// For flags

CVE-2009-0219

 

Severity Score

9.3
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The PDF distiller in the Attachment Service in Research in Motion (RIM) BlackBerry Enterprise Server (BES) 4.1.3 through 4.1.6, BlackBerry Professional Software 4.1.4, and BlackBerry Unite! before 1.0.3 bundle 28 performs delete operations on uninitialized pointers, which allows user-assisted remote attackers to execute arbitrary code via a crafted data stream in a .pdf file.

El PDF distiller en el servicio Attachment en Research in Motion (RIM) BlackBerry Enterprise Server (BES) v4.1.3 hasta v4.1.6, BlackBerry Professional Software v4.1.4, y BlackBerry Unite! anteriores a v1.0.3 bundle 28 realiza operaciones de borrado en punteros sin inicializar, lo que permite a atacantes remotos ayudados por el usuario ejecutar código de su elección a través de una secuencia de datos manipulada en un fichero .pdf.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2009-01-20 CVE Reserved
  • 2009-01-21 CVE Published
  • 2023-03-07 EPSS Updated
  • 2024-08-07 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-399: Resource Management Errors
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Research In Motion Limited
Search vendor "Research In Motion Limited"
Blackberry Enterprise Server
Search vendor "Research In Motion Limited" for product "Blackberry Enterprise Server"
4.1.3
Search vendor "Research In Motion Limited" for product "Blackberry Enterprise Server" and version "4.1.3"
-
Affected
Research In Motion Limited
Search vendor "Research In Motion Limited"
Blackberry Enterprise Server
Search vendor "Research In Motion Limited" for product "Blackberry Enterprise Server"
4.1.4
Search vendor "Research In Motion Limited" for product "Blackberry Enterprise Server" and version "4.1.4"
-
Affected
Research In Motion Limited
Search vendor "Research In Motion Limited"
Blackberry Enterprise Server
Search vendor "Research In Motion Limited" for product "Blackberry Enterprise Server"
4.1.5
Search vendor "Research In Motion Limited" for product "Blackberry Enterprise Server" and version "4.1.5"
-
Affected
Research In Motion Limited
Search vendor "Research In Motion Limited"
Blackberry Enterprise Server
Search vendor "Research In Motion Limited" for product "Blackberry Enterprise Server"
4.1.6
Search vendor "Research In Motion Limited" for product "Blackberry Enterprise Server" and version "4.1.6"
-
Affected
Research In Motion Limited
Search vendor "Research In Motion Limited"
Blackberry Professional Software
Search vendor "Research In Motion Limited" for product "Blackberry Professional Software"
4.1.4
Search vendor "Research In Motion Limited" for product "Blackberry Professional Software" and version "4.1.4"
-
Affected
Research In Motion Limited
Search vendor "Research In Motion Limited"
Blackberry Unite
Search vendor "Research In Motion Limited" for product "Blackberry Unite"
<= 1.0.3
Search vendor "Research In Motion Limited" for product "Blackberry Unite" and version " <= 1.0.3"
-
Affected
Research In Motion Limited
Search vendor "Research In Motion Limited"
Blackberry Unite
Search vendor "Research In Motion Limited" for product "Blackberry Unite"
1.0
Search vendor "Research In Motion Limited" for product "Blackberry Unite" and version "1.0"
-
Affected
Research In Motion Limited
Search vendor "Research In Motion Limited"
Blackberry Unite
Search vendor "Research In Motion Limited" for product "Blackberry Unite"
1.0.1
Search vendor "Research In Motion Limited" for product "Blackberry Unite" and version "1.0.1"
-
Affected
Research In Motion Limited
Search vendor "Research In Motion Limited"
Blackberry Unite
Search vendor "Research In Motion Limited" for product "Blackberry Unite"
1.0.2
Search vendor "Research In Motion Limited" for product "Blackberry Unite" and version "1.0.2"
-
Affected