| Vulnerability Name: | CVE-2009-0306 (CCN-54134) | ||||||||
| Assigned: | 2009-11-03 | ||||||||
| Published: | 2009-11-03 | ||||||||
| Updated: | 2009-11-12 | ||||||||
| Summary: | Buffer overflow in the IBM Lotus Notes Intellisync ActiveX control in lnresobject.dll in BlackBerry Desktop Manager in Research In Motion (RIM) BlackBerry Desktop Software before 5.0.1 allows remote attackers to execute arbitrary code via a crafted web page. Note: some of these details are obtained from third party information. | ||||||||
| CVSS v3 Severity: | 10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
| CVSS v2 Severity: | 9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C) 6.9 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
6.9 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||
| Vulnerability Type: | CWE-119 | ||||||||
| Vulnerability Consequences: | Gain Access | ||||||||
| References: | Source: MITRE Type: CNA CVE-2009-0306 Source: CCN Type: SA37244 BlackBerry Desktop Software Lotus Notes Intellisync Arbitrary Code Execution Source: CCN Type: Blackberry KB19701 Vulnerability in the BlackBerry Desktop Manager allows remote code execution Source: CONFIRM Type: Patch, Vendor Advisory http://www.blackberry.com/btsc/search.do?cmd=displayKC&docType=kc&externalId=KB19701 Source: CCN Type: DOE-CIRC TECHNICAL BULLETIN T-265 BlackBerry Desktop Manager ActiveX Control Remote Code Execution Vulnerability Source: CCN Type: OSVDB ID: 59748 IBM Lotus Notes Intellisync in BlackBerry Desktop Manager lnresobject.dll ActiveX Crafted Web Page Overflow Source: BID Type: UNKNOWN 36903 Source: CCN Type: BID-36903 BlackBerry Desktop Manager ActiveX Control Remote Code Execution Vulnerability Source: VUPEN Type: Patch, Vendor Advisory ADV-2009-3133 Source: XF Type: UNKNOWN blackberry-insresobject-code-execution(54134) | ||||||||
| Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||