CVE-2009-0176
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Multiple heap-based buffer overflows in the PDF distiller in the Attachment Service in Research in Motion (RIM) BlackBerry Enterprise Server (BES) 4.1.3 through 4.1.6, BlackBerry Professional Software 4.1.4, and BlackBerry Unite! before 1.0.3 bundle 28 allow user-assisted remote attackers to execute arbitrary code via (1) a crafted stream in a .pdf file, related to "symWidths"; or (2) a crafted data stream in a .pdf file, related to "bitmaps."
Múltiples desbordamientos de búfer basados en montículo en PDF distiller en el Servicio de Adjuntar en Research in Motion (RIM) Blackberry Enterprise Server (BES) v4.1.3 hasta 4.1.6, Blackberry Professional Software v4.1.4, y blackberry Unite! anteriores a v1.0.3 bundle 28, permite a atacantes remotos asistidos por usuarios, ejecutar código de su elección a a través (1)cadena manípulada en un fichero .PDF, relativo a "symWidths"; o (2) a cadenas de datos manipulada en un fichero .PDF, relativo a "bitmaps".
CVSS Scores
SSVC
- Decision:-
Timeline
- 2009-01-20 CVE Reserved
- 2009-01-20 CVE Published
- 2024-09-17 CVE Updated
- 2024-09-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=764 | Third Party Advisory | |
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=765 | Third Party Advisory | |
http://www.securityfocus.com/bid/33224 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Research In Motion Limited Search vendor "Research In Motion Limited" | Blackberry Enterprise Server Search vendor "Research In Motion Limited" for product "Blackberry Enterprise Server" | 4.1.3 Search vendor "Research In Motion Limited" for product "Blackberry Enterprise Server" and version "4.1.3" | - |
Affected
| ||||||
Research In Motion Limited Search vendor "Research In Motion Limited" | Blackberry Enterprise Server Search vendor "Research In Motion Limited" for product "Blackberry Enterprise Server" | 4.1.4 Search vendor "Research In Motion Limited" for product "Blackberry Enterprise Server" and version "4.1.4" | - |
Affected
| ||||||
Research In Motion Limited Search vendor "Research In Motion Limited" | Blackberry Enterprise Server Search vendor "Research In Motion Limited" for product "Blackberry Enterprise Server" | 4.1.5 Search vendor "Research In Motion Limited" for product "Blackberry Enterprise Server" and version "4.1.5" | - |
Affected
| ||||||
Research In Motion Limited Search vendor "Research In Motion Limited" | Blackberry Enterprise Server Search vendor "Research In Motion Limited" for product "Blackberry Enterprise Server" | 4.1.6 Search vendor "Research In Motion Limited" for product "Blackberry Enterprise Server" and version "4.1.6" | - |
Affected
| ||||||
Research In Motion Limited Search vendor "Research In Motion Limited" | Blackberry Professional Software Search vendor "Research In Motion Limited" for product "Blackberry Professional Software" | 4.1.4 Search vendor "Research In Motion Limited" for product "Blackberry Professional Software" and version "4.1.4" | - |
Affected
| ||||||
Research In Motion Limited Search vendor "Research In Motion Limited" | Blackberry Unite Search vendor "Research In Motion Limited" for product "Blackberry Unite" | <= 1.0.3 Search vendor "Research In Motion Limited" for product "Blackberry Unite" and version " <= 1.0.3" | - |
Affected
| ||||||
Research In Motion Limited Search vendor "Research In Motion Limited" | Blackberry Unite Search vendor "Research In Motion Limited" for product "Blackberry Unite" | 1.0 Search vendor "Research In Motion Limited" for product "Blackberry Unite" and version "1.0" | - |
Affected
| ||||||
Research In Motion Limited Search vendor "Research In Motion Limited" | Blackberry Unite Search vendor "Research In Motion Limited" for product "Blackberry Unite" | 1.0.1 Search vendor "Research In Motion Limited" for product "Blackberry Unite" and version "1.0.1" | - |
Affected
| ||||||
Research In Motion Limited Search vendor "Research In Motion Limited" | Blackberry Unite Search vendor "Research In Motion Limited" for product "Blackberry Unite" | 1.0.2 Search vendor "Research In Motion Limited" for product "Blackberry Unite" and version "1.0.2" | - |
Affected
|