Show filters
9 Total Results
Displaying 1-9 of 9
Sort by:
Attacker Value
Unknown
CVE-2006-0621
Disclosure Date: February 09, 2006 (last updated February 22, 2025)
Multiple buffer overflows in QNX Neutrino RTOS 6.2.0 allow local users to execute arbitrary code via a long first argument to the (1) su or (2) passwd commands.
0
Attacker Value
Unknown
CVE-2006-0620
Disclosure Date: February 09, 2006 (last updated February 22, 2025)
Race condition in phfont in QNX Neutrino RTOS 6.2.1 allows local users to execute arbitrary code via unspecified manipulations of the PHFONT and PHOTON2_PATH environment variables.
0
Attacker Value
Unknown
CVE-2005-1528
Disclosure Date: December 31, 2005 (last updated February 22, 2025)
Untrusted search path vulnerability in the crttrap command in QNX Neutrino RTOS 6.2.1 allows local users to load arbitrary libraries via a LD_LIBRARY_PATH environment variable that references a malicious library.
0
Attacker Value
Unknown
CVE-2005-3928
Disclosure Date: November 30, 2005 (last updated February 22, 2025)
Buffer overflow in phgrafx in QNX 6.2.1 and 6.3.0 allows local users to execute arbitrary code via a long command line argument.
0
Attacker Value
Unknown
CVE-2004-1391
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Untrusted execution path vulnerability in the PPPoE daemon (PPPoEd) in QNX RTP 6.1 allows local users to execute arbitrary programs by modifying the PATH environment variable to point to a malicious mount program.
0
Attacker Value
Unknown
CVE-2004-1390
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Multiple buffer overflows in the PPPoE daemon (PPPoEd) in QNX RTP 6.1 allow remote attackers to execute arbitrary code via a long argument to the (1) -F, (2) name, (3) en, (4) upscript, (5) downscript, (6) retries, (7) timeout, (8) scriptdetach, (9) noscript, (10) nodetach, (11) remote_mac, or (12) local_mac flags.
0
Attacker Value
Unknown
CVE-2002-2407
Disclosure Date: December 31, 2002 (last updated February 22, 2025)
Certain patches for QNX Neutrino realtime operating system (RTOS) 6.2.0 set insecure permissions for the files (1) /sbin/io-audio by OS Update Patch A, (2) /bin/shutdown, (3) /sbin/fs-pkg, and (4) phshutdown by QNX experimental patches, (5) cpim, (6) vpim, (7) phrelaycfg, and (8) columns, (9) othello, (10) peg, (11) solitaire, and (12) vpoker in the games pack 2.0.3, which allows local users to gain privileges by modifying the files before permissions are changed.
0
Attacker Value
Unknown
CVE-2002-2409
Disclosure Date: December 31, 2002 (last updated February 22, 2025)
Photon microGUI in QNX Neutrino realtime operating system (RTOS) 6.1.0 and 6.2.0 allows attackers to read user clipboard information via a direct request to the 1.TEXT file in a directory whose name is a hex-encoded user ID.
0
Attacker Value
Unknown
CVE-2002-1239
Disclosure Date: November 12, 2002 (last updated February 22, 2025)
QNX Neutrino RTOS 6.2.0 uses the PATH environment variable to find and execute the cp program while operating at raised privileges, which allows local users to gain privileges by modifying the PATH to point to a malicious cp program.
0