← Back

Qnx

qnx

31 CVEs • 7 products

Products (7)

Click to collapse
Toggle
Rtos
rtos
Rtp
rtp
Qnx
qnx
Voyager
voyager
Neutrino Rtos
neutrino_rtos
Qnx Rtos
qnx_rtos

CVEs (31)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Qnx
1Rtos
Apr 16, 2026
Dec 31, 2002
N/A· v4
N/A· v3
7.2 HIGH· v2
The (1) phrafx and (2) phgrafx-startup programs in QNX realtime operating system (RTOS) 4.25 and 6.1.0 do not properly drop privileges before executing the system command, which allows local users to execute arbitrary co...Show more
The (1) phrafx and (2) phgrafx-startup programs in QNX realtime operating system (RTOS) 4.25 and 6.1.0 do not properly drop privileges before executing the system command, which allows local users to execute arbitrary commands by modifying the PATH environment variable to reference a malicious crttrap program.Show less
1Qnx
1Rtos
Apr 16, 2026
Dec 31, 2002
N/A· v4
N/A· v3
2.1 LOW· v2
/bin/su in QNX realtime operating system (RTOS) 4.25 and 6.1.0 allows local users to obtain sensitive information from core dump files by sending the SIGSERV (invalid memory reference) signal.
1Qnx
1Rtos
Apr 16, 2026
Dec 31, 2002
N/A· v4
N/A· v3
2.1 LOW· v2
The timer implementation in QNX RTOS 6.1.0 allows local users to cause a denial of service (hang) and possibly execute arbitrary code by creating multiple timers with a 1-ms tick.
1Qnx
1Qnx Rtos
Apr 16, 2026
Dec 31, 2002
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Multiple buffer overflows in QNX 4.25 may allow local users to execute arbitrary code via long command line arguments to (1) sample, (2) ex, (3) du, (4) find, (5) lex, (6) mkdir, (7) rm, (8) serserv, (9) tcpserv, (10) te...Show more
Multiple buffer overflows in QNX 4.25 may allow local users to execute arbitrary code via long command line arguments to (1) sample, (2) ex, (3) du, (4) find, (5) lex, (6) mkdir, (7) rm, (8) serserv, (9) tcpserv, (10) termdef, (11) time, (12) unzip, (13) use, (14) wcc, (15) wcc386, (16) wd, (17) wdisasm, (18) which, (19) wlib, (20) wlink, (21) wpp, (22) wpp386, (23) wprof, (24) write, or (25) wstrip.Show less
1Qnx
1Rtos
Apr 16, 2026
Nov 12, 2002
N/A· v4
N/A· v3
7.2 HIGH· v2
QNX Neutrino RTOS 6.2.0 uses the PATH environment variable to find and execute the cp program while operating at raised privileges, which allows local users to gain privileges by modifying the PATH to point to a maliciou...Show more
QNX Neutrino RTOS 6.2.0 uses the PATH environment variable to find and execute the cp program while operating at raised privileges, which allows local users to gain privileges by modifying the PATH to point to a malicious cp program.Show less
1Qnx
1Qnx
Apr 16, 2026
Aug 2, 2001
N/A· v4
N/A· v3
2.1 LOW· v2
QNX 2.4 allows a local user to read arbitrary files by directly accessing the mount point for the FAT disk partition, e.g. /fs-dos.
1Qnx
1Rtp
Apr 16, 2026
May 3, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in QNX RTP 5.60 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a large number of arguments to the stat command.
1Qnx
1Voyager
Apr 16, 2026
Dec 19, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
QNX Embedded Resource Manager in Voyager web server 2.01B in the demo disks for QNX 405 allows remote attackers to read sensitive system statistics information via the embedded.html web page.
1Qnx
1Voyager
Apr 16, 2026
Dec 19, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Voyager web server 2.01B in the demo disks for QNX 405 stores sensitive web client information in the .photon directory in the web document root, which allows remote attackers to obtain that information.
1Qnx
1Voyager
Apr 16, 2026
Dec 19, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in Voyager web server 2.01B in the demo disks for QNX 405 allows remote attackers to read arbitrary files via a .. (dot dot) attack.
1Qnx
1Qnx
Apr 16, 2026
Apr 14, 2000
N/A· v4
N/A· v3
7.2 HIGH· v2
The crypt function in QNX uses weak encryption, which allows local users to decrypt passwords.