Back to Database
Status published
Medium
CVE-2006-0618
Format string vulnerability in fontsleuth in QNX Neutrino RTOS 6.3.0...
Vulnerability Description
Format string vulnerability in fontsleuth in QNX Neutrino RTOS 6.3.0 allows local users to execute arbitrary code via format string specifiers in the zeroth argument (program name).
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2006-0618
Credits & Attribution
No credits recorded in the NVD database.
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24559
- http://www.vupen.com/english/advisories/2006/0474
- http://secunia.com/advisories/18750
- http://www.idefense.com/intelligence/vulnerabilities/display.php?id=380
- http://securitytracker.com/id?1015599
- http://www.osvdb.org/22966
- http://www.securityfocus.com/bid/16539
More from qnx
View All →CVE-2011-4060
The runtime linker in QNX Neutrino RTOS 6.5.0 before Service...
Low
3.3
CVE-2006-0623
QNX Neutrino RTOS 6.3.0 ships /etc/rc.d/rc.local with world-writable permissions, which...
High
7.2
CVE-2006-0622
QNX Neutrino RTOS 6.3.0 allows local users to cause a...
Medium
4.9
CVE-2006-0621
Multiple buffer overflows in QNX Neutrino RTOS 6.2.0 allow local...
High
7.2
CVE-2006-0620
Race condition in phfont in QNX Neutrino RTOS 6.2.1 allows...
Medium
6.2
Affected Vendor
Affected Software
neutrino rtos
Vulnerable Versions:
6.3.0
Timeline
Official Publish:
February 9th, 2006
Last Modified:
August 7th, 2024
Added to House:
July 18th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.