← Vulnerability feed

Vulnerability record · CVE-2006-0623 · published 9 February 2006

CVE-2006-0623: Qnx rtos vulnerability

Qnx · Rtos

QNX Neutrino RTOS 6.3.0 ships /etc/rc.d/rc.local with world-writable permissions, which allows local users to modify the file and execute arbitrary code at system startup.

7.2 CVSS 2.0 High EPSS 0.91% · top 41.6%
7.2CVSS 2.0 base score
0.91%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
14References
16 Jun 2026Last modified by NVD

Description

QNX Neutrino RTOS 6.3.0 ships /etc/rc.d/rc.local with world-writable permissions, which allows local users to modify the file and execute arbitrary code at system startup.

AV:L/AC:L/Au:N/C:C/I:C/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2006-0623 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2004-1390Qnx rtos vulnerabilityMultiple buffer overflows in the PPPoE daemon (PPPoEd) in QNX RTP 6.1 allow remote attackers to execute arbitrary code via a long argument to the (1)…EPSS 7.3%7.2CVE-2006-0621Qnx rtos vulnerabilityMultiple buffer overflows in QNX Neutrino RTOS 6.2.0 allow local users to execute arbitrary code via a long first argument to the (1) su or (2) passw…EPSS 0.50%7.2CVE-2005-1528Qnx rtos vulnerabilityUntrusted search path vulnerability in the crttrap command in QNX Neutrino RTOS 6.2.1 allows local users to load arbitrary libraries via a LD_LIBRARY…EPSS 0.84%7.2CVE-2002-2040Qnx rtos vulnerabilityThe (1) phrafx and (2) phgrafx-startup programs in QNX realtime operating system (RTOS) 4.25 and 6.1.0 do not properly drop privileges before executi…EPSS 1.1%7.2CVE-2002-2041Qnx rtos vulnerabilityMultiple buffer overflows in realtime operating system (RTOS) 6.1.0 allows local users to execute arbitrary code via (1) a long ABLANG environment va…EPSS 1.2%7.2CVE-2002-2042Qnx rtos vulnerabilityptrace in the QNX realtime operating system (RTOS) 4.25 and 6.1.0 allows programs to attach to privileged processes, which could allow local users to…EPSS 1.0%7.2CVE-2002-1239Qnx rtos vulnerabilityQNX Neutrino RTOS 6.2.0 uses the PATH environment variable to find and execute the cp program while operating at raised privileges, which allows loca…EPSS 0.90%6.9CVE-2002-2407Qnx rtos permissions and access controls vulnerabilityCertain patches for QNX Neutrino realtime operating system (RTOS) 6.2.0 set insecure permissions for the files (1) /sbin/io-audio by OS Update Patch …EPSS 0.29%

Source: NIST National Vulnerability Database (record CVE-2006-0623), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.