← Vulnerability feed

Vulnerability record · CVE-2013-2687 · published 12 July 2013

CVE-2013-2687: Blackberry qnx momentics tool suite memory buffer overflow vulnerability

Blackberry · Qnx Momentics Tool Suite

Stack-based buffer overflow in the bpe_decompress function in (1) BlackBerry QNX Neutrino RTOS through 6.5.0 SP1 and (2) QNX Momentics Tool Suite through 6.5.0 SP1 in the QNX Software Development Platform allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted packets to TCP port 4868.

7.8 CVSS 2.0 High EPSS 8.2% · top 5.3% CWE-119 · Memory buffer overflow
7.8CVSS 2.0 base score
8.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
6References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in the bpe_decompress function in (1) BlackBerry QNX Neutrino RTOS through 6.5.0 SP1 and (2) QNX Momentics Tool Suite through 6.5.0 SP1 in the QNX Software Development Platform allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted packets to TCP port 4868.

AV:N/AC:L/Au:N/C:N/I:N/A:C

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2013-2687 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-2474Blackberry qnx software development platform out-of-bounds write vulnerabilityOut-of-bounds write in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause a denial-of-service …EPSS 0.73%9.8CVE-2024-48856Blackberry qnx software development platform out-of-bounds write vulnerabilityOut-of-bounds write in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause a denial-of-service …EPSS 0.62%9.8CVE-2021-32024Blackberry qnx software development platform vulnerabilityA remote code execution vulnerability in the BMP image codec of BlackBerry QNX SDP version(s) 6.4 to 7.1 could allow an attacker to potentially execu…EPSS 1.8%9.8CVE-2021-22156Blackberry qnx software development platform integer overflow vulnerabilityAn integer overflow vulnerability in the calloc() function of the C runtime library of affected versions of BlackBerry® QNX Software Development Plat…EPSS 1.8%9.8CVE-2020-6932Blackberry qnx software development platform vulnerabilityAn information disclosure and remote code execution vulnerability in the slinger web server of the BlackBerry QNX Software Development Platform versi…EPSS 3.6%9.6CVE-2017-3891Blackberry qnx software development platform incorrect authorization vulnerabilityIn BlackBerry QNX Software Development Platform (SDP) 6.6.0, an elevation of privilege vulnerability in the default configuration of the QNX SDP with…EPSS 1.3%9.0CVE-2024-35213Blackberry qnx software development platform vulnerabilityAn improper input validation vulnerability in the SGI Image Codec of QNX SDP version(s) 6.6, 7.0, and 7.1 could allow an attacker to potentially caus…EPSS 0.52%7.8CVE-2021-32025Blackberry qnx momentics vulnerabilityAn elevation of privilege vulnerability in the QNX Neutrino Kernel of affected versions of QNX Software Development Platform version(s) 6.4.0 to 7.0,…EPSS 0.18%

Source: NIST National Vulnerability Database (record CVE-2013-2687), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.