An information disclosure and remote code execution vulnerability in the slinger web server of the BlackBerry QNX Software Development Platform versions 6.4.0 to 6.6.0 could allow an attacker to potentially read arbitrary files and run arbitrary executables in the context of the web server.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:LBlackberry Qnx Software Development Platform
APPBlackberry6.4.0 – 6.6.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
Related vulnerabilities
CVE-2025-2474CRITICAL9.8PL ✓same product
Out-of-bounds write w kodeku PCX w BlackBerry QNX SDP — RCE i DoS
CVE-2024-48856CRITICAL9.8PL ✓same product
Out-of-bounds write w kodeku PCX w BlackBerry QNX SDP — RCE i DoS
CVE-2024-35213CRITICAL9.0PL ✓same product
Podatność improper input validation w SGI Image Codec QNX SDP
CVE-2021-32024CRITICAL9.8PL ✓same product
RCE w kodeku obrazów BMP w BlackBerry QNX SDP
CVE-2021-22156CRITICAL9.0PL ✓same product
Integer overflow w calloc() w BlackBerry QNX — RCE i DoS