QNX's vulnerability profile centers on its real-time operating system (RTOS) products and embedded platforms, which occupy a prominent position in the industrial automation, automotive, and critical-infrastructure control sectors despite a narrow product portfolio. The vendor's disclosures frequently acquire public exploit code, reflecting both the operational-technology focus of its user base and the inherent attractiveness of embedded systems as attack targets. The recurring weakness classes—including information exposure, improper link resolution, and memory-buffer violations—are characteristic of low-level systems code and the complex file-system and privilege semantics required in RTOS kernels. Defenders deploying QNX platforms, particularly in networked or internet-exposed roles, should prioritize tracking and testing available exploits and maintaining patch currency on systems that cannot be quickly isolated. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Qnx over time
Signals from CVEs in this vendor scope (32 CVEs).
32 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2004-1682HIGH Format string vulnerability in QNX 6.1 FTP client allows remote authenticated users to gain group bin privileges via format string specifiers in the QUOTE command. | Aug 15, 2004 | 10.0 | 31 | NO | NO |
CVE-2006-0623HIGH QNX Neutrino RTOS 6.3.0 ships /etc/rc.d/rc.local with world-writable permissions, which allows local users to modify the file and execute arbitrary code at system startup. | Feb 9, 2006 | 7.2 | 27 | NO | YES |
CVE-2005-1528HIGH Untrusted search path vulnerability in the crttrap command in QNX Neutrino RTOS 6.2.1 allows local users to load arbitrary libraries via a LD_LIBRARY_PATH environment variable that | Dec 31, 2005 | 7.2 | 27 | NO | YES |
CVE-2004-1390HIGH Multiple buffer overflows in the PPPoE daemon (PPPoEd) in QNX RTP 6.1 allow remote attackers to execute arbitrary code via a long argument to the (1) -F, (2) name, (3) en, (4) upsc | Dec 31, 2004 | 10.0 | 27 | NO | NO |
CVE-2004-1681HIGH Multiple buffer overflows in (1) phrelay-cfg, (2) phlocale, (3) pkg-installer, or (4) input-cfg in QNX Photon microGUI for QNX RTP 6.1 allow local users to gain privileges via a lo | Aug 26, 2004 | 7.2 | 27 | NO | YES |
CVE-2002-2040HIGH The (1) phrafx and (2) phgrafx-startup programs in QNX realtime operating system (RTOS) 4.25 and 6.1.0 do not properly drop privileges before executing the system command, which al | Dec 31, 2002 | 7.2 | 27 | NO | YES |
CVE-2002-2041HIGH Multiple buffer overflows in realtime operating system (RTOS) 6.1.0 allows local users to execute arbitrary code via (1) a long ABLANG environment variable in phlocale or (2) a lon | Dec 31, 2002 | 7.2 | 27 | NO | YES |
CVE-2002-2042HIGH ptrace in the QNX realtime operating system (RTOS) 4.25 and 6.1.0 allows programs to attach to privileged processes, which could allow local users to execute arbitrary code by modi | Dec 31, 2002 | 7.2 | 27 | NO | YES |
CVE-2002-1239HIGH QNX Neutrino RTOS 6.2.0 uses the PATH environment variable to find and execute the cp program while operating at raised privileges, which allows local users to gain privileges by m | Nov 12, 2002 | 7.2 | 27 | NO | YES |
CVE-2000-0250HIGH The crypt function in QNX uses weak encryption, which allows local users to decrypt passwords. | Apr 14, 2000 | 7.2 | 27 | NO | YES |
Signals from CVEs in this vendor scope (32 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Qnx.
Media articles that mention a CVE ID that affects a product developed by Qnx — matched by CVE ID, not by vendor name.