Vulnerability index

Browse CVEs

66 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unified Endpoint Management HIGH 7.5
CVE-2019-8999

An XML External Entity vulnerability in the UEM Core of BlackBerry UEM version(s) earlier than 12.10.1a could allow an attacker to potentially gain r…

Fix: after 12.10.1a
Fix from $1,950 2019-04-18
Athoc MEDIUM 5.9
CVE-2019-8997

An XML External Entity Injection (XXE) vulnerability in the Management System (console) of BlackBerry AtHoc versions earlier than 7.6 HF-567 could al…

Fix: 7.6_hf-567+
Fix from $1,600 2019-03-21
Unified Endpoint Manager MEDIUM 6.5
CVE-2018-8892

A cross-site request forgery (CSRF) vulnerability in the Management Console of BlackBerry UEM versions earlier than 12.9.1 could allow an attacker to…

Fix: 12.9.1+
Fix from $1,600 2018-12-20
Unified Endpoint Manager HIGH 7.5
CVE-2018-8890

An information disclosure vulnerability in the Management Console of BlackBerry UEM 12.8.0 and 12.8.1 could allow an attacker to take over a UEM user…

Mitigation only
Fix from $1,950 2018-10-12
Unified Endpoint Manager MEDIUM 6.1
CVE-2017-17442

In BlackBerry UEM Management Console version 12.7.1 and earlier, a reflected cross-site scripting vulnerability that could allow an attacker to execu…

Fix: after 12.7.1
Fix from $1,600 2018-03-13
Qnx Software Development Platform CRITICAL 9.6
CVE-2017-3891

In BlackBerry QNX Software Development Platform (SDP) 6.6.0, an elevation of privilege vulnerability in the default configuration of the QNX SDP with…

Mitigation only
Fix from $2,300 2017-11-14
Workspaces Vapp CRITICAL 9.8
CVE-2017-9367

A directory traversal vulnerability in the BlackBerry Workspaces Server could potentially allow an attacker to execute or upload arbitrary files, or …

Fix: after 1.11.2
Fix from $2,300 2017-10-16
Workspaces Vapp HIGH 7.5
CVE-2017-9368

An information disclosure vulnerability in the BlackBerry Workspaces Server could result in an attacker gaining access to source code for server-side…

Fix: after 1.11.2
Fix from $1,950 2017-10-16
Workspaces HIGH 8.8
CVE-2017-9370

An information disclosure / elevation of privilege vulnerability in the BlackBerry Workspaces Server could potentially allow an attacker who has legi…

Mitigation only
Fix from $1,950 2017-08-09
Enterprise Service MEDIUM 6.1
CVE-2017-3894

A stored cross site scripting vulnerability in the Management Console of BlackBerry Unified Endpoint Manager version 12.6.1 and earlier, and all vers…

Fix: after 12.6.1
Fix from $1,600 2017-05-10
Blackberry Enterprise Service HIGH 8.8
CVE-2016-1914

Multiple SQL injection vulnerabilities in the com.rim.mdm.ui.server.ImageServlet servlet in BlackBerry Enterprise Server 12 (BES12) Self-Service befo…

Fix: after 12.3.1
Fix from $1,950 2017-04-13
Blackberry Enterprise Service MEDIUM 6.1
CVE-2016-1915

Multiple cross-site scripting (XSS) vulnerabilities in BlackBerry Enterprise Server 12 (BES12) Self-Service before 12.4 allow remote attackers to inj…

Fix: after 12.3.1
Fix from $1,600 2017-04-13
Good Control Server HIGH 7.5
CVE-2016-3127

An information disclosure vulnerability in the logging implementation of BlackBerry Good Control Server versions earlier than 2.3.53.62 allows remote…

Fix: after 2.2.511.26
Fix from $1,950 2017-03-03
Enterprise Service HIGH 8.2
CVE-2016-3128

A spoofing vulnerability in the Core of BlackBerry Enterprise Server (BES) 12 through 12.5.2 allows remote attackers to enroll an illegitimate device…

Mitigation only
Fix from $1,950 2017-01-13
Enterprise Service HIGH 8.1
CVE-2016-3130

An information disclosure vulnerability in the Core and Management Console in BlackBerry Enterprise Server (BES) 12 through 12.5.2 allows remote atta…

Mitigation only
Fix from $1,950 2017-01-13
Appliance X MEDIUM 6.1
CVE-2017-3890

A reflected cross-site scripting vulnerability in the BlackBerry WatchDox Server components Appliance-X, version 1.8.1 and earlier, and vAPP, version…

Fix: after 1.8.1
Fix from $1,600 2017-01-13
Good Enterprise Mobility Server MEDIUM 6.6
CVE-2016-3129

A remote shell execution vulnerability in the BlackBerry Good Enterprise Mobility Server (GEMS) implementation of the Apache Karaf command shell in G…

Fix: after 2.2.22.25
Fix from $1,600 2016-12-16
Enterprise Server MEDIUM 6.1
CVE-2016-3126

Cross-site scripting (XSS) vulnerability in the Management Console in BlackBerry Enterprise Server (BES) 12 before 12.4.1 allows remote attackers to …

Fix: after 12.4
Fix from $1,600 2016-04-22
Enterprise Server MEDIUM 6.1
CVE-2016-1918

Cross-site scripting (XSS) vulnerability in the Management Console in BlackBerry Enterprise Server (BES) 12 before 12.4.1 allows remote attackers to …

Fix: after 12.4
Fix from $1,600 2016-04-22
Enterprise Server MEDIUM 6.1
CVE-2016-1917

Cross-site scripting (XSS) vulnerability in the Management Console in BlackBerry Enterprise Server (BES) 12 before 12.4.1 allows remote attackers to …

Fix: after 12.4
Fix from $1,600 2016-04-22
Enterprise Server MEDIUM 5.4
CVE-2016-1916

Cross-site scripting (XSS) vulnerability in the Management Console in BlackBerry Enterprise Server (BES) 12 before 12.4.1 allows remote authenticated…

Fix: after 12.4
Fix from $1,600 2016-04-22
Blackberry Link MEDIUM 6.8
CVE-2015-4111

mc_demux_mp4_ds.ax in an unspecified third-party codec demux in BlackBerry Link before 1.2.3.53 with installer before 1.1.0.22 allows remote attacker…

Fix: after 1.2.3.52
Fix from $1,600 2015-07-20
Blackberry Os MEDIUM 6.1
CVE-2014-2388

The Storage and Access service in BlackBerry OS 10.x before 10.2.1.1925 on Q5, Q10, Z10, and Z30 devices does not enforce the password requirement fo…

Fix: after 10.1.0.2354
Fix from $1,600 2014-08-18
Blackberry Os HIGH 9.3
CVE-2014-2389EPSS 6%

Stack-based buffer overflow in a certain decryption function in qconnDoor on BlackBerry Z10 devices with software 10.1.0.2312, when developer-mode ha…

No fix yet
Fix from $1,950 2014-04-12
Qnx Neutrino Rtos HIGH 7.2
CVE-2014-2533

/sbin/ifwatchd in BlackBerry QNX Neutrino RTOS 6.4.x and 6.5.x allows local users to gain privileges by providing an arbitrary program name as a comm…

No fix yet
Fix from $1,950 2014-03-18
Blackberry Enterprise Service MEDIUM 5.0
CVE-2014-1467

BlackBerry Enterprise Service 10 before 10.2.1, Universal Device Service 6, Enterprise Server Express for Domino through 5.0.4, Enterprise Server Exp…

Fix: after 5.0.4
Fix from $1,600 2014-02-14
Blackberry Link MEDIUM 6.8
CVE-2013-3694

BlackBerry Link before 1.2.1.31 on Windows and before 1.1.1 build 39 on Mac OS X does not require authentication for remote file-access folders, whic…

Fix: after 1.2.0.28
Fix from $1,600 2013-11-18
Blackberry Link MEDIUM 5.8
CVE-2013-6798

BlackBerry Link before 1.2.1.31 on Windows and before 1.1.1 build 39 on Mac OS X does not properly determine the user account for execution of Peer M…

Fix: after 1.2.0.28
Fix from $1,600 2013-11-18
Blackberry Enterprise Service HIGH 7.9
CVE-2013-3693

The BlackBerry Universal Device Service in BlackBerry Enterprise Service (BES) 10.0 through 10.1.2 does not properly restrict access to the JBoss Rem…

Mitigation only
Fix from $1,950 2013-10-11
Blackberry Os MEDIUM 6.2
CVE-2013-3692

BlackBerry 10 OS before 10.0.10.648 on BlackBerry Z10 smartphones uses weak permissions for a BlackBerry Protect object, which allows physically prox…

Fix: after 10.0.10.261
Fix from $1,600 2013-07-13