BlackBerry
First CVE: Apr 22, 2016Active for: 10 years
62
CVEs Published
More CVEs Published than 63% of tracked CNAs
5.6
Avg CVEs / Year
More Avg CVEs / Year than 36% of tracked CNAs
7.0
Avg CVSS Score
Higher Avg CVSS Score than 45% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Self-Reporting Analysis
Of all the CVEs published by BlackBerry as a CNA, 82.3% affect products that BlackBerry develops as a vendor.
82.3%
17.7%
Self-reported: 51Third-party: 11
Of all the CVEs published that affect products developed by BlackBerry, 58.0% are self-published by BlackBerry as a CNA.
58.0%
42.0%
Self-published: 51Published by other CNAs: 37
Trends Over Time
The number and severity of CVEs published by BlackBerry over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 22, 2016
10 years ago
Most Recent CVE
Jul 14, 2026
10 days ago
Top CVEs
All CVEs published by BlackBerry as a CNA, regardless of affected vendor or product.
62 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-22156CRITICAL An integer overflow vulnerability in the calloc() function of the C runtime library of affected versions of BlackBerry® QNX Software Development Platform (SDP) version(s) 6.5.0SP1 | Aug 17, 2021 | 9.8 | 32 | NO | NO |
CVE-2026-4017HIGH Buffer Overflow in the entry handler of the TraceEvent() system call could allow an attacker with local access to cause information disclosure, data tampering or a crash of the QNX | Jul 14, 2026 | 7.4 | 30 | NO | NO |
CVE-2025-2474CRITICAL Out-of-bounds write in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause a denial-of-service condition or execute code in th | Jun 10, 2025 | 9.8 | 30 | NO | NO |
CVE-2022-37425CRITICAL Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in OpenNebula OpenNebula core on Linux allows Remote Code Inclusion. | Oct 28, 2022 | 9.8 | 30 | NO | NO |
CVE-2021-32024CRITICAL A remote code execution vulnerability in the BMP image codec of BlackBerry QNX SDP version(s) 6.4 to 7.1 could allow an attacker to potentially execute code in the context of the a | Dec 13, 2021 | 9.8 | 30 | NO | NO |
CVE-2017-9367CRITICAL A directory traversal vulnerability in the BlackBerry Workspaces Server could potentially allow an attacker to execute or upload arbitrary files, or reveal the content of arbitrary | Oct 16, 2017 | 9.8 | 30 | NO | NO |
CVE-2016-3130HIGH An information disclosure vulnerability in the Core and Management Console in BlackBerry Enterprise Server (BES) 12 through 12.5.2 allows remote attackers to obtain local or domain | Jan 13, 2017 | 8.1 | 28 | NO | NO |
CVE-2016-3128HIGH A spoofing vulnerability in the Core of BlackBerry Enterprise Server (BES) 12 through 12.5.2 allows remote attackers to enroll an illegitimate device to the BES, gain access to dev | Jan 13, 2017 | 8.2 | 28 | NO | NO |
CVE-2026-4018MEDIUM TOCTOU Race Condition in specific trace commands of the TraceEvent() system call could allow an attacker with local access and with the PROCMGR_AID_TRACE ability, to cause informat | Jul 14, 2026 | 6.4 | 27 | NO | NO |
CVE-2026-0515MEDIUM Insufficient Parameter Validation in the SchedGet() system call could allow an attacker with local access to cause a crash of the QNX Neutrino kernel. | Jul 14, 2026 | 6.2 | 27 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA62 CVEs
45%
42%
13%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local17 (27.4%)
Network44 (71.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (1.6%)
Attack Complexity
Low49 (79.0%)
High13 (21.0%)
Unknown0 (0.0%)
User Interaction
None50 (80.6%)
Unknown0 (0.0%)
Required12 (19.4%)
Privileges Required
Low16 (25.8%)
High9 (14.5%)
None37 (59.7%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (62 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by BlackBerry as a CNA.
Media Mentions
Media articles that mention a CVE ID published by BlackBerry as a CNA — matched by CVE ID, not by organization name.