CVE-2018-21035
- EPSS 0.44%
- Veröffentlicht 28.02.2020 21:15:12
- Zuletzt bearbeitet 21.11.2024 04:02:44
In Qt through 5.14.1, the WebSocket implementation accepts up to 2GB for frames and 2GB for messages. Smaller limits cannot be configured. This makes it easier for attackers to cause a denial of service (memory consumption).
CVE-2015-9541
- EPSS 1.07%
- Veröffentlicht 24.01.2020 22:15:12
- Zuletzt bearbeitet 21.11.2024 02:40:53
Qt through 5.14 allows an exponential XML entity expansion attack via a crafted SVG document that is mishandled in QXmlStreamReader, a related issue to CVE-2003-1564.
CVE-2018-19872
- EPSS 0.28%
- Veröffentlicht 21.03.2019 16:00:32
- Zuletzt bearbeitet 21.11.2024 03:58:43
An issue was discovered in Qt 5.11. A malformed PPM image causes a division by zero and a crash in qppmhandler.cpp.
CVE-2018-19873
- EPSS 13.42%
- Veröffentlicht 26.12.2018 21:29:02
- Zuletzt bearbeitet 11.02.2025 20:11:38
An issue was discovered in Qt before 5.11.3. QBmpHandler has a buffer overflow via BMP data.
CVE-2018-19871
- EPSS 1.54%
- Veröffentlicht 26.12.2018 21:29:02
- Zuletzt bearbeitet 21.11.2024 03:58:43
An issue was discovered in Qt before 5.11.3. There is QTgaFile Uncontrolled Resource Consumption.
CVE-2018-19870
- EPSS 2.62%
- Veröffentlicht 26.12.2018 21:29:02
- Zuletzt bearbeitet 21.11.2024 03:58:43
An issue was discovered in Qt before 5.11.3. A malformed GIF image causes a NULL pointer dereference in QGifHandler resulting in a segmentation fault.
CVE-2018-19869
- EPSS 0.91%
- Veröffentlicht 26.12.2018 21:29:02
- Zuletzt bearbeitet 21.11.2024 03:58:43
An issue was discovered in Qt before 5.11.3. A malformed SVG image causes a segmentation fault in qsvghandler.cpp.
CVE-2018-15518
- EPSS 2.18%
- Veröffentlicht 26.12.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:50:59
QXmlStream in Qt 5.x before 5.11.3 has a double-free or corruption during parsing of a specially crafted illegal XML document.
CVE-2018-19865
- EPSS 0.8%
- Veröffentlicht 05.12.2018 11:29:06
- Zuletzt bearbeitet 21.11.2024 03:58:43
A keystroke logging issue was discovered in Virtual Keyboard in Qt 5.7.x, 5.8.x, 5.9.x, 5.10.x, and 5.11.x before 5.11.3.
CVE-2015-1290
- EPSS 1.04%
- Veröffentlicht 09.01.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 02:25:05
The Google V8 engine, as used in Google Chrome before 44.0.2403.89 and QtWebEngineCore in Qt before 5.5.1, allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a crafted web site.