Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown

CVE-2005-4082

Disclosure Date: December 08, 2005 (last updated February 22, 2025)
The dhcp.client program for QNX 4.25 vmware is setuid, possibly by default, which allows local users to modify the NIC configuration and conduct other attacks.
0
Attacker Value
Unknown

CVE-2002-1633

Disclosure Date: December 31, 2002 (last updated February 22, 2025)
Multiple buffer overflows in QNX 4.25 may allow local users to execute arbitrary code via long command line arguments to (1) sample, (2) ex, (3) du, (4) find, (5) lex, (6) mkdir, (7) rm, (8) serserv, (9) tcpserv, (10) termdef, (11) time, (12) unzip, (13) use, (14) wcc, (15) wcc386, (16) wd, (17) wdisasm, (18) which, (19) wlib, (20) wlink, (21) wpp, (22) wpp386, (23) wprof, (24) write, or (25) wstrip.
0
Attacker Value
Unknown

CVE-2002-0793

Disclosure Date: August 12, 2002 (last updated February 22, 2025)
Hard link and possibly symbolic link following vulnerabilities in QNX RTOS 4.25 (aka QNX4) allow local users to overwrite arbitrary files via (1) the -f argument to the monitor utility, (2) the -d argument to dumper, (3) the -c argument to crttrap, or (4) using the Watcom sample utility.
Attacker Value
Unknown

CVE-2000-0250

Disclosure Date: April 14, 2000 (last updated February 22, 2025)
The crypt function in QNX uses weak encryption, which allows local users to decrypt passwords.
0