CVE Tools

Qnx

27 CVEs tracked since 2000. Since Apr 2000, none of them reached CISA KEV.

Qnx CVEs per month

Apr 2000 to Oct 2011. Point at a month, or focus the strip and use the arrow keys.
Qnx CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2000-0410
2000-05null or fewer
2000-06null or fewer
2000-07null or fewer
2000-08null or fewer
2000-09null or fewer
2000-10null or fewer
2000-1130
2000-12null or fewer
2001-01null or fewer
2001-02null or fewer
2001-03null or fewer
2001-0410
2001-05null or fewer
2001-06null or fewer
2001-0710
2001-08null or fewer
2001-09null or fewer
2001-10null or fewer
2001-11null or fewer
2001-12null or fewer
2002-01null or fewer
2002-02null or fewer
2002-03null or fewer
2002-04null or fewer
2002-05null or fewer
2002-06null or fewer
2002-07null or fewer
2002-08null or fewer
2002-09null or fewer
2002-10null or fewer
2002-11null or fewer
2002-12null or fewer
2003-01null or fewer
2003-02null or fewer
2003-03null or fewer
2003-04null or fewer
2003-05null or fewer
2003-06null or fewer
2003-07null or fewer
2003-08null or fewer
2003-09null or fewer
2003-10null or fewer
2003-11null or fewer
2003-12null or fewer
2004-01null or fewer
2004-02null or fewer
2004-03null or fewer
2004-04null or fewer
2004-05null or fewer
2004-06null or fewer
2004-07null or fewer
2004-08null or fewer
2004-0910
2004-10null or fewer
2004-11null or fewer
2004-12null or fewer
2005-01null or fewer
2005-0240
2005-03null or fewer
2005-04null or fewer
2005-05null or fewer
2005-06null or fewer
2005-0740
2005-0820
2005-09null or fewer
2005-10null or fewer
2005-11null or fewer
2005-12null or fewer
2006-01null or fewer
2006-0270
2006-03null or fewer
2006-04null or fewer
2006-05null or fewer
2006-06null or fewer
2006-07null or fewer
2006-08null or fewer
2006-09null or fewer
2006-10null or fewer
2006-11null or fewer
2006-12null or fewer
2007-01null or fewer
2007-02null or fewer
2007-03null or fewer
2007-04null or fewer
2007-05null or fewer
2007-06null or fewer
2007-07null or fewer
2007-08null or fewer
2007-09null or fewer
2007-10null or fewer
2007-1120
2007-12null or fewer
2008-01null or fewer
2008-02null or fewer
2008-03null or fewer
2008-04null or fewer
2008-05null or fewer
2008-06null or fewer
2008-07null or fewer
2008-08null or fewer
2008-09null or fewer
2008-10null or fewer
2008-11null or fewer
2008-12null or fewer
2009-01null or fewer
2009-02null or fewer
2009-03null or fewer
2009-04null or fewer
2009-05null or fewer
2009-06null or fewer
2009-07null or fewer
2009-08null or fewer
2009-09null or fewer
2009-10null or fewer
2009-11null or fewer
2009-12null or fewer
2010-01null or fewer
2010-02null or fewer
2010-03null or fewer
2010-04null or fewer
2010-05null or fewer
2010-06null or fewer
2010-07null or fewer
2010-08null or fewer
2010-09null or fewer
2010-10null or fewer
2010-11null or fewer
2010-12null or fewer
2011-01null or fewer
2011-02null or fewer
2011-03null or fewer
2011-04null or fewer
2011-05null or fewer
2011-06null or fewer
2011-07null or fewer
2011-08null or fewer
2011-09null or fewer
2011-1010

Products

The products that kept showing up in Qnx's monthly top three, with their CVEs summed over those months.

  1. Rtos166 months
  2. Rtp52 months
  3. Neutrino Rtos33 months
  4. Voyager31 month
  5. Photon Microgui22 months
  6. Qnx22 months

Latest CVEs

The 15 most recently published vulnerabilities affecting Qnx.

  1. CVE-2011-4060The runtime linker in QNX Neutrino RTOS 6.5.0 before Service Pack 1 does not properly clear the LD_DEBUG_OUTPUT and LD_DEBUG environment variables when a program is spawned from a setuid program, w...3.3
  2. CVE-2002-2409Photon microGUI in QNX Neutrino realtime operating system (RTOS) 6.1.0 and 6.2.0 allows attackers to read user clipboard information via a direct request to the 1.TEXT file in a directory whose nam...3.5
  3. CVE-2002-2407Certain patches for QNX Neutrino realtime operating system (RTOS) 6.2.0 set insecure permissions for the files (1) /sbin/io-audio by OS Update Patch A, (2) /bin/shutdown, (3) /sbin/fs-pkg, and (4) ...6.9
  4. CVE-2006-0622QNX Neutrino RTOS 6.3.0 allows local users to cause a denial of service (hang) by supplying a "break *0xb032d59f" command to gdb.4.9
  5. CVE-2006-0621Multiple buffer overflows in QNX Neutrino RTOS 6.2.0 allow local users to execute arbitrary code via a long first argument to the (1) su or (2) passwd commands.7.2
  6. CVE-2006-0623QNX Neutrino RTOS 6.3.0 ships /etc/rc.d/rc.local with world-writable permissions, which allows local users to modify the file and execute arbitrary code at system startup.7.2
  7. CVE-2006-0620Race condition in phfont in QNX Neutrino RTOS 6.2.1 allows local users to execute arbitrary code via unspecified manipulations of the PHFONT and PHOTON2_PATH environment variables.6.2
  8. CVE-2006-0619Multiple stack-based buffer overflows in QNX Neutrino RTOS 6.3.0 allow local users to execute arbitrary code via long (1) ABLPATH or (2) ABLANG environment variables in the libAP library (libAp.so....4.6
  9. CVE-2006-0618Format string vulnerability in fontsleuth in QNX Neutrino RTOS 6.3.0 allows local users to execute arbitrary code via format string specifiers in the zeroth argument (program name).4.6
  10. CVE-2005-1528Untrusted search path vulnerability in the crttrap command in QNX Neutrino RTOS 6.2.1 allows local users to load arbitrary libraries via a LD_LIBRARY_PATH environment variable that references a mal...7.2
  11. CVE-2005-4082The dhcp.client program for QNX 4.25 vmware is setuid, possibly by default, which allows local users to modify the NIC configuration and conduct other attacks.4.6
  12. CVE-2005-3928Buffer overflow in phgrafx in QNX 6.2.1 and 6.3.0 allows local users to execute arbitrary code via a long command line argument.4.6
  13. CVE-2005-2725The inputtrap utility in QNX RTOS 6.1.0, 6.3, and possibly earlier versions does not properly check permissions when the -t flag is specified, which allows local users to read arbitrary files.2.1
  14. CVE-2002-2120Multiple buffer overflows in QNX RTOS 4.25 may allow attackers to execute arbitrary code via long filename arguments to (1) Watcom or (2) int10.4.6
  15. CVE-2002-2040The (1) phrafx and (2) phgrafx-startup programs in QNX realtime operating system (RTOS) 4.25 and 6.1.0 do not properly drop privileges before executing the system command, which allows local users ...7.2

The record

Peak rank
#4 in Nov 2000
Busiest month shown
Feb 2006, 7 CVEs
Months with a KEV entry
0 since Apr 2000
Monthly snapshots
11 since 2000
Qnx's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store