RIM's vulnerability footprint concentrates in its BlackBerry enterprise ecosystem, including server infrastructure, desktop software, and device firmware that served mobile workforce deployment across large organizations. The vendor's disclosure history spans a modest but persistent volume, with a small product portfolio reflecting the focused scope of its platform. The recurring weakness classes center on memory-safety issues, input validation flaws, cross-site scripting in web-facing components, and information exposure, patterns typical of complex enterprise software managing authentication and data synchronization. Vulnerabilities affecting this vendor show a moderate tendency to acquire public exploit code. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Rim over time
Signals from CVEs in this vendor scope (36 CVEs).
36 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-1290HIGH Integer overflow in WebKit, as used on the Research In Motion (RIM) BlackBerry Torch 9800 with firmware 6.0.0.246, in Google Chrome before 10.0.648.133, and in Apple Safari before | Mar 11, 2011 | 10.0 | 34 | NO | NO |
CVE-2012-0870HIGH Heap-based buffer overflow in process.c in smbd in Samba 3.0, as used in the file-sharing service on the BlackBerry PlayBook tablet before 2.0.0.7971 and other products, allows rem | Feb 23, 2012 | 7.9 | 29 | NO | NO |
CVE-2010-2604HIGH Multiple buffer overflows in the PDF Distiller in the BlackBerry Attachment Service component in Research In Motion (RIM) BlackBerry Enterprise Server 4.1.3 through 5.0.2, and Ente | Jan 13, 2011 | 9.3 | 29 | NO | NO |
CVE-2010-2600HIGH Untrusted search path vulnerability in BlackBerry Desktop Software before 6.0.0.47 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hija | Sep 15, 2010 | 9.3 | 27 | NO | NO |
CVE-2009-2643HIGH Multiple unspecified vulnerabilities in the PDF distiller in the Attachment Service component in Research In Motion (RIM) BlackBerry Enterprise Server (BES) software 4.1.3 through | Jul 28, 2009 | 9.3 | 27 | NO | NO |
CVE-2008-3246HIGH Unspecified vulnerability in the PDF distiller component in the BlackBerry Attachment Service in BlackBerry Unite! 1.0 SP1 (1.0.1) before bundle 36 and BlackBerry Enterprise Server | Jul 21, 2008 | 9.3 | 25 | NO | NO |
CVE-2007-3483HIGH Research in Motion BlackBerry Enterprise Server 4.0 through 4.1 has a default configuration that permits installation of arbitrary third-party applications on BlackBerry devices, w | Jun 28, 2007 | 10.0 | 25 | NO | NO |
CVE-2009-4778HIGH Multiple unspecified vulnerabilities in the PDF distiller in the Attachment Service component in Research In Motion (RIM) BlackBerry Enterprise Server (BES) software 4.1.3 through | Apr 21, 2010 | 9.3 | 24 | NO | NO |
CVE-2009-0306HIGH Buffer overflow in the IBM Lotus Notes Intellisync ActiveX control in lnresobject.dll in BlackBerry Desktop Manager in Research In Motion (RIM) BlackBerry Desktop Software before 5 | Nov 4, 2009 | 9.3 | 24 | NO | NO |
CVE-2009-2646HIGH Multiple unspecified vulnerabilities in the PDF distiller in the Attachment Service component in Research In Motion (RIM) BlackBerry Enterprise Server (BES) software 4.1.3 through | Jul 30, 2009 | 9.3 | 24 | NO | NO |
Signals from CVEs in this vendor scope (36 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Rim.
Media articles that mention a CVE ID that affects a product developed by Rim — matched by CVE ID, not by vendor name.