4.3

CVE-2012-5624

The XMLHttpRequest object in Qt before 4.8.4 enables http redirection to the file scheme, which allows man-in-the-middle attackers to force the read of arbitrary local files and possibly obtain sensitive information via a file: URL to a QML application.

Data is provided by the National Vulnerability Database (NVD)
DigiaQt Version <= 4.8.3
QtQt Version1.41
QtQt Version1.42
QtQt Version1.43
QtQt Version1.44
QtQt Version1.45
QtQt Version2.0.0
QtQt Version2.0.1
QtQt Version2.0.2
QtQt Version3.3.0
QtQt Version3.3.1
QtQt Version3.3.2
QtQt Version3.3.3
QtQt Version3.3.4
QtQt Version3.3.5
QtQt Version3.3.6
QtQt Version4.0.0
QtQt Version4.0.1
QtQt Version4.1.0
QtQt Version4.1.1
QtQt Version4.1.2
QtQt Version4.1.3
QtQt Version4.1.4
QtQt Version4.1.5
QtQt Version4.2.0
QtQt Version4.2.1
QtQt Version4.2.3
QtQt Version4.3.0
QtQt Version4.3.1
QtQt Version4.3.2
QtQt Version4.3.3
QtQt Version4.3.4
QtQt Version4.3.5
QtQt Version4.4.0
QtQt Version4.4.1
QtQt Version4.4.2
QtQt Version4.4.3
QtQt Version4.5.0
QtQt Version4.5.1
QtQt Version4.5.2
QtQt Version4.5.3
QtQt Version4.6.0
QtQt Version4.6.0 Updaterc1
QtQt Version4.6.1
QtQt Version4.6.2
QtQt Version4.6.3
QtQt Version4.6.4
QtQt Version4.6.5
QtQt Version4.6.5 Updaterc
QtQt Version4.7.0
QtQt Version4.7.1
QtQt Version4.7.2
QtQt Version4.7.3
QtQt Version4.7.4
QtQt Version4.7.5
QtQt Version4.7.6
QtQt Version4.7.6 Updaterc
QtQt Version4.8.0
QtQt Version4.8.1
QtQt Version4.8.2
CanonicalUbuntu Linux Version10.04 Update- Editionlts
CanonicalUbuntu Linux Version11.10
CanonicalUbuntu Linux Version12.04 Update- Editionlts
CanonicalUbuntu Linux Version12.10
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.47% 0.791
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.