Service 10 before 10.2.1, Universal Device Service 6, Enterprise Server Express for Domino through 5.0.4, Enterprise Server Express for Exchange through 5.0.4, Enterprise Server for Domino through 5.0.4 MR6, Enterprise Server for Exchange through 5.0.4 MR6, and Enterprise Server for GroupWise through 5.0.4 MR6 log cleartext credentials during exception handling, which might allow context-dependent attackers to obtain sensitive information by reading a log file. BlackBerry Enterprise Se... • http://www.blackberry.com/btsc/KB35647 • CWE-255: Credentials Management Errors •