CVE-2009-0306

high

Description

Buffer overflow in the IBM Lotus Notes Intellisync ActiveX control in lnresobject.dll in BlackBerry Desktop Manager in Research In Motion (RIM) BlackBerry Desktop Software before 5.0.1 allows remote attackers to execute arbitrary code via a crafted web page. NOTE: some of these details are obtained from third party information.

References

http://www.vupen.com/english/advisories/2009/3133

http://www.securityfocus.com/bid/36903

http://www.blackberry.com/btsc/search.do?cmd=displayKC&docType=kc&externalId=KB19701

Details

Source: Mitre, NVD

Published: 2009-11-04

Updated: 2009-11-12

Risk Information

CVSS v2

Base Score: 9.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Severity: High