Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Qnx

First CVE: Apr 14, 2000Active for: 26 yearsTotal CVEs: 32
32.9
VTI Score
Medium

QNX's vulnerability profile centers on its real-time operating system (RTOS) products and embedded platforms, which occupy a prominent position in the industrial automation, automotive, and critical-infrastructure control sectors despite a narrow product portfolio. The vendor's disclosures frequently acquire public exploit code, reflecting both the operational-technology focus of its user base and the inherent attractiveness of embedded systems as attack targets. The recurring weakness classes—including information exposure, improper link resolution, and memory-buffer violations—are characteristic of low-level systems code and the complex file-system and privilege semantics required in RTOS kernels. Defenders deploying QNX platforms, particularly in networked or internet-exposed roles, should prioritize tracking and testing available exploits and maintaining patch currency on systems that cannot be quickly isolated. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.

FAUCET AI Generated
32
Total CVEs
More Total CVEs than 97% of tracked vendors
0.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 10% of tracked vendors
5.5
Avg CVSS Score
Higher Avg CVSS Score than 23% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Qnx over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 14, 2000
26 years ago
Most Recent CVE
Oct 18, 2011
5,393 days ago

Products(7 total)

Top CVEs

Signals from CVEs in this vendor scope (32 CVEs).

32 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2004-1682HIGH
Format string vulnerability in QNX 6.1 FTP client allows remote authenticated users to gain group bin privileges via format string specifiers in the QUOTE command.
Aug 15, 200410.031NONO
CVE-2006-0623HIGH
QNX Neutrino RTOS 6.3.0 ships /etc/rc.d/rc.local with world-writable permissions, which allows local users to modify the file and execute arbitrary code at system startup.
Feb 9, 20067.227NOYES
CVE-2005-1528HIGH
Untrusted search path vulnerability in the crttrap command in QNX Neutrino RTOS 6.2.1 allows local users to load arbitrary libraries via a LD_LIBRARY_PATH environment variable that
Dec 31, 20057.227NOYES
CVE-2004-1390HIGH
Multiple buffer overflows in the PPPoE daemon (PPPoEd) in QNX RTP 6.1 allow remote attackers to execute arbitrary code via a long argument to the (1) -F, (2) name, (3) en, (4) upsc
Dec 31, 200410.027NONO
CVE-2004-1681HIGH
Multiple buffer overflows in (1) phrelay-cfg, (2) phlocale, (3) pkg-installer, or (4) input-cfg in QNX Photon microGUI for QNX RTP 6.1 allow local users to gain privileges via a lo
Aug 26, 20047.227NOYES
CVE-2002-2040HIGH
The (1) phrafx and (2) phgrafx-startup programs in QNX realtime operating system (RTOS) 4.25 and 6.1.0 do not properly drop privileges before executing the system command, which al
Dec 31, 20027.227NOYES
CVE-2002-2041HIGH
Multiple buffer overflows in realtime operating system (RTOS) 6.1.0 allows local users to execute arbitrary code via (1) a long ABLANG environment variable in phlocale or (2) a lon
Dec 31, 20027.227NOYES
CVE-2002-2042HIGH
ptrace in the QNX realtime operating system (RTOS) 4.25 and 6.1.0 allows programs to attach to privileged processes, which could allow local users to execute arbitrary code by modi
Dec 31, 20027.227NOYES
CVE-2002-1239HIGH
QNX Neutrino RTOS 6.2.0 uses the PATH environment variable to find and execute the cp program while operating at raised privileges, which allows local users to gain privileges by m
Nov 12, 20027.227NOYES
CVE-2000-0250HIGH
The crypt function in QNX uses weak encryption, which allows local users to decrypt passwords.
Apr 14, 20007.227NOYES
View all 32 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products32 CVEs
22%
41%
38%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown32 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown32 (100.0%)
User Interaction
None0 (0.0%)
Unknown32 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown32 (100.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (32 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
15 CVEs
46.9% of CVEs· 81st percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Qnx.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Qnx — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Qnx's Products

View all 1 CNAs →

Top CWEs