4.3

CVE-2014-6611

The BlackBerry World app before 5.0.0.262 on BlackBerry 10 OS 10.2.0, before 5.0.0.263 on BlackBerry 10 OS 10.2.1, and before 5.1.0.53 on BlackBerry 10 OS 10.3.0 does not properly validate download/update requests, which allows user-assisted man-in-the-middle attackers to spoof servers and trigger the download of a crafted app by modifying the client-server data stream.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Blackberry ≫ Blackberry World Version <= 5.1.0.52
Blackberry ≫ Blackberry Os Version 10.3.0
Blackberry ≫ Blackberry World Version <= 5.0.0.262
Blackberry ≫ Blackberry Os Version 10.2.1
Blackberry ≫ Blackberry World Version <= 5.0.0.261
Blackberry ≫ Blackberry Os Version 10.2.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.99% 0.579
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://secunia.com/advisories/61013
http://www.blackberry.com/btsc/kb36360
Vendor Advisory