CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

blackberry

qnx_software_development_platform

14 known vulnerabilities · sorted by CVSS score

CVE-2020-6932
CRITICAL10.0

An information disclosure and remote code execution vulnerability in the slinger web server of the BlackBerry QNX Software Development Platform versions 6.4.0 to 6.6.0 could allow an attacker to potentially read arbitrary files and run arbitrary executables in the context of the web server.

blackberry / qnx_software_development_platform
Network
Published Aug 12, 2020
CVE-2024-48856
CRITICAL9.8

Out-of-bounds write in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause a denial-of-service condition or execute code in the context of the process using the image codec.

blackberry / qnx_software_development_platform+2
Network
Published Jan 14, 2025
CVE-2021-32024
CRITICAL9.8

A remote code execution vulnerability in the BMP image codec of BlackBerry QNX SDP version(s) 6.4 to 7.1 could allow an attacker to potentially execute code in the context of the affected process.

blackberry / qnx_software_development_platform
Network
Published Dec 13, 2021
CVE-2025-2474
CRITICAL9.8

Out-of-bounds write in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause a denial-of-service condition or execute code in the context of the process using the image codec.

blackberry / qnx_software_development_platform+2
Network
Published Jun 10, 2025
CVE-2024-35213
CRITICAL9.0

An improper input validation vulnerability in the SGI Image Codec of QNX SDP version(s) 6.6, 7.0, and 7.1 could allow an attacker to potentially cause a denial-of-service condition or execute code in the context of the image processing process.

blackberry / qnx_software_development_platform
Network
Published Jun 11, 2024
CVE-2021-22156
CRITICAL9.0

An integer overflow vulnerability in the calloc() function of the C runtime library of affected versions of BlackBerry® QNX Software Development Platform (SDP) version(s) 6.5.0SP1 and earlier, QNX OS for Medical 1.1 and earlier, and QNX OS for Safety 1.0.1 and earlier that could allow an attacker to potentially perform a denial of service or execute arbitrary code.

blackberry / qnx_software_development_platform+4
Network
Published Aug 17, 2021
CVE-2021-32025
HIGH8.1

An elevation of privilege vulnerability in the QNX Neutrino Kernel of affected versions of QNX Software Development Platform version(s) 6.4.0 to 7.0, QNX Momentics all 6.3.x versions, QNX OS for Safety versions 1.0.0 to 1.0.2, QNX OS for Safety versions 2.0.0 to 2.0.1, QNX for Medical versions 1.0.0 to 1.1.1, and QNX OS for Medical version 2.0.0 could allow an attacker to potentially access data, modify behavior, or permanently crash the system.

blackberry / qnx_momentics+6
Local
Published Mar 10, 2022
CVE-2019-8998
HIGH7.8

An information disclosure vulnerability leading to a potential local escalation of privilege in the procfs service (the /proc filesystem) of BlackBerry QNX Software Development Platform version(s) 6.5.0 SP1 and earlier could allow an attacker to potentially gain unauthorized access to a chosen process address space.

blackberry / qnx_software_development_platform
Local
Published Jul 12, 2019
CVE-2024-48857
HIGH7.5

NULL pointer dereference in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause a denial-of-service condition in the context of the process using the image codec.

blackberry / qnx_software_development_platform+2
Network
Published Jan 14, 2025
CVE-2024-48858
HIGH7.5

Improper input validation in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause a denial-of-service condition in the context of the process using the image codec.

blackberry / qnx_software_development_platform+2
Network
Published Jan 14, 2025
CVE-2023-32701
HIGH7.1

Improper Input Validation in the Networking Stack of QNX SDP version(s) 6.6, 7.0, and 7.1 could allow an attacker to potentially cause Information Disclosure or a Denial-of-Service condition.

blackberry / qnx_software_development_platform+2
Local
Published Nov 14, 2023
CVE-2024-35215
MEDIUM6.2

NULL pointer dereference in IP socket options processing of the Networking Stack in QNX Software Development Platform (SDP) version(s) 7.1 and 7.0 could allow an attacker with local access to cause a denial-of-service condition in the context of the Networking Stack process.

blackberry / qnx_software_development_platform
Local
Published Oct 8, 2024
CVE-2024-48854
MEDIUM5.3

Off-by-one error in the TIFF image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause an information disclosure in the context of the process using the image codec.

blackberry / qnx_software_development_platform+2
Network
Published Jan 14, 2025
CVE-2024-48855
MEDIUM5.3

Out-of-bounds read in the TIFF image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause an information disclosure in the context of the process using the image codec.

blackberry / qnx_software_development_platform+2
Network
Published Jan 14, 2025