CVE-2024-48854: Blackberry Qnx Software Development Platform
High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.
Off-by-one error in the TIFF image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to cause an information disclosure in the context of the process using the image codec.
Affected products
- Blackberry Qnx Software Development Platform: version 7.0 only; version 7.1 only; version 8.0 only
Published 2025-01-14. Last modified 2026-06-17.