Qt kayıtları
qt üreticisine ait 64 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 11
- Düzeltme kaydı olan
- %87,5
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer9
- CWE-20 Improper Input Validation6
- CWE-787 Out-of-bounds Write4
- CWE-190 Integer Overflow or Wraparound3
- CWE-125 Out-of-bounds Read3
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
64 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2018-19873İstismar yok | An issue was discovered in Qt before 5.11.3.qt · qt · CWE-119 | Kritik9,8 | — | %3,4 | 26 Ara 2018 |
40Planlayın | CVE-2020-12267İstismar yok | setMarkdown in Qt before 5.14.2 has a use-after-free related to QTextMarkdownImporter::insertBlock.qt · qt · CWE-416 | Kritik9,8 | — | %2,4 | 26 Nis 2020 |
40Planlayın | CVE-2017-10904İstismar yok | Qt for Android prior to 5.9.0 allows remote attackers to execute arbitrary OS commands via unspecified vectors.qt · qt · CWE-78 | Kritik9,8 | — | %2,0 | 15 Ara 2017 |
39İzleyin | CVE-2011-3193İstismar yok | Heap-based buffer overflow in the Lookup_MarkMarkPos function in the HarfBuzz module (harfbuzz-gpos.c), as used by Qt before 4.7.4 and Pangoqt · qt · CWE-787 | Kritik9,3 | — | %7,3 | 15 Haz 2012 |
39İzleyin | CVE-2011-3194İstismar yok | Buffer overflow in the TIFF reader in gui/image/qtiffhandler.cpp in Qt 4.7.4 allows remote attackers to cause a denial of service (crash) anqt · qt · CWE-119 | Kritik9,3 | — | %7,0 | 15 Haz 2012 |
39İzleyin | CVE-2023-51714İstismar yok | An issue was discovered in the HTTP2 implementation in Qt before 5.15.17, 6.x before 6.2.11, 6.3.x through 6.5.x before 6.5.4, and 6.6.x befqt · qt · CWE-190 | Kritik9,8 | — | %1,0 | 24 Ara 2023 |
39İzleyin | CVE-2024-36048İstismar yok | QAbstractOAuth in Qt Network Authorization in Qt before 5.15.17, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.6, and 6.6.x through 6.7.qt · qt · CWE-335 | Kritik9,8 | — | %1,0 | 18 May 2024 |
36İzleyin | CVE-2015-1290İstismar yok | The Google V8 engine, as used in Google Chrome before 44.0.2403.89 and QtWebEngineCore in Qt before 5.5.1, allows remote attackers to cause google · chrome · CWE-119 | Yüksek8,8 | — | %3,3 | 9 Oca 2018 |
36İzleyin | CVE-2018-15518İstismar yok | QXmlStream in Qt 5.x before 5.11.3 has a double-free or corruption during parsing of a specially crafted illegal XML document.qt · qt · CWE-415 | Yüksek8,8 | — | %2,5 | 26 Ara 2018 |
36İzleyin | CVE-2018-19870İstismar yok | An issue was discovered in Qt before 5.11.3.qt · qt · CWE-476 | Yüksek8,8 | — | %2,4 | 26 Ara 2018 |
35İzleyin | CVE-2022-43591İstismar yok | A buffer overflow vulnerability exists in the QML QtScript Reflect API of Qt Project Qt 6.3.2.qt · qt · CWE-122 | Yüksek8,8 | — | %1,1 | 12 Oca 2023 |
35İzleyin | CVE-2022-40983İstismar yok | An integer overflow vulnerability exists in the QML QtScript Reflect API of Qt Project Qt 6.3.2.qt · qt · CWE-190 | Yüksek8,8 | — | %1,1 | 12 Oca 2023 |
31İzleyin | CVE-2021-38593İstismar yok | Qt 5.x before 5.15.6 and 6.x through 6.1.2 has an out-of-bounds write in QOutlineMapper::convertPath (called from QRasterPaintEngine::fill aqt · qt · CWE-787 | Yüksek7,5 | — | %3,0 | 11 Ağu 2021 |
31İzleyin | CVE-2020-13962İstismar yok | Qt 5.12.2 through 5.14.2, as used in unofficial builds of Mumble 1.3.0 and other products, mishandles OpenSSL's error queue, which can causemumble · mumble | Yüksek7,5 | — | %3,0 | 8 Haz 2020 |
31İzleyin | CVE-2015-9541İstismar yok | Qt through 5.14 allows an exponential XML entity expansion attack via a crafted SVG document that is mishandled in QXmlStreamReader, a relatqt · qt · CWE-776 | Yüksek7,5 | — | %2,5 | 24 Oca 2020 |
31İzleyin | CVE-2018-21035İstismar yok | In Qt through 5.14.1, the WebSocket implementation accepts up to 2GB for frames and 2GB for messages.qt · qt · CWE-770 | Yüksek7,5 | — | %2,3 | 28 Şub 2020 |
31İzleyin | CVE-2018-19865İstismar yok | A keystroke logging issue was discovered in Virtual Keyboard in Qt 5.7.x, 5.8.x, 5.9.x, 5.10.x, and 5.11.x before 5.11.3.qt · qt · CWE-532 | Yüksek7,5 | — | %2,2 | 5 Ara 2018 |
31İzleyin | CVE-2022-25634İstismar yok | Qt through 5.15.8 and 6.x through 6.2.3 can load system library files from an unintended working directory.qt · qt · CWE-22 | Yüksek7,5 | — | %2,0 | 2 Mar 2022 |
31İzleyin | CVE-2020-24742İstismar yok | An issue has been fixed in Qt versions 5.14.0 where QPluginLoader attempts to load plugins relative to the working directory, allowing attacqt · qt | Yüksek7,8 | — | %1,2 | 9 Ağu 2021 |
31İzleyin | CVE-2022-25255İstismar yok | In Qt 5.9.x through 5.15.x before 5.15.9 and 6.x before 6.2.4 on Linux and UNIX, QProcess could execute a binary from the current working diqt · qt | Yüksek7,8 | — | %0,3 | 16 Şub 2022 |
30İzleyin | CVE-2015-1860İstismar yok | Multiple buffer overflows in gui/image/qgifhandler.cpp in the QtBase module in Qt before 4.8.7 and 5.x before 5.4.2 allow remote attackers tqt · qt · CWE-119 | Orta6,8 | — | %8,7 | 12 May 2015 |
30İzleyin | CVE-2023-37369İstismar yok | In Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.2, there can be an application crash in QXmlStreamReader via a crqt · qt | Yüksek7,5 | — | %1,6 | 20 Ağu 2023 |
30İzleyin | CVE-2017-15011İstismar yok | The named pipes in qtsingleapp in Qt 5.x, as used in qBittorrent and SugarSync, are configured for remote access and allow remote attackers qt · qt · CWE-119 | Yüksek7,5 | — | %1,4 | 3 Eki 2017 |
30İzleyin | CVE-2023-24607İstismar yok | Qt before 6.4.3 allows a denial of service via a crafted string when the SQL ODBC driver plugin is used and the size of SQLTCHAR is 4.qt · qt | Yüksek7,5 | — | %1,3 | 14 Nis 2023 |
30İzleyin | CVE-2023-32763İstismar yok | An issue was discovered in Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1.qt · qt · CWE-120 | Yüksek7,5 | — | %1,3 | 28 May 2023 |
- CVE-2018-1987340Planlayın
An issue was discovered in Qt before 5.11.3.
KritikCVSS 9,8İstismar yokEPSS %3qt · qt26 Ara 2018
- CVE-2020-1226740Planlayın
setMarkdown in Qt before 5.14.2 has a use-after-free related to QTextMarkdownImporter::insertBlock.
KritikCVSS 9,8İstismar yokEPSS %2qt · qt26 Nis 2020
- CVE-2017-1090440Planlayın
Qt for Android prior to 5.9.0 allows remote attackers to execute arbitrary OS commands via unspecified vectors.
KritikCVSS 9,8İstismar yokEPSS %2qt · qt15 Ara 2017
- CVE-2011-319339İzleyin
Heap-based buffer overflow in the Lookup_MarkMarkPos function in the HarfBuzz module (harfbuzz-gpos.c), as used by Qt before 4.7.4 and Pango
KritikCVSS 9,3İstismar yokEPSS %7qt · qt15 Haz 2012
- CVE-2011-319439İzleyin
Buffer overflow in the TIFF reader in gui/image/qtiffhandler.cpp in Qt 4.7.4 allows remote attackers to cause a denial of service (crash) an
KritikCVSS 9,3İstismar yokEPSS %7qt · qt15 Haz 2012
- CVE-2023-5171439İzleyin
An issue was discovered in the HTTP2 implementation in Qt before 5.15.17, 6.x before 6.2.11, 6.3.x through 6.5.x before 6.5.4, and 6.6.x bef
KritikCVSS 9,8İstismar yokEPSS %1qt · qt24 Ara 2023
- CVE-2024-3604839İzleyin
QAbstractOAuth in Qt Network Authorization in Qt before 5.15.17, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.6, and 6.6.x through 6.7.
KritikCVSS 9,8İstismar yokEPSS %1qt · qt18 May 2024
- CVE-2015-129036İzleyin
The Google V8 engine, as used in Google Chrome before 44.0.2403.89 and QtWebEngineCore in Qt before 5.5.1, allows remote attackers to cause
YüksekCVSS 8,8İstismar yokEPSS %3google · chrome9 Oca 2018
- CVE-2018-1551836İzleyin
QXmlStream in Qt 5.x before 5.11.3 has a double-free or corruption during parsing of a specially crafted illegal XML document.
YüksekCVSS 8,8İstismar yokEPSS %3qt · qt26 Ara 2018
- CVE-2018-1987036İzleyin
An issue was discovered in Qt before 5.11.3.
YüksekCVSS 8,8İstismar yokEPSS %2qt · qt26 Ara 2018
- CVE-2022-4359135İzleyin
A buffer overflow vulnerability exists in the QML QtScript Reflect API of Qt Project Qt 6.3.2.
YüksekCVSS 8,8İstismar yokEPSS %1qt · qt12 Oca 2023
- CVE-2022-4098335İzleyin
An integer overflow vulnerability exists in the QML QtScript Reflect API of Qt Project Qt 6.3.2.
YüksekCVSS 8,8İstismar yokEPSS %1qt · qt12 Oca 2023
- CVE-2021-3859331İzleyin
Qt 5.x before 5.15.6 and 6.x through 6.1.2 has an out-of-bounds write in QOutlineMapper::convertPath (called from QRasterPaintEngine::fill a
YüksekCVSS 7,5İstismar yokEPSS %3qt · qt11 Ağu 2021
- CVE-2020-1396231İzleyin
Qt 5.12.2 through 5.14.2, as used in unofficial builds of Mumble 1.3.0 and other products, mishandles OpenSSL's error queue, which can cause
YüksekCVSS 7,5İstismar yokEPSS %3mumble · mumble8 Haz 2020
- CVE-2015-954131İzleyin
Qt through 5.14 allows an exponential XML entity expansion attack via a crafted SVG document that is mishandled in QXmlStreamReader, a relat
YüksekCVSS 7,5İstismar yokEPSS %2qt · qt24 Oca 2020
- CVE-2018-2103531İzleyin
In Qt through 5.14.1, the WebSocket implementation accepts up to 2GB for frames and 2GB for messages.
YüksekCVSS 7,5İstismar yokEPSS %2qt · qt28 Şub 2020
- CVE-2018-1986531İzleyin
A keystroke logging issue was discovered in Virtual Keyboard in Qt 5.7.x, 5.8.x, 5.9.x, 5.10.x, and 5.11.x before 5.11.3.
YüksekCVSS 7,5İstismar yokEPSS %2qt · qt5 Ara 2018
- CVE-2022-2563431İzleyin
Qt through 5.15.8 and 6.x through 6.2.3 can load system library files from an unintended working directory.
YüksekCVSS 7,5İstismar yokEPSS %2qt · qt2 Mar 2022
- CVE-2020-2474231İzleyin
An issue has been fixed in Qt versions 5.14.0 where QPluginLoader attempts to load plugins relative to the working directory, allowing attac
YüksekCVSS 7,8İstismar yokEPSS %1qt · qt9 Ağu 2021
- CVE-2022-2525531İzleyin
In Qt 5.9.x through 5.15.x before 5.15.9 and 6.x before 6.2.4 on Linux and UNIX, QProcess could execute a binary from the current working di
YüksekCVSS 7,8İstismar yokEPSS %0qt · qt16 Şub 2022
- CVE-2015-186030İzleyin
Multiple buffer overflows in gui/image/qgifhandler.cpp in the QtBase module in Qt before 4.8.7 and 5.x before 5.4.2 allow remote attackers t
OrtaCVSS 6,8İstismar yokEPSS %9qt · qt12 May 2015
- CVE-2023-3736930İzleyin
In Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.2, there can be an application crash in QXmlStreamReader via a cr
YüksekCVSS 7,5İstismar yokEPSS %2qt · qt20 Ağu 2023
- CVE-2017-1501130İzleyin
The named pipes in qtsingleapp in Qt 5.x, as used in qBittorrent and SugarSync, are configured for remote access and allow remote attackers
YüksekCVSS 7,5İstismar yokEPSS %1qt · qt3 Eki 2017
- CVE-2023-2460730İzleyin
Qt before 6.4.3 allows a denial of service via a crafted string when the SQL ODBC driver plugin is used and the size of SQLTCHAR is 4.
YüksekCVSS 7,5İstismar yokEPSS %1qt · qt14 Nis 2023
- CVE-2023-3276330İzleyin
An issue was discovered in Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1.
YüksekCVSS 7,5İstismar yokEPSS %1qt · qt28 May 2023