BlackBerry

First CVE: Apr 22, 2016Active for: 10 years
62
CVEs Published
More CVEs Published than 63% of tracked CNAs
5.6
Avg CVEs / Year
More Avg CVEs / Year than 36% of tracked CNAs
7.0
Avg CVSS Score
Higher Avg CVSS Score than 45% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by BlackBerry as a CNA, 82.3% affect products that BlackBerry develops as a vendor.

82.3%
17.7%
Self-reported: 51Third-party: 11

Of all the CVEs published that affect products developed by BlackBerry, 58.0% are self-published by BlackBerry as a CNA.

58.0%
42.0%
Self-published: 51Published by other CNAs: 37

Trends Over Time

The number and severity of CVEs published by BlackBerry over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 22, 2016
10 years ago
Most Recent CVE
Jul 14, 2026
10 days ago

Top CVEs

All CVEs published by BlackBerry as a CNA, regardless of affected vendor or product.

62 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
An integer overflow vulnerability in the calloc() function of the C runtime library of affected versions of BlackBerry® QNX Software Development Platform (SDP) version(s) 6.5.0SP1
Aug 17, 20219.832NONO
Buffer Overflow in the entry handler of the TraceEvent() system call could allow an attacker with local access to cause information disclosure, data tampering or a crash of the QNX
Jul 14, 20267.430NONO
Out-of-bounds write in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause a denial-of-service condition or execute code in th
Jun 10, 20259.830NONO
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in OpenNebula OpenNebula core on Linux allows Remote Code Inclusion.
Oct 28, 20229.830NONO
A remote code execution vulnerability in the BMP image codec of BlackBerry QNX SDP version(s) 6.4 to 7.1 could allow an attacker to potentially execute code in the context of the a
Dec 13, 20219.830NONO
A directory traversal vulnerability in the BlackBerry Workspaces Server could potentially allow an attacker to execute or upload arbitrary files, or reveal the content of arbitrary
Oct 16, 20179.830NONO
An information disclosure vulnerability in the Core and Management Console in BlackBerry Enterprise Server (BES) 12 through 12.5.2 allows remote attackers to obtain local or domain
Jan 13, 20178.128NONO
A spoofing vulnerability in the Core of BlackBerry Enterprise Server (BES) 12 through 12.5.2 allows remote attackers to enroll an illegitimate device to the BES, gain access to dev
Jan 13, 20178.228NONO
TOCTOU Race Condition in specific trace commands of the TraceEvent() system call could allow an attacker with local access and with the PROCMGR_AID_TRACE ability, to cause informat
Jul 14, 20266.427NONO
Insufficient Parameter Validation in the SchedGet() system call could allow an attacker with local access to cause a crash of the QNX Neutrino kernel.
Jul 14, 20266.227NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA62 CVEs
Severity distribution among all CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local17 (27.4%)
Network44 (71.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (1.6%)
Attack Complexity
Low49 (79.0%)
High13 (21.0%)
Unknown0 (0.0%)
User Interaction
None50 (80.6%)
Unknown0 (0.0%)
Required12 (19.4%)
Privileges Required
Low16 (25.8%)
High9 (14.5%)
None37 (59.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (62 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by BlackBerry as a CNA.

Media Mentions

Media articles that mention a CVE ID published by BlackBerry as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs