- EPSS 10.54%
- Veröffentlicht 02.07.2010 20:30:01
- Zuletzt bearbeitet 16.06.2026 23:21:05
The QSslSocketBackendPrivate::transmit function in src_network_ssl_qsslsocket_openssl.cpp in Qt 4.6.3 and earlier allows remote attackers to cause a denial of service (infinite loop) via a malformed request.
CVE-2009-2700
- EPSS 0.94%
- Veröffentlicht 02.09.2009 17:30:00
- Zuletzt bearbeitet 16.06.2026 23:10:03
src/network/ssl/qsslcertificate.cpp in Nokia Trolltech Qt 4.x does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL se...
CVE-2007-0242
- EPSS 2.05%
- Veröffentlicht 03.04.2007 16:19:00
- Zuletzt bearbeitet 16.06.2026 22:35:11
The UTF-8 decoder in codecs/qutfcodec.cpp in Qt 3.3.8 and 4.2.3 does not reject long UTF-8 sequences as required by the standard, which allows remote attackers to conduct cross-site scripting (XSS) and directory traversal attacks via long sequences t...
CVE-2006-4811
- EPSS 4.25%
- Veröffentlicht 18.10.2006 17:07:00
- Zuletzt bearbeitet 16.06.2026 22:29:50
Integer overflow in Qt 3.3 before 3.3.7, 4.1 before 4.1.5, and 4.2 before 4.2.1, as used in the KDE khtml library, kdelibs 3.1.3, and possibly other packages, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary...