This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Qt First view 2009-09-02
Product Qt Last view 2025-03-21
Version 4.6.4 Type Application
Update *  
Edition *  
Language *  
Sofware Edition *  
Target Software *  
Target Hardware *  
Other *  
 
CPE Product cpe:2.3:a:qt:qt

Activity : Overall

Related : CVE

This CPE have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
  Date Alert Description
5.3 2025-03-21 CVE-2025-30348

encodeText in QDom in Qt before 6.8.0 has a complex algorithm involving XML string copy and inline replacement of parts of a string (with relocation of later data).

5.9 2024-07-04 CVE-2024-39936

An issue was discovered in HTTP2 in Qt before 5.15.18, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.7, and 6.6.x through 6.7.x before 6.7.3. Code to make security-relevant decisions about an established connection may execute too early, because the encrypted() signal has not yet been emitted and processed..

9.8 2023-12-24 CVE-2023-51714

An issue was discovered in the HTTP2 implementation in Qt before 5.15.17, 6.x before 6.2.11, 6.3.x through 6.5.x before 6.5.4, and 6.6.x before 6.6.2. network/access/http2/hpacktable.cpp has an incorrect HPack integer overflow check.

5.5 2023-09-18 CVE-2023-43114

An issue was discovered in Qt before 5.15.16, 6.x before 6.2.10, and 6.3.x through 6.5.x before 6.5.3 on Windows. When using the GDI font engine, if a corrupted font is loaded via QFontDatabase::addApplicationFont{FromData], then it can cause the application to crash because of missing length checks.

7.5 2023-08-20 CVE-2023-37369

In Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.2, there can be an application crash in QXmlStreamReader via a crafted XML string that triggers a situation in which a prefix is greater than a length.

7.5 2023-07-13 CVE-2023-38197

An issue was discovered in Qt before 5.15.15, 6.x before 6.2.10, and 6.3.x through 6.5.x before 6.5.3. There are infinite loops in recursive entity expansion.

5.3 2023-06-05 CVE-2023-34410

An issue was discovered in Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.2. Certificate validation for TLS does not always consider whether the root of a chain is a configured CA certificate.

7.5 2023-05-28 CVE-2023-32763

An issue was discovered in Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1. When a SVG file with an image inside it is rendered, a QTextLayout buffer overflow can be triggered.

5.3 2023-05-28 CVE-2023-32762

An issue was discovered in Qt before 5.15.14, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1. Qt Network incorrectly parses the strict-transport-security (HSTS) header, allowing unencrypted connections to be established, even when explicitly prohibited by the server. This happens if the case used for this header does not exactly match.

5.3 2023-05-22 CVE-2023-33285

An issue was discovered in Qt 5.x before 5.15.14, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1. QDnsLookup has a buffer over-read via a crafted reply from a DNS server.

6.5 2023-05-10 CVE-2023-32573

In Qt before 5.15.14, 6.0.x through 6.2.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1, QtSvg QSvgFont m_unitsPerEm initialization is mishandled.

7.5 2023-04-15 CVE-2023-24607

Qt before 6.4.3 allows a denial of service via a crafted string when the SQL ODBC driver plugin is used and the size of SQLTCHAR is 4. The affected versions are 5.x before 5.15.13, 6.x before 6.2.8, and 6.3.x before 6.4.3.

7.5 2022-03-02 CVE-2022-25634

Qt through 5.15.8 and 6.x through 6.2.3 can load system library files from an unintended working directory.

7.8 2022-02-16 CVE-2022-25255

In Qt 5.9.x through 5.15.x before 5.15.9 and 6.x before 6.2.4 on Linux and UNIX, QProcess could execute a binary from the current working directory when not found in the PATH.

7.5 2021-08-12 CVE-2021-38593

Qt 5.x before 5.15.6 and 6.x through 6.1.2 has an out-of-bounds write in QOutlineMapper::convertPath (called from QRasterPaintEngine::fill and QPaintEngineEx::stroke).

7.8 2021-08-09 CVE-2020-24742

An issue has been fixed in Qt versions 5.14.0 where QPluginLoader attempts to load plugins relative to the working directory, allowing attackers to execute arbitrary code via crafted files.

7.3 2020-09-14 CVE-2020-0570

Uncontrolled search path in the QT Library before 5.14.0, 5.12.7 and 5.9.10 may allow an authenticated user to potentially enable elevation of privilege via local access.

5.3 2020-08-12 CVE-2020-17507

An issue was discovered in Qt through 5.12.9, and 5.13.x through 5.15.x before 5.15.1. read_xbm_body in gui/image/qxbmhandler.cpp has a buffer over-read.

7.5 2020-06-09 CVE-2020-13962

Qt 5.12.2 through 5.14.2, as used in unofficial builds of Mumble 1.3.0 and other products, mishandles OpenSSL's error queue, which can cause a denial of service to QSslSocket users. Because errors leak in unrelated TLS sessions, an unrelated session may be disconnected when any handshake fails. (Mumble 1.3.1 is not affected, regardless of the Qt version.)

7.5 2020-02-28 CVE-2018-21035

In Qt through 5.14.1, the WebSocket implementation accepts up to 2GB for frames and 2GB for messages. Smaller limits cannot be configured. This makes it easier for attackers to cause a denial of service (memory consumption).

7.5 2020-01-24 CVE-2015-9541

Qt through 5.14 allows an exponential XML entity expansion attack via a crafted SVG document that is mishandled in QXmlStreamReader, a related issue to CVE-2003-1564.

9.8 2018-12-26 CVE-2018-19873

An issue was discovered in Qt before 5.11.3. QBmpHandler has a buffer overflow via BMP data.

6.5 2018-12-26 CVE-2018-19871

An issue was discovered in Qt before 5.11.3. There is QTgaFile Uncontrolled Resource Consumption.

8.8 2018-12-26 CVE-2018-19870

An issue was discovered in Qt before 5.11.3. A malformed GIF image causes a NULL pointer dereference in QGifHandler resulting in a segmentation fault.

6.5 2018-12-26 CVE-2018-19869

An issue was discovered in Qt before 5.11.3. A malformed SVG image causes a segmentation fault in qsvghandler.cpp.

CWE : Common Weakness Enumeration

%idName
13% (4) CWE-20 Improper Input Validation
6% (2) CWE-787 Out-of-bounds Write
6% (2) CWE-476 NULL Pointer Dereference
6% (2) CWE-125 Out-of-bounds Read
6% (2) CWE-119 Failure to Constrain Operations within the Bounds of a Memory Buffer
3% (1) CWE-776 Unrestricted Recursive Entity References in DTDs ('XML Bomb')
3% (1) CWE-770 Allocation of Resources Without Limits or Throttling
3% (1) CWE-532 Information Leak Through Log Files
3% (1) CWE-426 Untrusted Search Path
3% (1) CWE-415 Double Free
3% (1) CWE-407 Algorithmic Complexity
3% (1) CWE-400 Uncontrolled Resource Consumption ('Resource Exhaustion')
3% (1) CWE-369 Divide By Zero
3% (1) CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition
3% (1) CWE-310 Cryptographic Issues
3% (1) CWE-295 Certificate Issues
3% (1) CWE-264 Permissions, Privileges, and Access Controls
3% (1) CWE-200 Information Exposure
3% (1) CWE-190 Integer Overflow or Wraparound
3% (1) CWE-189 Numeric Errors
3% (1) CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflo...
3% (1) CWE-78 Improper Sanitization of Special Elements used in an OS Command ('O...
3% (1) CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path ...

Open Source Vulnerability Database (OSVDB)

id Description
75652 Qt src/3rdparty/harfbuzz/src/harfbuzz-gpos.c Font Handling Overflow
57633 Qt X.509 Certificate Authority (CA) Subject Alternative Name Null Byte Handli...

OpenVAS Exploits

This CPE have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
id Description
2012-12-26 Name : Fedora Update for qt FEDORA-2012-19715
File : nvt/gb_fedora_2012_19715_qt_fc16.nasl
2012-12-14 Name : Fedora Update for qt FEDORA-2012-19759
File : nvt/gb_fedora_2012_19759_qt_fc17.nasl
2012-07-30 Name : CentOS Update for frysk CESA-2011:1327 centos4 x86_64
File : nvt/gb_CESA-2011_1327_frysk_centos4_x86_64.nasl
2012-07-30 Name : CentOS Update for phonon-backend-gstreamer CESA-2012:0880 centos6
File : nvt/gb_CESA-2012_0880_phonon-backend-gstreamer_centos6.nasl
2012-07-30 Name : CentOS Update for pango CESA-2011:1326 centos5 x86_64
File : nvt/gb_CESA-2011_1326_pango_centos5_x86_64.nasl
2012-07-30 Name : CentOS Update for evolution28-pango CESA-2011:1325 centos4 x86_64
File : nvt/gb_CESA-2011_1325_evolution28-pango_centos4_x86_64.nasl
2012-07-30 Name : CentOS Update for qt4 CESA-2011:1324 centos5 x86_64
File : nvt/gb_CESA-2011_1324_qt4_centos5_x86_64.nasl
2012-07-16 Name : Ubuntu Update for qt4-x11 USN-1504-1
File : nvt/gb_ubuntu_USN_1504_1.nasl
2012-07-09 Name : RedHat Update for qt RHSA-2011:1323-01
File : nvt/gb_RHSA-2011_1323-01_qt.nasl
2012-06-22 Name : RedHat Update for qt RHSA-2012:0880-04
File : nvt/gb_RHSA-2012_0880-04_qt.nasl
2011-09-23 Name : CentOS Update for evolution28-pango CESA-2011:1325 centos4 i386
File : nvt/gb_CESA-2011_1325_evolution28-pango_centos4_i386.nasl
2011-09-23 Name : CentOS Update for pango CESA-2011:1326 centos5 i386
File : nvt/gb_CESA-2011_1326_pango_centos5_i386.nasl
2011-09-23 Name : CentOS Update for qt4 CESA-2011:1324 centos5 i386
File : nvt/gb_CESA-2011_1324_qt4_centos5_i386.nasl
2011-09-23 Name : CentOS Update for frysk CESA-2011:1327 centos4 i386
File : nvt/gb_CESA-2011_1327_frysk_centos4_i386.nasl
2011-09-23 Name : RedHat Update for qt4 RHSA-2011:1324-01
File : nvt/gb_RHSA-2011_1324-01_qt4.nasl
2011-09-23 Name : RedHat Update for evolution28-pango RHSA-2011:1325-01
File : nvt/gb_RHSA-2011_1325-01_evolution28-pango.nasl
2011-09-23 Name : RedHat Update for pango RHSA-2011:1326-01
File : nvt/gb_RHSA-2011_1326-01_pango.nasl
2011-09-23 Name : RedHat Update for frysk RHSA-2011:1327-01
File : nvt/gb_RHSA-2011_1327-01_frysk.nasl
2010-05-17 Name : Fedora Update for qt FEDORA-2010-8379
File : nvt/gb_fedora_2010_8379_qt_fc11.nasl
2009-11-17 Name : Fedora Core 11 FEDORA-2009-11491 (qt)
File : nvt/fcore_2009_11491.nasl
2009-11-17 Name : SLES10: Security update for Qt3
File : nvt/sles10_dbus-1-qt.nasl
2009-11-17 Name : SLES11: Security update for libqt4
File : nvt/sles11_libqt4.nasl
2009-11-17 Name : Fedora Core 10 FEDORA-2009-11488 (qt)
File : nvt/fcore_2009_11488.nasl
2009-09-15 Name : Mandrake Security Advisory MDVSA-2009:225 (qt4)
File : nvt/mdksa_2009_225.nasl
2009-09-15 Name : Ubuntu USN-829-1 (qt4-x11)
File : nvt/ubuntu_829_1.nasl

Nessus® Vulnerability Scanner

This CPE have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
id Description
2019-01-07 Name: The remote Debian host is missing a security update.
File: debian_DLA-1627.nasl - Type: ACT_GATHER_INFO
2019-01-03 Name: The remote Fedora host is missing a security update.
File: fedora_2018-17843a895b.nasl - Type: ACT_GATHER_INFO
2018-06-11 Name: The remote Fedora host is missing a security update.
File: fedora_2018-0a0da2f3b7.nasl - Type: ACT_GATHER_INFO
2015-12-29 Name: The remote openSUSE host is missing a security update.
File: openSUSE-2015-953.nasl - Type: ACT_GATHER_INFO
2015-08-18 Name: The remote SUSE host is missing one or more security updates.
File: suse_SU-2015-1383-1.nasl - Type: ACT_GATHER_INFO
2015-08-13 Name: The remote SUSE host is missing one or more security updates.
File: suse_SU-2015-1359-1.nasl - Type: ACT_GATHER_INFO
2015-07-27 Name: The remote FreeBSD host is missing one or more security-related updates.
File: freebsd_pkg_9d73207832c711e5b26300262d5ed8ee.nasl - Type: ACT_GATHER_INFO
2015-06-04 Name: The remote Ubuntu host is missing one or more security-related patches.
File: ubuntu_USN-2626-1.nasl - Type: ACT_GATHER_INFO
2015-06-02 Name: The remote SUSE host is missing one or more security updates.
File: suse_SU-2015-0977-1.nasl - Type: ACT_GATHER_INFO
2015-05-05 Name: The remote Fedora host is missing a security update.
File: fedora_2015-6925.nasl - Type: ACT_GATHER_INFO
2015-05-04 Name: The remote Fedora host is missing a security update.
File: fedora_2015-6932.nasl - Type: ACT_GATHER_INFO
2015-05-01 Name: The remote Debian host is missing a security update.
File: debian_DLA-210.nasl - Type: ACT_GATHER_INFO
2015-04-22 Name: The remote Slackware host is missing a security update.
File: Slackware_SSA_2015-111-13.nasl - Type: ACT_GATHER_INFO
2015-03-26 Name: The remote Debian host is missing a security update.
File: debian_DLA-117.nasl - Type: ACT_GATHER_INFO
2015-03-24 Name: The remote openSUSE host is missing a security update.
File: openSUSE-2015-251.nasl - Type: ACT_GATHER_INFO
2015-03-10 Name: The remote Fedora host is missing a security update.
File: fedora_2015-2869.nasl - Type: ACT_GATHER_INFO
2015-03-10 Name: The remote Fedora host is missing a security update.
File: fedora_2015-2886.nasl - Type: ACT_GATHER_INFO
2015-03-10 Name: The remote Fedora host is missing a security update.
File: fedora_2015-2901.nasl - Type: ACT_GATHER_INFO
2015-03-09 Name: The remote Fedora host is missing a security update.
File: fedora_2015-2866.nasl - Type: ACT_GATHER_INFO
2015-03-09 Name: The remote Fedora host is missing a security update.
File: fedora_2015-2897.nasl - Type: ACT_GATHER_INFO
2015-03-05 Name: The remote Fedora host is missing a security update.
File: fedora_2015-2895.nasl - Type: ACT_GATHER_INFO
2015-03-05 Name: The remote FreeBSD host is missing one or more security-related updates.
File: freebsd_pkg_c9c3374dc2c111e4b2365453ed2e2b49.nasl - Type: ACT_GATHER_INFO
2014-12-15 Name: The remote Gentoo host is missing one or more security-related patches.
File: gentoo_GLSA-201412-25.nasl - Type: ACT_GATHER_INFO
2014-07-21 Name: The remote FreeBSD host is missing one or more security-related updates.
File: freebsd_pkg_904d78b80f7e11e48b715453ed2e2b49.nasl - Type: ACT_GATHER_INFO
2014-06-13 Name: The remote openSUSE host is missing a security update.
File: openSUSE-2013-10.nasl - Type: ACT_GATHER_INFO