Home/Product/blackberry qnx software development platform
Product

blackberry qnx software development platform

21 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-2474
all versions
Out-of-bounds write in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause a
9.8CRITICAL
CVE-2024-48858
all versions
Improper input validation in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to c
7.5HIGH
CVE-2024-48857
all versions
NULL pointer dereference in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to ca
7.5HIGH
CVE-2024-48856
all versions
Out-of-bounds write in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause a
9.8CRITICAL
CVE-2024-48855
all versions
Out-of-bounds read in the TIFF image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause a
5.3MEDIUM
CVE-2024-48854
all versions
Off-by-one error in the TIFF image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause an
5.3MEDIUM
CVE-2024-35215
>= 7.0 and < 8.0
NULL pointer dereference in IP socket options processing of the Networking Stack in QNX Software Development Platform (SDP) versio
6.2MEDIUM
CVE-2024-35213
>= 6.6.0 and < 8.0
An improper input validation vulnerability in the SGI Image Codec of QNX SDP version(s) 6.6, 7.0, and 7.1 could allow an attacker
9.0CRITICAL
CVE-2023-32701
all versions
Improper Input Validation in the Networking Stack of QNX SDP version(s) 6.6, 7.0, and 7.1 could allow an attacker to potentially c
7.1HIGH
CVE-2021-32025
>= 6.4.0 and <= 7.0
An elevation of privilege vulnerability in the QNX Neutrino Kernel of affected versions of QNX Software Development Platform versi
8.1HIGH
CVE-2021-32024
>= 6.4.0 and <= 7.1
A remote code execution vulnerability in the BMP image codec of BlackBerry QNX SDP version(s) 6.4 to 7.1 could allow an attacker t
9.8CRITICAL
CVE-2021-22156
< 6.5.0
An integer overflow vulnerability in the calloc() function of the C runtime library of affected versions of BlackBerry® QNX Softw
9.0CRITICAL
CVE-2020-6932
>= 6.4.0 and <= 6.6.0
An information disclosure and remote code execution vulnerability in the slinger web server of the BlackBerry QNX Software Develop
10.0CRITICAL
CVE-2019-8998
<= 6.5.0
An information disclosure vulnerability leading to a potential local escalation of privilege in the procfs service (the /proc file
7.8HIGH
CVE-2017-9371
all versions
In BlackBerry QNX Software Development Platform (SDP) 6.6.0 and 6.5.0 SP1 and earlier, a loss of integrity vulnerability in the de
2.6LOW
CVE-2017-9369
all versions
In BlackBerry QNX Software Development Platform (SDP) 6.6.0 and 6.5.0 SP1 and earlier, an information disclosure vulnerability in
3.8LOW
CVE-2017-3893
all versions
In BlackBerry QNX Software Development Platform (SDP) 6.6.0, the default configuration of the QNX SDP system did not in all circum
1.9LOW
CVE-2017-3892
all versions
In BlackBerry QNX Software Development Platform (SDP) 6.6.0, an information disclosure vulnerability in the default configuration
3.8LOW
CVE-2017-3891
all versions
In BlackBerry QNX Software Development Platform (SDP) 6.6.0, an elevation of privilege vulnerability in the default configuration
9.6CRITICAL
CVE-2013-2688
all versions
Buffer overflow in phrelay in BlackBerry QNX Neutrino RTOS through 6.5.0 SP1 in the QNX Software Development Platform allows remot
CVE-2013-2687
all versions
Stack-based buffer overflow in the bpe_decompress function in (1) BlackBerry QNX Neutrino RTOS through 6.5.0 SP1 and (2) QNX Momen
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin