- EPSS 0.11%
- Veröffentlicht 29.07.2026 17:58:27
- Zuletzt bearbeitet 30.07.2026 16:51:19
Improper Input Validation in the decode() function of the traceparser library could allow an attacker with a corrupted kernel trace event log (.kev) file, to execute arbitrary code or cause a crash in processes that use libtraceparser in QNX hosts or...
CVE-2026-4018
- EPSS 0.09%
- Veröffentlicht 14.07.2026 17:34:01
- Zuletzt bearbeitet 15.07.2026 16:24:31
TOCTOU Race Condition in specific trace commands of the TraceEvent() system call could allow an attacker with local access and with the PROCMGR_AID_TRACE ability, to cause information disclosure, data tampering or a crash of the QNX Neutrino kernel.
CVE-2026-4017
- EPSS 0.12%
- Veröffentlicht 14.07.2026 17:25:13
- Zuletzt bearbeitet 15.07.2026 16:24:31
Buffer Overflow in the entry handler of the TraceEvent() system call could allow an attacker with local access to cause information disclosure, data tampering or a crash of the QNX Neutrino kernel.
CVE-2026-0515
- EPSS 0.11%
- Veröffentlicht 14.07.2026 17:13:07
- Zuletzt bearbeitet 15.07.2026 16:24:31
Insufficient Parameter Validation in the SchedGet() system call could allow an attacker with local access to cause a crash of the QNX Neutrino kernel.
CVE-2025-8090
- EPSS 0.12%
- Veröffentlicht 13.01.2026 16:36:21
- Zuletzt bearbeitet 15.04.2026 00:35:42
Null pointer dereference in the MsgRegisterEvent() system call could allow an attacker with local access and code execution abilities to crash the QNX Neutrino kernel.
CVE-2025-2474
- EPSS 0.61%
- Veröffentlicht 10.06.2025 17:38:03
- Zuletzt bearbeitet 01.12.2025 18:05:04
Out-of-bounds write in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause a denial-of-service condition or execute code in the context of the process using the image codec.
CVE-2024-48858
- EPSS 0.57%
- Veröffentlicht 14.01.2025 20:15:28
- Zuletzt bearbeitet 01.12.2025 18:06:16
Improper input validation in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause a denial-of-service condition in the context of the process using the image codec.
CVE-2024-48857
- EPSS 0.44%
- Veröffentlicht 14.01.2025 19:15:31
- Zuletzt bearbeitet 21.01.2025 18:06:46
NULL pointer dereference in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause a denial-of-service condition in the context of the process using the image codec.
CVE-2024-48856
- EPSS 0.62%
- Veröffentlicht 14.01.2025 19:15:31
- Zuletzt bearbeitet 21.01.2025 18:06:49
Out-of-bounds write in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause a denial-of-service condition or execute code in the context of the process using the image codec.
CVE-2024-48855
- EPSS 0.37%
- Veröffentlicht 14.01.2025 19:15:31
- Zuletzt bearbeitet 21.01.2025 18:07:12
Out-of-bounds read in the TIFF image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause an information disclosure in the context of the process using the image codec.