Summary
Detail | |||
---|---|---|---|
Vendor | Qt | First view | 2009-09-02 |
Product | Qt | Last view | 2025-03-21 |
Version | 4.6.4 | Type | Application |
Update | * | ||
Edition | * | ||
Language | * | ||
Sofware Edition | * | ||
Target Software | * | ||
Target Hardware | * | ||
Other | * | ||
CPE Product | cpe:2.3:a:qt:qt |
Activity : Overall
Related : CVE
Date | Alert | Description | |
---|---|---|---|
5.3 | 2025-03-21 | CVE-2025-30348 | encodeText in QDom in Qt before 6.8.0 has a complex algorithm involving XML string copy and inline replacement of parts of a string (with relocation of later data). |
5.9 | 2024-07-04 | CVE-2024-39936 | An issue was discovered in HTTP2 in Qt before 5.15.18, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.7, and 6.6.x through 6.7.x before 6.7.3. Code to make security-relevant decisions about an established connection may execute too early, because the encrypted() signal has not yet been emitted and processed.. |
9.8 | 2023-12-24 | CVE-2023-51714 | An issue was discovered in the HTTP2 implementation in Qt before 5.15.17, 6.x before 6.2.11, 6.3.x through 6.5.x before 6.5.4, and 6.6.x before 6.6.2. network/access/http2/hpacktable.cpp has an incorrect HPack integer overflow check. |
5.5 | 2023-09-18 | CVE-2023-43114 | An issue was discovered in Qt before 5.15.16, 6.x before 6.2.10, and 6.3.x through 6.5.x before 6.5.3 on Windows. When using the GDI font engine, if a corrupted font is loaded via QFontDatabase::addApplicationFont{FromData], then it can cause the application to crash because of missing length checks. |
7.5 | 2023-08-20 | CVE-2023-37369 | In Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.2, there can be an application crash in QXmlStreamReader via a crafted XML string that triggers a situation in which a prefix is greater than a length. |
7.5 | 2023-07-13 | CVE-2023-38197 | An issue was discovered in Qt before 5.15.15, 6.x before 6.2.10, and 6.3.x through 6.5.x before 6.5.3. There are infinite loops in recursive entity expansion. |
5.3 | 2023-06-05 | CVE-2023-34410 | An issue was discovered in Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.2. Certificate validation for TLS does not always consider whether the root of a chain is a configured CA certificate. |
7.5 | 2023-05-28 | CVE-2023-32763 | An issue was discovered in Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1. When a SVG file with an image inside it is rendered, a QTextLayout buffer overflow can be triggered. |
5.3 | 2023-05-28 | CVE-2023-32762 | An issue was discovered in Qt before 5.15.14, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1. Qt Network incorrectly parses the strict-transport-security (HSTS) header, allowing unencrypted connections to be established, even when explicitly prohibited by the server. This happens if the case used for this header does not exactly match. |
5.3 | 2023-05-22 | CVE-2023-33285 | An issue was discovered in Qt 5.x before 5.15.14, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1. QDnsLookup has a buffer over-read via a crafted reply from a DNS server. |
6.5 | 2023-05-10 | CVE-2023-32573 | In Qt before 5.15.14, 6.0.x through 6.2.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1, QtSvg QSvgFont m_unitsPerEm initialization is mishandled. |
7.5 | 2023-04-15 | CVE-2023-24607 | Qt before 6.4.3 allows a denial of service via a crafted string when the SQL ODBC driver plugin is used and the size of SQLTCHAR is 4. The affected versions are 5.x before 5.15.13, 6.x before 6.2.8, and 6.3.x before 6.4.3. |
7.5 | 2022-03-02 | CVE-2022-25634 | Qt through 5.15.8 and 6.x through 6.2.3 can load system library files from an unintended working directory. |
7.8 | 2022-02-16 | CVE-2022-25255 | In Qt 5.9.x through 5.15.x before 5.15.9 and 6.x before 6.2.4 on Linux and UNIX, QProcess could execute a binary from the current working directory when not found in the PATH. |
7.5 | 2021-08-12 | CVE-2021-38593 | Qt 5.x before 5.15.6 and 6.x through 6.1.2 has an out-of-bounds write in QOutlineMapper::convertPath (called from QRasterPaintEngine::fill and QPaintEngineEx::stroke). |
7.8 | 2021-08-09 | CVE-2020-24742 | An issue has been fixed in Qt versions 5.14.0 where QPluginLoader attempts to load plugins relative to the working directory, allowing attackers to execute arbitrary code via crafted files. |
7.3 | 2020-09-14 | CVE-2020-0570 | Uncontrolled search path in the QT Library before 5.14.0, 5.12.7 and 5.9.10 may allow an authenticated user to potentially enable elevation of privilege via local access. |
5.3 | 2020-08-12 | CVE-2020-17507 | An issue was discovered in Qt through 5.12.9, and 5.13.x through 5.15.x before 5.15.1. read_xbm_body in gui/image/qxbmhandler.cpp has a buffer over-read. |
7.5 | 2020-06-09 | CVE-2020-13962 | Qt 5.12.2 through 5.14.2, as used in unofficial builds of Mumble 1.3.0 and other products, mishandles OpenSSL's error queue, which can cause a denial of service to QSslSocket users. Because errors leak in unrelated TLS sessions, an unrelated session may be disconnected when any handshake fails. (Mumble 1.3.1 is not affected, regardless of the Qt version.) |
7.5 | 2020-02-28 | CVE-2018-21035 | In Qt through 5.14.1, the WebSocket implementation accepts up to 2GB for frames and 2GB for messages. Smaller limits cannot be configured. This makes it easier for attackers to cause a denial of service (memory consumption). |
7.5 | 2020-01-24 | CVE-2015-9541 | Qt through 5.14 allows an exponential XML entity expansion attack via a crafted SVG document that is mishandled in QXmlStreamReader, a related issue to CVE-2003-1564. |
9.8 | 2018-12-26 | CVE-2018-19873 | An issue was discovered in Qt before 5.11.3. QBmpHandler has a buffer overflow via BMP data. |
6.5 | 2018-12-26 | CVE-2018-19871 | An issue was discovered in Qt before 5.11.3. There is QTgaFile Uncontrolled Resource Consumption. |
8.8 | 2018-12-26 | CVE-2018-19870 | An issue was discovered in Qt before 5.11.3. A malformed GIF image causes a NULL pointer dereference in QGifHandler resulting in a segmentation fault. |
6.5 | 2018-12-26 | CVE-2018-19869 | An issue was discovered in Qt before 5.11.3. A malformed SVG image causes a segmentation fault in qsvghandler.cpp. |
CWE : Common Weakness Enumeration
% | id | Name |
---|---|---|
13% (4) | CWE-20 | Improper Input Validation |
6% (2) | CWE-787 | Out-of-bounds Write |
6% (2) | CWE-476 | NULL Pointer Dereference |
6% (2) | CWE-125 | Out-of-bounds Read |
6% (2) | CWE-119 | Failure to Constrain Operations within the Bounds of a Memory Buffer |
3% (1) | CWE-776 | Unrestricted Recursive Entity References in DTDs ('XML Bomb') |
3% (1) | CWE-770 | Allocation of Resources Without Limits or Throttling |
3% (1) | CWE-532 | Information Leak Through Log Files |
3% (1) | CWE-426 | Untrusted Search Path |
3% (1) | CWE-415 | Double Free |
3% (1) | CWE-407 | Algorithmic Complexity |
3% (1) | CWE-400 | Uncontrolled Resource Consumption ('Resource Exhaustion') |
3% (1) | CWE-369 | Divide By Zero |
3% (1) | CWE-367 | Time-of-check Time-of-use (TOCTOU) Race Condition |
3% (1) | CWE-310 | Cryptographic Issues |
3% (1) | CWE-295 | Certificate Issues |
3% (1) | CWE-264 | Permissions, Privileges, and Access Controls |
3% (1) | CWE-200 | Information Exposure |
3% (1) | CWE-190 | Integer Overflow or Wraparound |
3% (1) | CWE-189 | Numeric Errors |
3% (1) | CWE-120 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflo... |
3% (1) | CWE-78 | Improper Sanitization of Special Elements used in an OS Command ('O... |
3% (1) | CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path ... |
Open Source Vulnerability Database (OSVDB)
id | Description |
---|---|
75652 | Qt src/3rdparty/harfbuzz/src/harfbuzz-gpos.c Font Handling Overflow |
57633 | Qt X.509 Certificate Authority (CA) Subject Alternative Name Null Byte Handli... |
OpenVAS Exploits
id | Description |
---|---|
2012-12-26 | Name : Fedora Update for qt FEDORA-2012-19715 File : nvt/gb_fedora_2012_19715_qt_fc16.nasl |
2012-12-14 | Name : Fedora Update for qt FEDORA-2012-19759 File : nvt/gb_fedora_2012_19759_qt_fc17.nasl |
2012-07-30 | Name : CentOS Update for frysk CESA-2011:1327 centos4 x86_64 File : nvt/gb_CESA-2011_1327_frysk_centos4_x86_64.nasl |
2012-07-30 | Name : CentOS Update for phonon-backend-gstreamer CESA-2012:0880 centos6 File : nvt/gb_CESA-2012_0880_phonon-backend-gstreamer_centos6.nasl |
2012-07-30 | Name : CentOS Update for pango CESA-2011:1326 centos5 x86_64 File : nvt/gb_CESA-2011_1326_pango_centos5_x86_64.nasl |
2012-07-30 | Name : CentOS Update for evolution28-pango CESA-2011:1325 centos4 x86_64 File : nvt/gb_CESA-2011_1325_evolution28-pango_centos4_x86_64.nasl |
2012-07-30 | Name : CentOS Update for qt4 CESA-2011:1324 centos5 x86_64 File : nvt/gb_CESA-2011_1324_qt4_centos5_x86_64.nasl |
2012-07-16 | Name : Ubuntu Update for qt4-x11 USN-1504-1 File : nvt/gb_ubuntu_USN_1504_1.nasl |
2012-07-09 | Name : RedHat Update for qt RHSA-2011:1323-01 File : nvt/gb_RHSA-2011_1323-01_qt.nasl |
2012-06-22 | Name : RedHat Update for qt RHSA-2012:0880-04 File : nvt/gb_RHSA-2012_0880-04_qt.nasl |
2011-09-23 | Name : CentOS Update for evolution28-pango CESA-2011:1325 centos4 i386 File : nvt/gb_CESA-2011_1325_evolution28-pango_centos4_i386.nasl |
2011-09-23 | Name : CentOS Update for pango CESA-2011:1326 centos5 i386 File : nvt/gb_CESA-2011_1326_pango_centos5_i386.nasl |
2011-09-23 | Name : CentOS Update for qt4 CESA-2011:1324 centos5 i386 File : nvt/gb_CESA-2011_1324_qt4_centos5_i386.nasl |
2011-09-23 | Name : CentOS Update for frysk CESA-2011:1327 centos4 i386 File : nvt/gb_CESA-2011_1327_frysk_centos4_i386.nasl |
2011-09-23 | Name : RedHat Update for qt4 RHSA-2011:1324-01 File : nvt/gb_RHSA-2011_1324-01_qt4.nasl |
2011-09-23 | Name : RedHat Update for evolution28-pango RHSA-2011:1325-01 File : nvt/gb_RHSA-2011_1325-01_evolution28-pango.nasl |
2011-09-23 | Name : RedHat Update for pango RHSA-2011:1326-01 File : nvt/gb_RHSA-2011_1326-01_pango.nasl |
2011-09-23 | Name : RedHat Update for frysk RHSA-2011:1327-01 File : nvt/gb_RHSA-2011_1327-01_frysk.nasl |
2010-05-17 | Name : Fedora Update for qt FEDORA-2010-8379 File : nvt/gb_fedora_2010_8379_qt_fc11.nasl |
2009-11-17 | Name : Fedora Core 11 FEDORA-2009-11491 (qt) File : nvt/fcore_2009_11491.nasl |
2009-11-17 | Name : SLES10: Security update for Qt3 File : nvt/sles10_dbus-1-qt.nasl |
2009-11-17 | Name : SLES11: Security update for libqt4 File : nvt/sles11_libqt4.nasl |
2009-11-17 | Name : Fedora Core 10 FEDORA-2009-11488 (qt) File : nvt/fcore_2009_11488.nasl |
2009-09-15 | Name : Mandrake Security Advisory MDVSA-2009:225 (qt4) File : nvt/mdksa_2009_225.nasl |
2009-09-15 | Name : Ubuntu USN-829-1 (qt4-x11) File : nvt/ubuntu_829_1.nasl |
Nessus® Vulnerability Scanner
id | Description |
---|---|
2019-01-07 | Name: The remote Debian host is missing a security update. File: debian_DLA-1627.nasl - Type: ACT_GATHER_INFO |
2019-01-03 | Name: The remote Fedora host is missing a security update. File: fedora_2018-17843a895b.nasl - Type: ACT_GATHER_INFO |
2018-06-11 | Name: The remote Fedora host is missing a security update. File: fedora_2018-0a0da2f3b7.nasl - Type: ACT_GATHER_INFO |
2015-12-29 | Name: The remote openSUSE host is missing a security update. File: openSUSE-2015-953.nasl - Type: ACT_GATHER_INFO |
2015-08-18 | Name: The remote SUSE host is missing one or more security updates. File: suse_SU-2015-1383-1.nasl - Type: ACT_GATHER_INFO |
2015-08-13 | Name: The remote SUSE host is missing one or more security updates. File: suse_SU-2015-1359-1.nasl - Type: ACT_GATHER_INFO |
2015-07-27 | Name: The remote FreeBSD host is missing one or more security-related updates. File: freebsd_pkg_9d73207832c711e5b26300262d5ed8ee.nasl - Type: ACT_GATHER_INFO |
2015-06-04 | Name: The remote Ubuntu host is missing one or more security-related patches. File: ubuntu_USN-2626-1.nasl - Type: ACT_GATHER_INFO |
2015-06-02 | Name: The remote SUSE host is missing one or more security updates. File: suse_SU-2015-0977-1.nasl - Type: ACT_GATHER_INFO |
2015-05-05 | Name: The remote Fedora host is missing a security update. File: fedora_2015-6925.nasl - Type: ACT_GATHER_INFO |
2015-05-04 | Name: The remote Fedora host is missing a security update. File: fedora_2015-6932.nasl - Type: ACT_GATHER_INFO |
2015-05-01 | Name: The remote Debian host is missing a security update. File: debian_DLA-210.nasl - Type: ACT_GATHER_INFO |
2015-04-22 | Name: The remote Slackware host is missing a security update. File: Slackware_SSA_2015-111-13.nasl - Type: ACT_GATHER_INFO |
2015-03-26 | Name: The remote Debian host is missing a security update. File: debian_DLA-117.nasl - Type: ACT_GATHER_INFO |
2015-03-24 | Name: The remote openSUSE host is missing a security update. File: openSUSE-2015-251.nasl - Type: ACT_GATHER_INFO |
2015-03-10 | Name: The remote Fedora host is missing a security update. File: fedora_2015-2869.nasl - Type: ACT_GATHER_INFO |
2015-03-10 | Name: The remote Fedora host is missing a security update. File: fedora_2015-2886.nasl - Type: ACT_GATHER_INFO |
2015-03-10 | Name: The remote Fedora host is missing a security update. File: fedora_2015-2901.nasl - Type: ACT_GATHER_INFO |
2015-03-09 | Name: The remote Fedora host is missing a security update. File: fedora_2015-2866.nasl - Type: ACT_GATHER_INFO |
2015-03-09 | Name: The remote Fedora host is missing a security update. File: fedora_2015-2897.nasl - Type: ACT_GATHER_INFO |
2015-03-05 | Name: The remote Fedora host is missing a security update. File: fedora_2015-2895.nasl - Type: ACT_GATHER_INFO |
2015-03-05 | Name: The remote FreeBSD host is missing one or more security-related updates. File: freebsd_pkg_c9c3374dc2c111e4b2365453ed2e2b49.nasl - Type: ACT_GATHER_INFO |
2014-12-15 | Name: The remote Gentoo host is missing one or more security-related patches. File: gentoo_GLSA-201412-25.nasl - Type: ACT_GATHER_INFO |
2014-07-21 | Name: The remote FreeBSD host is missing one or more security-related updates. File: freebsd_pkg_904d78b80f7e11e48b715453ed2e2b49.nasl - Type: ACT_GATHER_INFO |
2014-06-13 | Name: The remote openSUSE host is missing a security update. File: openSUSE-2013-10.nasl - Type: ACT_GATHER_INFO |