Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2010-2600

Опубликовано: 15 сент. 2010
Источник: nvd
CVSS2: 9.3
EPSS Низкий

Описание

Untrusted search path vulnerability in BlackBerry Desktop Software before 6.0.0.47 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse DLL that is located in the same folder as a file that is processed by Blackberry.

Комментарий

Per: http://cwe.mitre.org/data/definitions/426.html

'CWE-426: Untrusted Search Path'

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:rim:blackberry_desktop_software:*:*:*:*:*:*:*:*
Версия до 6.0 (включая)
cpe:2.3:a:rim:blackberry_desktop_software:3.0:*:*:*:*:*:*:*
cpe:2.3:a:rim:blackberry_desktop_software:4.0:*:*:*:*:*:*:*
cpe:2.3:a:rim:blackberry_desktop_software:4.5:*:*:*:*:*:*:*
cpe:2.3:a:rim:blackberry_desktop_software:4.6:*:*:*:*:*:*:*
cpe:2.3:a:rim:blackberry_desktop_software:4.7:*:*:*:*:*:*:*
cpe:2.3:a:rim:blackberry_desktop_software:5.0:*:*:*:*:*:*:*
cpe:2.3:a:rim:blackberry_desktop_software:5.0.1:*:*:*:*:*:*:*

EPSS

Процентиль: 87%
0.03135
Низкий

9.3 Critical

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

github
больше 3 лет назад

Untrusted search path vulnerability in BlackBerry Desktop Software before 6.0.0.47 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse DLL that is located in the same folder as a file that is processed by Blackberry.

EPSS

Процентиль: 87%
0.03135
Низкий

9.3 Critical

CVSS2

Дефекты

NVD-CWE-Other