{"api_version":"1","generated_at":"2026-07-23T07:46:16+00:00","cve":"CVE-2009-0176","urls":{"html":"https://cve.report/CVE-2009-0176","api":"https://cve.report/api/cve/CVE-2009-0176.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2009-0176","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2009-0176"},"summary":{"title":"CVE-2009-0176","description":"Multiple heap-based buffer overflows in the PDF distiller in the Attachment Service in Research in Motion (RIM) BlackBerry Enterprise Server (BES) 4.1.3 through 4.1.6, BlackBerry Professional Software 4.1.4, and BlackBerry Unite! before 1.0.3 bundle 28 allow user-assisted remote attackers to execute arbitrary code via (1) a crafted stream in a .pdf file, related to \"symWidths\"; or (2) a crafted data stream in a .pdf file, related to \"bitmaps.\"","state":"PUBLISHED","assigner":"mitre","published_at":"2009-01-20 16:00:09","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-119","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"9.3","severity":"","vector":"AV:N/AC:M/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=765","name":"http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=765","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Public Advisory: 01.13.09 // iDefense Labs","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://secunia.com/advisories/33534","name":"http://secunia.com/advisories/33534","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"BlackBerry Products PDF Distiller Multiple Vulnerabilities - Secunia Advisories - Vulnerability Information - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.blackberry.com/btsc/search.do?cmd=displayKC&docType=kc&externalId=KB17118","name":"http://www.blackberry.com/btsc/search.do?cmd=displayKC&docType=kc&externalId=KB17118","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"View Document","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.blackberry.com/btsc/search.do?cmd=displayKC&docType=kc&externalId=KB17119","name":"http://www.blackberry.com/btsc/search.do?cmd=displayKC&docType=kc&externalId=KB17119","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"View Document","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/33224","name":"http://www.securityfocus.com/bid/33224","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"BlackBerry Attachment Service PDF Distiller Remote Buffer Overflow Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=764","name":"http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=764","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Public Advisory: 01.13.09 // iDefense Labs","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2009-0176","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2009-0176","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2009","cve_id":"176","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"research_in_motion_limited","cpe5":"blackberry_enterprise_server","cpe6":"4.1.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"176","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"research_in_motion_limited","cpe5":"blackberry_enterprise_server","cpe6":"4.1.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"176","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"research_in_motion_limited","cpe5":"blackberry_enterprise_server","cpe6":"4.1.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"176","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"research_in_motion_limited","cpe5":"blackberry_enterprise_server","cpe6":"4.1.6","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"176","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"research_in_motion_limited","cpe5":"blackberry_professional_software","cpe6":"4.1.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"176","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"research_in_motion_limited","cpe5":"blackberry_unite","cpe6":"1.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"176","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"research_in_motion_limited","cpe5":"blackberry_unite","cpe6":"1.0.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"176","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"research_in_motion_limited","cpe5":"blackberry_unite","cpe6":"1.0.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"176","vulnerable":"1","versionEndIncluding":"1.0.3","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"research_in_motion_limited","cpe5":"blackberry_unite","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T04:24:18.067Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.blackberry.com/btsc/search.do?cmd=displayKC&docType=kc&externalId=KB17118"},{"name":"33224","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/33224"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.blackberry.com/btsc/search.do?cmd=displayKC&docType=kc&externalId=KB17119"},{"name":"20090113 RIM BlackBerry Enterprise Server Attachment Service PDF Distiller 'bitmaps' Heap Overflow Vulnerability","tags":["third-party-advisory","x_refsource_IDEFENSE","x_transferred"],"url":"http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=765"},{"name":"20090113 RIM BlackBerry Enterprise Server Attachment Service PDF Distiller 'symWidths' Heap Overflow Vulnerability","tags":["third-party-advisory","x_refsource_IDEFENSE","x_transferred"],"url":"http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=764"},{"name":"33534","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/33534"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"descriptions":[{"lang":"en","value":"Multiple heap-based buffer overflows in the PDF distiller in the Attachment Service in Research in Motion (RIM) BlackBerry Enterprise Server (BES) 4.1.3 through 4.1.6, BlackBerry Professional Software 4.1.4, and BlackBerry Unite! before 1.0.3 bundle 28 allow user-assisted remote attackers to execute arbitrary code via (1) a crafted stream in a .pdf file, related to \"symWidths\"; or (2) a crafted data stream in a .pdf file, related to \"bitmaps.\""}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2009-01-20T15:26:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"http://www.blackberry.com/btsc/search.do?cmd=displayKC&docType=kc&externalId=KB17118"},{"name":"33224","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/33224"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.blackberry.com/btsc/search.do?cmd=displayKC&docType=kc&externalId=KB17119"},{"name":"20090113 RIM BlackBerry Enterprise Server Attachment Service PDF Distiller 'bitmaps' Heap Overflow Vulnerability","tags":["third-party-advisory","x_refsource_IDEFENSE"],"url":"http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=765"},{"name":"20090113 RIM BlackBerry Enterprise Server Attachment Service PDF Distiller 'symWidths' Heap Overflow Vulnerability","tags":["third-party-advisory","x_refsource_IDEFENSE"],"url":"http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=764"},{"name":"33534","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/33534"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2009-0176","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple heap-based buffer overflows in the PDF distiller in the Attachment Service in Research in Motion (RIM) BlackBerry Enterprise Server (BES) 4.1.3 through 4.1.6, BlackBerry Professional Software 4.1.4, and BlackBerry Unite! before 1.0.3 bundle 28 allow user-assisted remote attackers to execute arbitrary code via (1) a crafted stream in a .pdf file, related to \"symWidths\"; or (2) a crafted data stream in a .pdf file, related to \"bitmaps.\""}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://www.blackberry.com/btsc/search.do?cmd=displayKC&docType=kc&externalId=KB17118","refsource":"CONFIRM","url":"http://www.blackberry.com/btsc/search.do?cmd=displayKC&docType=kc&externalId=KB17118"},{"name":"33224","refsource":"BID","url":"http://www.securityfocus.com/bid/33224"},{"name":"http://www.blackberry.com/btsc/search.do?cmd=displayKC&docType=kc&externalId=KB17119","refsource":"CONFIRM","url":"http://www.blackberry.com/btsc/search.do?cmd=displayKC&docType=kc&externalId=KB17119"},{"name":"20090113 RIM BlackBerry Enterprise Server Attachment Service PDF Distiller 'bitmaps' Heap Overflow Vulnerability","refsource":"IDEFENSE","url":"http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=765"},{"name":"20090113 RIM BlackBerry Enterprise Server Attachment Service PDF Distiller 'symWidths' Heap Overflow Vulnerability","refsource":"IDEFENSE","url":"http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=764"},{"name":"33534","refsource":"SECUNIA","url":"http://secunia.com/advisories/33534"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2009-0176","datePublished":"2009-01-20T15:26:00.000Z","dateReserved":"2009-01-20T00:00:00.000Z","dateUpdated":"2024-09-17T02:31:04.504Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2009-01-20 16:00:09","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-119","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":8.6,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:research_in_motion_limited:blackberry_enterprise_server:4.1.3:*:*:*:*:*:*:*","matchCriteriaId":"4DDE9EAC-D9FF-47C2-A830-0316F74D822E"},{"vulnerable":true,"criteria":"cpe:2.3:a:research_in_motion_limited:blackberry_enterprise_server:4.1.4:*:*:*:*:*:*:*","matchCriteriaId":"F3B71789-C43D-4D75-9C49-71D9347EF321"},{"vulnerable":true,"criteria":"cpe:2.3:a:research_in_motion_limited:blackberry_enterprise_server:4.1.5:*:*:*:*:*:*:*","matchCriteriaId":"59C67945-B4C6-4159-8FF0-05227D46E282"},{"vulnerable":true,"criteria":"cpe:2.3:a:research_in_motion_limited:blackberry_enterprise_server:4.1.6:*:*:*:*:*:*:*","matchCriteriaId":"D2FE657D-6988-4A19-B0EC-8D9413AB7A5E"},{"vulnerable":true,"criteria":"cpe:2.3:a:research_in_motion_limited:blackberry_professional_software:4.1.4:*:*:*:*:*:*:*","matchCriteriaId":"4E3AB6DC-0733-4683-B495-2FF85923ACB8"},{"vulnerable":true,"criteria":"cpe:2.3:a:research_in_motion_limited:blackberry_unite:*:*:*:*:*:*:*:*","versionEndIncluding":"1.0.3","matchCriteriaId":"9DC011EA-0F76-4554-B19D-3B93F7C1D774"},{"vulnerable":true,"criteria":"cpe:2.3:a:research_in_motion_limited:blackberry_unite:1.0:*:*:*:*:*:*:*","matchCriteriaId":"3D4FFD7E-241B-458A-AB88-C4C06E47C017"},{"vulnerable":true,"criteria":"cpe:2.3:a:research_in_motion_limited:blackberry_unite:1.0.1:*:*:*:*:*:*:*","matchCriteriaId":"3C6120B4-CEE1-412B-9EE3-9F2B0BE690A1"},{"vulnerable":true,"criteria":"cpe:2.3:a:research_in_motion_limited:blackberry_unite:1.0.2:*:*:*:*:*:*:*","matchCriteriaId":"5A748FD0-2FED-4C8F-9693-ED16095E917A"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2009","CveId":"176","Ordinal":"1","Title":"CVE-2009-0176","CVE":"CVE-2009-0176","Year":"2009"},"notes":[{"CveYear":"2009","CveId":"176","Ordinal":"1","NoteData":"Multiple heap-based buffer overflows in the PDF distiller in the Attachment Service in Research in Motion (RIM) BlackBerry Enterprise Server (BES) 4.1.3 through 4.1.6, BlackBerry Professional Software 4.1.4, and BlackBerry Unite! before 1.0.3 bundle 28 allow user-assisted remote attackers to execute arbitrary code via (1) a crafted stream in a .pdf file, related to \"symWidths\"; or (2) a crafted data stream in a .pdf file, related to \"bitmaps.\"","Type":"Description","Title":"CVE-2009-0176"},{"CveYear":"2009","CveId":"176","Ordinal":"2","NoteData":"2009-01-20","Type":"Other","Title":"Published"}]}}}