{"api_version":"1","generated_at":"2026-07-23T21:41:04+00:00","cve":"CVE-2010-2604","urls":{"html":"https://cve.report/CVE-2010-2604","api":"https://cve.report/api/cve/CVE-2010-2604.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2010-2604","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2010-2604"},"summary":{"title":"CVE-2010-2604","description":"Multiple buffer overflows in the PDF Distiller in the BlackBerry Attachment Service component in Research In Motion (RIM) BlackBerry Enterprise Server 4.1.3 through 5.0.2, and Enterprise Server Express 5.0.1 and 5.0.2, allow remote attackers to execute arbitrary code via a crafted PDF file.","state":"PUBLISHED","assigner":"mitre","published_at":"2011-01-13 01:00:01","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-119","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"9.3","severity":"","vector":"AV:N/AC:M/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://secunia.com/advisories/42882","name":"http://secunia.com/advisories/42882","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"BlackBerry Enterprise Server PDF Distiller Buffer Overflow Vulnerability - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/45753","name":"http://www.securityfocus.com/bid/45753","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"BlackBerry Attachment Service PDF Distiller (CVE-2010-2604) Remote Buffer Overflow Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/64621","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/64621","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id?1024953","name":"http://www.securitytracker.com/id?1024953","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"BlackBerry Enterprise Server Buffer Overflow in Attachment Service PDF Distiller Lets Remote Users Execute Arbitrary Code - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2011/0081","name":"http://www.vupen.com/english/advisories/2011/0081","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/70393","name":"http://osvdb.org/70393","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.blackberry.com/btsc/KB25382","name":"http://www.blackberry.com/btsc/KB25382","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"KB25382-Vulnerability in the PDF distiller of the BlackBerry Attachment Service for the BlackBerry Enterprise Server","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2010-2604","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2010-2604","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2010","cve_id":"2604","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"rim","cpe5":"blackberry_enterprise_server","cpe6":"4.1.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"2604","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"rim","cpe5":"blackberry_enterprise_server","cpe6":"4.1.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"2604","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"rim","cpe5":"blackberry_enterprise_server","cpe6":"4.1.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"2604","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"rim","cpe5":"blackberry_enterprise_server","cpe6":"4.1.6","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"2604","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"rim","cpe5":"blackberry_enterprise_server","cpe6":"4.1.6","cpe7":"mr4","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"2604","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"rim","cpe5":"blackberry_enterprise_server","cpe6":"4.1.7","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"2604","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"rim","cpe5":"blackberry_enterprise_server","cpe6":"5.0.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"2604","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"rim","cpe5":"blackberry_enterprise_server","cpe6":"5.0.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"2604","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"rim","cpe5":"blackberry_enterprise_server","cpe6":"5.0.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"2604","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"rim","cpe5":"blackberry_enterprise_server_express","cpe6":"5.0.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"2604","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"rim","cpe5":"blackberry_enterprise_server_express","cpe6":"5.0.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T02:39:37.701Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"ADV-2011-0081","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2011/0081"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.blackberry.com/btsc/KB25382"},{"name":"blackberry-pdf-distiller-bo(64621)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/64621"},{"name":"42882","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/42882"},{"name":"1024953","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1024953"},{"name":"45753","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/45753"},{"name":"70393","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/70393"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2011-01-11T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple buffer overflows in the PDF Distiller in the BlackBerry Attachment Service component in Research In Motion (RIM) BlackBerry Enterprise Server 4.1.3 through 5.0.2, and Enterprise Server Express 5.0.1 and 5.0.2, allow remote attackers to execute arbitrary code via a crafted PDF file."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-16T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"ADV-2011-0081","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2011/0081"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.blackberry.com/btsc/KB25382"},{"name":"blackberry-pdf-distiller-bo(64621)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/64621"},{"name":"42882","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/42882"},{"name":"1024953","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1024953"},{"name":"45753","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/45753"},{"name":"70393","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/70393"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2010-2604","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple buffer overflows in the PDF Distiller in the BlackBerry Attachment Service component in Research In Motion (RIM) BlackBerry Enterprise Server 4.1.3 through 5.0.2, and Enterprise Server Express 5.0.1 and 5.0.2, allow remote attackers to execute arbitrary code via a crafted PDF file."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"ADV-2011-0081","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2011/0081"},{"name":"http://www.blackberry.com/btsc/KB25382","refsource":"CONFIRM","url":"http://www.blackberry.com/btsc/KB25382"},{"name":"blackberry-pdf-distiller-bo(64621)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/64621"},{"name":"42882","refsource":"SECUNIA","url":"http://secunia.com/advisories/42882"},{"name":"1024953","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1024953"},{"name":"45753","refsource":"BID","url":"http://www.securityfocus.com/bid/45753"},{"name":"70393","refsource":"OSVDB","url":"http://osvdb.org/70393"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2010-2604","datePublished":"2011-01-12T23:00:00.000Z","dateReserved":"2010-07-01T00:00:00.000Z","dateUpdated":"2024-08-07T02:39:37.701Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2011-01-13 01:00:01","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-119","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":8.6,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:rim:blackberry_enterprise_server:4.1.3:*:*:*:*:*:*:*","matchCriteriaId":"E4BD344A-EE9C-4ECB-8CB1-35146FD6F056"},{"vulnerable":true,"criteria":"cpe:2.3:a:rim:blackberry_enterprise_server:4.1.4:*:*:*:*:*:*:*","matchCriteriaId":"B1694E42-9AA5-4503-9714-CBDE388481A5"},{"vulnerable":true,"criteria":"cpe:2.3:a:rim:blackberry_enterprise_server:4.1.5:*:*:*:*:*:*:*","matchCriteriaId":"16F378AF-E25B-4D60-AF7E-9E6FB228BF1B"},{"vulnerable":true,"criteria":"cpe:2.3:a:rim:blackberry_enterprise_server:4.1.6:*:*:*:*:*:*:*","matchCriteriaId":"265D8F90-96C3-4627-ABA5-994C25F70A45"},{"vulnerable":true,"criteria":"cpe:2.3:a:rim:blackberry_enterprise_server:4.1.6:mr4:*:*:*:*:*:*","matchCriteriaId":"F5A7A6BD-C0D7-40E0-BE1A-EC4396853296"},{"vulnerable":true,"criteria":"cpe:2.3:a:rim:blackberry_enterprise_server:4.1.7:*:*:*:*:*:*:*","matchCriteriaId":"3E00E895-AEEC-406B-9DC2-D01916BB1CCE"},{"vulnerable":true,"criteria":"cpe:2.3:a:rim:blackberry_enterprise_server:5.0.0:*:*:*:*:*:*:*","matchCriteriaId":"7EBA5181-F946-4F86-B5DB-07795ACF32D9"},{"vulnerable":true,"criteria":"cpe:2.3:a:rim:blackberry_enterprise_server:5.0.1:*:*:*:*:*:*:*","matchCriteriaId":"85752BAD-8110-41B4-BAEF-4C97BFDA046A"},{"vulnerable":true,"criteria":"cpe:2.3:a:rim:blackberry_enterprise_server:5.0.2:*:*:*:*:*:*:*","matchCriteriaId":"377D4536-5EAC-4F0A-94AD-4D326935A142"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:rim:blackberry_enterprise_server_express:5.0.1:*:*:*:*:*:*:*","matchCriteriaId":"079D4AE1-AA56-4169-8073-E665452A0BF1"},{"vulnerable":true,"criteria":"cpe:2.3:a:rim:blackberry_enterprise_server_express:5.0.2:*:*:*:*:*:*:*","matchCriteriaId":"4D861AF4-F293-40D9-BFA9-1EECBDFA8253"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2010","CveId":"2604","Ordinal":"1","Title":"CVE-2010-2604","CVE":"CVE-2010-2604","Year":"2010"},"notes":[{"CveYear":"2010","CveId":"2604","Ordinal":"1","NoteData":"Multiple buffer overflows in the PDF Distiller in the BlackBerry Attachment Service component in Research In Motion (RIM) BlackBerry Enterprise Server 4.1.3 through 5.0.2, and Enterprise Server Express 5.0.1 and 5.0.2, allow remote attackers to execute arbitrary code via a crafted PDF file.","Type":"Description","Title":"CVE-2010-2604"},{"CveYear":"2010","CveId":"2604","Ordinal":"2","NoteData":"2011-01-12","Type":"Other","Title":"Published"},{"CveYear":"2010","CveId":"2604","Ordinal":"3","NoteData":"2017-08-16","Type":"Other","Title":"Modified"}]}}}