Skip to main content

Vendor archive

qnx CVEs

Beta · best-effort

32 CVEs tagged to vendor qnx2 Critical, 10 High, 13 Medium, 7 Low, 0 Unrated.

CVE-2011-4060

Published Oct 18, 2011

The runtime linker in QNX Neutrino RTOS 6.5.0 before Service Pack 1 does not properly clear the LD_DEBUG_OUTPUT and LD_DEBUG environment variables when a program is spawned from a…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-0618

Published Feb 9, 2006

Format string vulnerability in fontsleuth in QNX Neutrino RTOS 6.3.0 allows local users to execute arbitrary code via format string specifiers in the zeroth argument (program name…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0619

Published Feb 9, 2006

Multiple stack-based buffer overflows in QNX Neutrino RTOS 6.3.0 allow local users to execute arbitrary code via long (1) ABLPATH or (2) ABLANG environment variables in the libAP…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0620

Published Feb 9, 2006

Race condition in phfont in QNX Neutrino RTOS 6.2.1 allows local users to execute arbitrary code via unspecified manipulations of the PHFONT and PHOTON2_PATH environment variables.

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0621

Published Feb 9, 2006

Multiple buffer overflows in QNX Neutrino RTOS 6.2.0 allow local users to execute arbitrary code via a long first argument to the (1) su or (2) passwd commands.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2006-0622

Published Feb 9, 2006

QNX Neutrino RTOS 6.3.0 allows local users to cause a denial of service (hang) by supplying a "break *0xb032d59f" command to gdb.

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0623

Published Feb 9, 2006

QNX Neutrino RTOS 6.3.0 ships /etc/rc.d/rc.local with world-writable permissions, which allows local users to modify the file and execute arbitrary code at system startup.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2005-1528

Published Dec 31, 2005

Untrusted search path vulnerability in the crttrap command in QNX Neutrino RTOS 6.2.1 allows local users to load arbitrary libraries via a LD_LIBRARY_PATH environment variable tha…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4082

Published Dec 8, 2005

The dhcp.client program for QNX 4.25 vmware is setuid, possibly by default, which allows local users to modify the NIC configuration and conduct other attacks.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-3928

Published Nov 30, 2005

Buffer overflow in phgrafx in QNX 6.2.1 and 6.3.0 allows local users to execute arbitrary code via a long command line argument.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-2725

Published Aug 30, 2005

The inputtrap utility in QNX RTOS 6.1.0, 6.3, and possibly earlier versions does not properly check permissions when the -t flag is specified, which allows local users to read arb…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2004-1390

Published Dec 31, 2004

Multiple buffer overflows in the PPPoE daemon (PPPoEd) in QNX RTP 6.1 allow remote attackers to execute arbitrary code via a long argument to the (1) -F, (2) name, (3) en, (4) ups…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2004-1391

Published Dec 31, 2004

Untrusted execution path vulnerability in the PPPoE daemon (PPPoEd) in QNX RTP 6.1 allows local users to execute arbitrary programs by modifying the PATH environment variable to p…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1683

Published Sep 13, 2004

A race condition in crrtrap for QNX RTP 6.1 allows local users to gain privileges by modifying the PATH environment variable to reference a malicious io-graphics program before is…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2004-1681

Published Aug 26, 2004

Multiple buffer overflows in (1) phrelay-cfg, (2) phlocale, (3) pkg-installer, or (4) input-cfg in QNX Photon microGUI for QNX RTP 6.1 allow local users to gain privileges via a l…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2004-1682

Published Aug 15, 2004

Format string vulnerability in QNX 6.1 FTP client allows remote authenticated users to gain group bin privileges via format string specifiers in the QUOTE command.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2002-1633

Published Dec 31, 2002

Multiple buffer overflows in QNX 4.25 may allow local users to execute arbitrary code via long command line arguments to (1) sample, (2) ex, (3) du, (4) find, (5) lex, (6) mkdir,…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-1983

Published Dec 31, 2002

The timer implementation in QNX RTOS 6.1.0 allows local users to cause a denial of service (hang) and possibly execute arbitrary code by creating multiple timers with a 1-ms tick.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2002-2039

Published Dec 31, 2002

/bin/su in QNX realtime operating system (RTOS) 4.25 and 6.1.0 allows local users to obtain sensitive information from core dump files by sending the SIGSERV (invalid memory refer…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2002-2040

Published Dec 31, 2002

The (1) phrafx and (2) phgrafx-startup programs in QNX realtime operating system (RTOS) 4.25 and 6.1.0 do not properly drop privileges before executing the system command, which a…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2002-2041

Published Dec 31, 2002

Multiple buffer overflows in realtime operating system (RTOS) 6.1.0 allows local users to execute arbitrary code via (1) a long ABLANG environment variable in phlocale or (2) a lo…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2002-2042

Published Dec 31, 2002

ptrace in the QNX realtime operating system (RTOS) 4.25 and 6.1.0 allows programs to attach to privileged processes, which could allow local users to execute arbitrary code by mod…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2002-2120

Published Dec 31, 2002

Multiple buffer overflows in QNX RTOS 4.25 may allow attackers to execute arbitrary code via long filename arguments to (1) Watcom or (2) int10.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-2407

Published Dec 31, 2002

Certain patches for QNX Neutrino realtime operating system (RTOS) 6.2.0 set insecure permissions for the files (1) /sbin/io-audio by OS Update Patch A, (2) /bin/shutdown, (3) /sbi…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-2409

Published Dec 31, 2002

Photon microGUI in QNX Neutrino realtime operating system (RTOS) 6.1.0 and 6.2.0 allows attackers to read user clipboard information via a direct request to the 1.TEXT file in a d…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort
Showing 1-25 of 32 CVEsPage 1 of 2