Vulnerabilities > RIM > Blackberry Enterprise Server > 4.0.3

DATE CVE VULNERABILITY TITLE RISK
2010-10-14 CVE-2010-2601 Buffer Errors vulnerability in RIM products
Multiple buffer overflows in the PDF distiller in the Attachment Service component in Research In Motion (RIM) BlackBerry Enterprise Server (BES) software 4.1.7 and earlier and 5.0.0 through 5.0.2, and BlackBerry Professional Software 4.1.4 and earlier, allow user-assisted remote attackers to cause a denial of service or possibly execute arbitrary code via a crafted PDF document.
network
high complexity
rim CWE-119
7.6
2009-04-22 CVE-2009-0307 Cross-Site Scripting vulnerability in RIM Blackberry Enterprise Server
Cross-site scripting (XSS) vulnerability in the "Customize Statistics Page" (admin/statistics/ConfigureStatistics) in the MDS Connection Service in Research in Motion (RIM) BlackBerry Enterprise Server (BES) before 4.1.6 MR5 allows remote attackers to inject arbitrary web script or HTML via the (1) customDate, (2) interval, (3) lastCustomInterval, (4) lastIntervalLength, (5) nextCustomInterval, (6) nextIntervalLength, (7) action, (8) delIntervalIndex, (9) addStatIndex, (10) delStatIndex, and (11) referenceTime parameters.
network
rim CWE-79
4.3