CVE-2010-2604
Estado: ModificadaAlta (9.3)—
Multiple buffer overflows in the PDF Distiller in the BlackBerry Attachment Service component in Research In Motion (RIM) BlackBerry Enterprise Server 4.1.3 through 5.0.2, and Enterprise Server Express 5.0.1 and 5.0.2, allow remote attackers to execute arbitrary code via a crafted PDF file.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C
- Puntuación base: 9.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 5.72%
- Percentil entre todas las CVEs puntuadas: 93
- Fecha de la puntuación: 4/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- CWE-119
Referencias
- http://osvdb.org/70393
- http://secunia.com/advisories/42882
- http://www.blackberry.com/btsc/KB25382
- http://www.securityfocus.com/bid/45753
- http://www.securitytracker.com/id?1024953
- http://www.vupen.com/english/advisories/2011/0081
- https://exchange.xforce.ibmcloud.com/vulnerabilities/64621
- http://osvdb.org/70393
- http://secunia.com/advisories/42882
- http://www.blackberry.com/btsc/KB25382
- http://www.securityfocus.com/bid/45753
- http://www.securitytracker.com/id?1024953
- http://www.vupen.com/english/advisories/2011/0081
- https://exchange.xforce.ibmcloud.com/vulnerabilities/64621
JSON original (NVD)
Mostrar
{
"id": "CVE-2010-2604",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 9.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "MEDIUM",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2011-01-13T01:00:01.553",
"references": [
{
"url": "http://osvdb.org/70393",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/42882",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.blackberry.com/btsc/KB25382",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/45753",
"source": "cve@mitre.org"
},
{
"url": "http://www.securitytracker.com/id?1024953",
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2011/0081",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/64621",
"source": "cve@mitre.org"
},
{
"url": "http://osvdb.org/70393",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/42882",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.blackberry.com/btsc/KB25382",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/45753",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securitytracker.com/id?1024953",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2011/0081",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/64621",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-119"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Multiple buffer overflows in the PDF Distiller in the BlackBerry Attachment Service component in Research In Motion (RIM) BlackBerry Enterprise Server 4.1.3 through 5.0.2, and Enterprise Server Express 5.0.1 and 5.0.2, allow remote attackers to execute arbitrary code via a crafted PDF file."
},
{
"lang": "es",
"value": "Múltiples desbordamientos de búfer en PDF Distiller en el componente de BlackBerry Attachment Service de Research In Motion (RIM) BlackBerry Enterprise Server v4.1.3 hasta v5.0.2, y Enterprise Server Express v5.0.1 y v5.0.2, permite a atacantes remotos ejecutar código de su elección a través de un archivo PDF manipulado."
}
],
"lastModified": "2026-06-16T23:21:04.110",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:rim:blackberry_enterprise_server:4.1.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E4BD344A-EE9C-4ECB-8CB1-35146FD6F056"
},
{
"criteria": "cpe:2.3:a:rim:blackberry_enterprise_server:4.1.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B1694E42-9AA5-4503-9714-CBDE388481A5"
},
{
"criteria": "cpe:2.3:a:rim:blackberry_enterprise_server:4.1.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "16F378AF-E25B-4D60-AF7E-9E6FB228BF1B"
},
{
"criteria": "cpe:2.3:a:rim:blackberry_enterprise_server:4.1.6:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "265D8F90-96C3-4627-ABA5-994C25F70A45"
},
{
"criteria": "cpe:2.3:a:rim:blackberry_enterprise_server:4.1.6:mr4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F5A7A6BD-C0D7-40E0-BE1A-EC4396853296"
},
{
"criteria": "cpe:2.3:a:rim:blackberry_enterprise_server:4.1.7:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3E00E895-AEEC-406B-9DC2-D01916BB1CCE"
},
{
"criteria": "cpe:2.3:a:rim:blackberry_enterprise_server:5.0.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7EBA5181-F946-4F86-B5DB-07795ACF32D9"
},
{
"criteria": "cpe:2.3:a:rim:blackberry_enterprise_server:5.0.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "85752BAD-8110-41B4-BAEF-4C97BFDA046A"
},
{
"criteria": "cpe:2.3:a:rim:blackberry_enterprise_server:5.0.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "377D4536-5EAC-4F0A-94AD-4D326935A142"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:rim:blackberry_enterprise_server_express:5.0.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "079D4AE1-AA56-4169-8073-E665452A0BF1"
},
{
"criteria": "cpe:2.3:a:rim:blackberry_enterprise_server_express:5.0.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4D861AF4-F293-40D9-BFA9-1EECBDFA8253"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}