blackberry kayıtları
blackberry üreticisine ait 93 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 2 · %2,2
- Silahlaştırılmış
- 3 · %3,2
- Pre-auth RCE
- 9
- Düzeltme kaydı olan
- %3,2
- Yayından KEV’e ortanca
- 645 gün
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')15
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor8
- CWE-264 Permissions, Privileges, and Access Controls6
- CWE-20 Improper Input Validation4
- CWE-1287 Improper Validation of Specified Type of Input3
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer3
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
93 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
99Hemen | CVE-2020-1938Silahlaştırılmış | When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat.apache · geode | Kritik9,8 | KEV | %99,3 | 24 Şub 2020 |
82Hemen | CVE-2020-11652Silahlaştırılmış | An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2.saltstack · salt · CWE-22 | Orta6,5 | KEV | %86,2 | 30 Nis 2020 |
40Planlayın | CVE-2020-6932İstismar yok | An information disclosure and remote code execution vulnerability in the slinger web server of the BlackBerry QNX Software Development Platfblackberry · qnx software development platform · CWE-150 | Kritik9,8 | — | %3,6 | 12 Ağu 2020 |
40Planlayın | CVE-2021-22156İstismar yok | An integer overflow vulnerability in the calloc() function of the C runtime library of affected versions of BlackBerry® QNX Software Developblackberry · qnx software development platform · CWE-190 | Kritik9,8 | — | %1,8 | 17 Ağu 2021 |
40Planlayın | CVE-2021-32024İstismar yok | A remote code execution vulnerability in the BMP image codec of BlackBerry QNX SDP version(s) 6.4 to 7.1 could allow an attacker to potentiablackberry · qnx software development platform · CWE-1287 | Kritik9,8 | — | %1,8 | 13 Ara 2021 |
39İzleyin | CVE-2008-3246İstismar yok | Unspecified vulnerability in the PDF distiller component in the BlackBerry Attachment Service in BlackBerry Unite! 1.0 SP1 (1.0.1) before bublackberry · enterprise server · CWE-94 | Kritik9,3 | — | %6,9 | 21 Tem 2008 |
39İzleyin | CVE-2008-3024Kavram kanıtı | Stack-based buffer overflow in phgrafx in QNX Momentics (aka RTOS) 6.3.2 and earlier allows local users to gain privileges via a long .pal fblackberry · qnx momentics · CWE-787 | Kritik9,3 | — | %5,9 | 7 Tem 2008 |
39İzleyin | CVE-2014-2389İstismar yok | Stack-based buffer overflow in a certain decryption function in qconnDoor on BlackBerry Z10 devices with software 10.1.0.2312, when developeblackberry · blackberry os · CWE-119 | Kritik9,3 | — | %5,7 | 12 Nis 2014 |
39İzleyin | CVE-2017-9367İstismar yok | A directory traversal vulnerability in the BlackBerry Workspaces Server could potentially allow an attacker to execute or upload arbitrary fblackberry · workspaces vapp · CWE-22 | Kritik9,8 | — | %1,6 | 16 Eki 2017 |
39İzleyin | CVE-2025-2474İstismar yok | Vulnerability in PCX Image Codec Impacts QNX Software Development Platformblackberry · qnx software development platform · CWE-787 | Kritik9,8 | — | %0,7 | 10 Haz 2025 |
39İzleyin | CVE-2025-3945İstismar yok | Improper Neutralization of Argument Delimiters in a Command (‘Argument Injection’)tridium · niagara · CWE-88 | Kritik9,8 | — | %0,7 | 22 May 2025 |
39İzleyin | CVE-2024-48856İstismar yok | Vulnerabilities in TIFF and PCX Image Codecs Impact QNX Software Development Platformblackberry · qnx software development platform · CWE-787 | Kritik9,8 | — | %0,6 | 14 Oca 2025 |
39İzleyin | CVE-2025-3944İstismar yok | Incorrect Permission Assignment for Critical Resourcetridium · niagara · CWE-732 | Kritik9,8 | — | %0,5 | 22 May 2025 |
39İzleyin | CVE-2025-3940İstismar yok | Improper Use of Validation Frameworktridium · niagara · CWE-1173 | Kritik9,8 | — | %0,4 | 22 May 2025 |
39İzleyin | CVE-2025-3937İstismar yok | Use of Password Hash with Insufficient Computational Efforttridium · niagara · CWE-916 | Kritik9,8 | — | %0,4 | 22 May 2025 |
39İzleyin | CVE-2025-3938İstismar yok | Missing Cryptographic Steptridium · niagara · CWE-325 | Kritik9,8 | — | %0,3 | 22 May 2025 |
38İzleyin | CVE-2017-3891İstismar yok | In BlackBerry QNX Software Development Platform (SDP) 6.6.0, an elevation of privilege vulnerability in the default configuration of the QNXblackberry · qnx software development platform · CWE-923 | Kritik9,6 | — | %1,3 | 14 Kas 2017 |
36İzleyin | CVE-2016-1914Kavram kanıtı | Multiple SQL injection vulnerabilities in the com.rim.mdm.ui.server.ImageServlet servlet in BlackBerry Enterprise Server 12 (BES12) Self-Serblackberry · blackberry enterprise service · CWE-89 | Yüksek8,8 | — | %4,1 | 13 Nis 2017 |
36İzleyin | CVE-2024-35213İstismar yok | Vulnerability in SGI Image Codec Impacts BlackBerry QNX Software Development Platform (SDP)blackberry · qnx software development platform · CWE-1287 | Kritik9,0 | — | %0,5 | 11 Haz 2024 |
35İzleyin | CVE-2021-22155İstismar yok | An Authentication Bypass vulnerability in the SAML Authentication component of BlackBerry Workspaces Server (deployed with Appliance-X) versblackberry · workspaces server · CWE-287 | Yüksek8,8 | — | %1,0 | 12 May 2021 |
35İzleyin | CVE-2017-9370İstismar yok | An information disclosure / elevation of privilege vulnerability in the BlackBerry Workspaces Server could potentially allow an attacker whoblackberry · workspaces · CWE-287 | Yüksek8,8 | — | %0,9 | 9 Ağu 2017 |
34İzleyin | CVE-2026-18084İstismar yok | Cross-Site Scripting (XSS) in Management Console of BlackBerry UEMblackberry · unified endpoint manager · CWE-79 | Yüksek8,6 | — | %0,3 | 28 Tem 2026 |
33İzleyin | CVE-2025-3943İstismar yok | Use of GET Request Method With sensitive Query Stringstridium · niagara · CWE-598 | Yüksek7,5 | — | %10,7 | 22 May 2025 |
33İzleyin | CVE-2013-2687İstismar yok | Stack-based buffer overflow in the bpe_decompress function in (1) BlackBerry QNX Neutrino RTOS through 6.5.0 SP1 and (2) QNX Momentics Tool blackberry · qnx momentics tool suite · CWE-119 | Yüksek7,8 | — | %8,2 | 12 Tem 2013 |
33İzleyin | CVE-2019-9506Kavram kanıtı | Blutooth BR/EDR specification does not specify sufficient encryption key length and allows an attacker to influence key length negotiationgoogle · android · CWE-310 | Yüksek8,1 | — | %2,7 | 14 Ağu 2019 |
- CVE-2020-193899Hemen
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat.
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99apache · geode24 Şub 2020
- CVE-2020-1165282Hemen
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2.
OrtaCVSS 6,5KEVSilahlaştırılmışEPSS %86saltstack · salt30 Nis 2020
- CVE-2020-693240Planlayın
An information disclosure and remote code execution vulnerability in the slinger web server of the BlackBerry QNX Software Development Platf
KritikCVSS 9,8İstismar yokEPSS %4blackberry · qnx software development platform12 Ağu 2020
- CVE-2021-2215640Planlayın
An integer overflow vulnerability in the calloc() function of the C runtime library of affected versions of BlackBerry® QNX Software Develop
KritikCVSS 9,8İstismar yokEPSS %2blackberry · qnx software development platform17 Ağu 2021
- CVE-2021-3202440Planlayın
A remote code execution vulnerability in the BMP image codec of BlackBerry QNX SDP version(s) 6.4 to 7.1 could allow an attacker to potentia
KritikCVSS 9,8İstismar yokEPSS %2blackberry · qnx software development platform13 Ara 2021
- CVE-2008-324639İzleyin
Unspecified vulnerability in the PDF distiller component in the BlackBerry Attachment Service in BlackBerry Unite! 1.0 SP1 (1.0.1) before bu
KritikCVSS 9,3İstismar yokEPSS %7blackberry · enterprise server21 Tem 2008
- CVE-2008-302439İzleyin
Stack-based buffer overflow in phgrafx in QNX Momentics (aka RTOS) 6.3.2 and earlier allows local users to gain privileges via a long .pal f
KritikCVSS 9,3Kavram kanıtıEPSS %6blackberry · qnx momentics7 Tem 2008
- CVE-2014-238939İzleyin
Stack-based buffer overflow in a certain decryption function in qconnDoor on BlackBerry Z10 devices with software 10.1.0.2312, when develope
KritikCVSS 9,3İstismar yokEPSS %6blackberry · blackberry os12 Nis 2014
- CVE-2017-936739İzleyin
A directory traversal vulnerability in the BlackBerry Workspaces Server could potentially allow an attacker to execute or upload arbitrary f
KritikCVSS 9,8İstismar yokEPSS %2blackberry · workspaces vapp16 Eki 2017
- CVE-2025-247439İzleyin
Vulnerability in PCX Image Codec Impacts QNX Software Development Platform
KritikCVSS 9,8İstismar yokEPSS %1blackberry · qnx software development platform10 Haz 2025
- CVE-2025-394539İzleyin
Improper Neutralization of Argument Delimiters in a Command (‘Argument Injection’)
KritikCVSS 9,8İstismar yokEPSS %1tridium · niagara22 May 2025
- CVE-2024-4885639İzleyin
Vulnerabilities in TIFF and PCX Image Codecs Impact QNX Software Development Platform
KritikCVSS 9,8İstismar yokEPSS %1blackberry · qnx software development platform14 Oca 2025
- CVE-2025-394439İzleyin
Incorrect Permission Assignment for Critical Resource
KritikCVSS 9,8İstismar yokEPSS %1tridium · niagara22 May 2025
- CVE-2025-394039İzleyin
Improper Use of Validation Framework
KritikCVSS 9,8İstismar yokEPSS %0tridium · niagara22 May 2025
- CVE-2025-393739İzleyin
Use of Password Hash with Insufficient Computational Effort
KritikCVSS 9,8İstismar yokEPSS %0tridium · niagara22 May 2025
- CVE-2025-393839İzleyin
Missing Cryptographic Step
KritikCVSS 9,8İstismar yokEPSS %0tridium · niagara22 May 2025
- CVE-2017-389138İzleyin
In BlackBerry QNX Software Development Platform (SDP) 6.6.0, an elevation of privilege vulnerability in the default configuration of the QNX
KritikCVSS 9,6İstismar yokEPSS %1blackberry · qnx software development platform14 Kas 2017
- CVE-2016-191436İzleyin
Multiple SQL injection vulnerabilities in the com.rim.mdm.ui.server.ImageServlet servlet in BlackBerry Enterprise Server 12 (BES12) Self-Ser
YüksekCVSS 8,8Kavram kanıtıEPSS %4blackberry · blackberry enterprise service13 Nis 2017
- CVE-2024-3521336İzleyin
Vulnerability in SGI Image Codec Impacts BlackBerry QNX Software Development Platform (SDP)
KritikCVSS 9,0İstismar yokEPSS %1blackberry · qnx software development platform11 Haz 2024
- CVE-2021-2215535İzleyin
An Authentication Bypass vulnerability in the SAML Authentication component of BlackBerry Workspaces Server (deployed with Appliance-X) vers
YüksekCVSS 8,8İstismar yokEPSS %1blackberry · workspaces server12 May 2021
- CVE-2017-937035İzleyin
An information disclosure / elevation of privilege vulnerability in the BlackBerry Workspaces Server could potentially allow an attacker who
YüksekCVSS 8,8İstismar yokEPSS %1blackberry · workspaces9 Ağu 2017
- CVE-2026-1808434İzleyin
Cross-Site Scripting (XSS) in Management Console of BlackBerry UEM
YüksekCVSS 8,6İstismar yokEPSS %0blackberry · unified endpoint manager28 Tem 2026
- CVE-2025-394333İzleyin
Use of GET Request Method With sensitive Query Strings
YüksekCVSS 7,5İstismar yokEPSS %11tridium · niagara22 May 2025
- CVE-2013-268733İzleyin
Stack-based buffer overflow in the bpe_decompress function in (1) BlackBerry QNX Neutrino RTOS through 6.5.0 SP1 and (2) QNX Momentics Tool
YüksekCVSS 7,8İstismar yokEPSS %8blackberry · qnx momentics tool suite12 Tem 2013
- CVE-2019-950633İzleyin
Blutooth BR/EDR specification does not specify sufficient encryption key length and allows an attacker to influence key length negotiation
YüksekCVSS 8,1Kavram kanıtıEPSS %3google · android14 Ağu 2019