5.9

CVE-2024-39936

An issue was discovered in HTTP2 in Qt before 5.15.18, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.7, and 6.6.x through 6.7.x before 6.7.3. Code to make security-relevant decisions about an established connection may execute too early, because the encrypted() signal has not yet been emitted and processed..
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Qt ≫ Qt Version < 5.15.18
Qt ≫ Qt Version >= 6.0.0 < 6.2.13
Qt ≫ Qt Version >= 6.3.0 < 6.5.7
Qt ≫ Qt Version >= 6.6.0 < 6.7.3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.49% 0.395
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.9 2.2 3.6
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
MITRE 8.6 3.9 4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition

The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check.

https://codereview.qt-project.org/c/qt/qtbase/+/571601
Vendor Advisory
https://lists.debian.org/debian-lts-announce/2025/11/msg00031.html