Show filters
9 Total Results
Displaying 1-9 of 9
Sort by:
Attacker Value
Unknown

CVE-2006-0621

Disclosure Date: February 09, 2006 (last updated February 22, 2025)
Multiple buffer overflows in QNX Neutrino RTOS 6.2.0 allow local users to execute arbitrary code via a long first argument to the (1) su or (2) passwd commands.
0
Attacker Value
Unknown

CVE-2006-0620

Disclosure Date: February 09, 2006 (last updated February 22, 2025)
Race condition in phfont in QNX Neutrino RTOS 6.2.1 allows local users to execute arbitrary code via unspecified manipulations of the PHFONT and PHOTON2_PATH environment variables.
0
Attacker Value
Unknown

CVE-2005-1528

Disclosure Date: December 31, 2005 (last updated February 22, 2025)
Untrusted search path vulnerability in the crttrap command in QNX Neutrino RTOS 6.2.1 allows local users to load arbitrary libraries via a LD_LIBRARY_PATH environment variable that references a malicious library.
0
Attacker Value
Unknown

CVE-2005-3928

Disclosure Date: November 30, 2005 (last updated February 22, 2025)
Buffer overflow in phgrafx in QNX 6.2.1 and 6.3.0 allows local users to execute arbitrary code via a long command line argument.
0
Attacker Value
Unknown

CVE-2004-1391

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Untrusted execution path vulnerability in the PPPoE daemon (PPPoEd) in QNX RTP 6.1 allows local users to execute arbitrary programs by modifying the PATH environment variable to point to a malicious mount program.
0
Attacker Value
Unknown

CVE-2004-1390

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Multiple buffer overflows in the PPPoE daemon (PPPoEd) in QNX RTP 6.1 allow remote attackers to execute arbitrary code via a long argument to the (1) -F, (2) name, (3) en, (4) upscript, (5) downscript, (6) retries, (7) timeout, (8) scriptdetach, (9) noscript, (10) nodetach, (11) remote_mac, or (12) local_mac flags.
0
Attacker Value
Unknown

CVE-2002-2407

Disclosure Date: December 31, 2002 (last updated February 22, 2025)
Certain patches for QNX Neutrino realtime operating system (RTOS) 6.2.0 set insecure permissions for the files (1) /sbin/io-audio by OS Update Patch A, (2) /bin/shutdown, (3) /sbin/fs-pkg, and (4) phshutdown by QNX experimental patches, (5) cpim, (6) vpim, (7) phrelaycfg, and (8) columns, (9) othello, (10) peg, (11) solitaire, and (12) vpoker in the games pack 2.0.3, which allows local users to gain privileges by modifying the files before permissions are changed.
0
Attacker Value
Unknown

CVE-2002-2409

Disclosure Date: December 31, 2002 (last updated February 22, 2025)
Photon microGUI in QNX Neutrino realtime operating system (RTOS) 6.1.0 and 6.2.0 allows attackers to read user clipboard information via a direct request to the 1.TEXT file in a directory whose name is a hex-encoded user ID.
0
Attacker Value
Unknown

CVE-2002-1239

Disclosure Date: November 12, 2002 (last updated February 22, 2025)
QNX Neutrino RTOS 6.2.0 uses the PATH environment variable to find and execute the cp program while operating at raised privileges, which allows local users to gain privileges by modifying the PATH to point to a malicious cp program.
0