Записи Qt
64 опубликованных записей вендора qt.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 11
- С записью об исправлении
- 87,5 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer9
- CWE-20 Improper Input Validation6
- CWE-787 Out-of-bounds Write4
- CWE-190 Integer Overflow or Wraparound3
- CWE-125 Out-of-bounds Read3
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
64 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2018-19873Эксплойта нет | An issue was discovered in Qt before 5.11.3.qt · qt · CWE-119 | Критическая9,8 | — | 3,4 % | 26 дек. 2018 г. |
40В плане | CVE-2020-12267Эксплойта нет | setMarkdown in Qt before 5.14.2 has a use-after-free related to QTextMarkdownImporter::insertBlock.qt · qt · CWE-416 | Критическая9,8 | — | 2,4 % | 26 апр. 2020 г. |
40В плане | CVE-2017-10904Эксплойта нет | Qt for Android prior to 5.9.0 allows remote attackers to execute arbitrary OS commands via unspecified vectors.qt · qt · CWE-78 | Критическая9,8 | — | 2,0 % | 15 дек. 2017 г. |
39Наблюдать | CVE-2011-3193Эксплойта нет | Heap-based buffer overflow in the Lookup_MarkMarkPos function in the HarfBuzz module (harfbuzz-gpos.c), as used by Qt before 4.7.4 and Pangoqt · qt · CWE-787 | Критическая9,3 | — | 7,3 % | 15 июн. 2012 г. |
39Наблюдать | CVE-2011-3194Эксплойта нет | Buffer overflow in the TIFF reader in gui/image/qtiffhandler.cpp in Qt 4.7.4 allows remote attackers to cause a denial of service (crash) anqt · qt · CWE-119 | Критическая9,3 | — | 7,0 % | 15 июн. 2012 г. |
39Наблюдать | CVE-2023-51714Эксплойта нет | An issue was discovered in the HTTP2 implementation in Qt before 5.15.17, 6.x before 6.2.11, 6.3.x through 6.5.x before 6.5.4, and 6.6.x befqt · qt · CWE-190 | Критическая9,8 | — | 1,0 % | 24 дек. 2023 г. |
39Наблюдать | CVE-2024-36048Эксплойта нет | QAbstractOAuth in Qt Network Authorization in Qt before 5.15.17, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.6, and 6.6.x through 6.7.qt · qt · CWE-335 | Критическая9,8 | — | 1,0 % | 18 мая 2024 г. |
36Наблюдать | CVE-2015-1290Эксплойта нет | The Google V8 engine, as used in Google Chrome before 44.0.2403.89 and QtWebEngineCore in Qt before 5.5.1, allows remote attackers to cause google · chrome · CWE-119 | Высокая8,8 | — | 3,3 % | 9 янв. 2018 г. |
36Наблюдать | CVE-2018-15518Эксплойта нет | QXmlStream in Qt 5.x before 5.11.3 has a double-free or corruption during parsing of a specially crafted illegal XML document.qt · qt · CWE-415 | Высокая8,8 | — | 2,5 % | 26 дек. 2018 г. |
36Наблюдать | CVE-2018-19870Эксплойта нет | An issue was discovered in Qt before 5.11.3.qt · qt · CWE-476 | Высокая8,8 | — | 2,4 % | 26 дек. 2018 г. |
35Наблюдать | CVE-2022-43591Эксплойта нет | A buffer overflow vulnerability exists in the QML QtScript Reflect API of Qt Project Qt 6.3.2.qt · qt · CWE-122 | Высокая8,8 | — | 1,1 % | 12 янв. 2023 г. |
35Наблюдать | CVE-2022-40983Эксплойта нет | An integer overflow vulnerability exists in the QML QtScript Reflect API of Qt Project Qt 6.3.2.qt · qt · CWE-190 | Высокая8,8 | — | 1,1 % | 12 янв. 2023 г. |
31Наблюдать | CVE-2021-38593Эксплойта нет | Qt 5.x before 5.15.6 and 6.x through 6.1.2 has an out-of-bounds write in QOutlineMapper::convertPath (called from QRasterPaintEngine::fill aqt · qt · CWE-787 | Высокая7,5 | — | 3,0 % | 11 авг. 2021 г. |
31Наблюдать | CVE-2020-13962Эксплойта нет | Qt 5.12.2 through 5.14.2, as used in unofficial builds of Mumble 1.3.0 and other products, mishandles OpenSSL's error queue, which can causemumble · mumble | Высокая7,5 | — | 3,0 % | 8 июн. 2020 г. |
31Наблюдать | CVE-2015-9541Эксплойта нет | Qt through 5.14 allows an exponential XML entity expansion attack via a crafted SVG document that is mishandled in QXmlStreamReader, a relatqt · qt · CWE-776 | Высокая7,5 | — | 2,5 % | 24 янв. 2020 г. |
31Наблюдать | CVE-2018-21035Эксплойта нет | In Qt through 5.14.1, the WebSocket implementation accepts up to 2GB for frames and 2GB for messages.qt · qt · CWE-770 | Высокая7,5 | — | 2,3 % | 28 февр. 2020 г. |
31Наблюдать | CVE-2018-19865Эксплойта нет | A keystroke logging issue was discovered in Virtual Keyboard in Qt 5.7.x, 5.8.x, 5.9.x, 5.10.x, and 5.11.x before 5.11.3.qt · qt · CWE-532 | Высокая7,5 | — | 2,2 % | 5 дек. 2018 г. |
31Наблюдать | CVE-2022-25634Эксплойта нет | Qt through 5.15.8 and 6.x through 6.2.3 can load system library files from an unintended working directory.qt · qt · CWE-22 | Высокая7,5 | — | 2,0 % | 2 мар. 2022 г. |
31Наблюдать | CVE-2020-24742Эксплойта нет | An issue has been fixed in Qt versions 5.14.0 where QPluginLoader attempts to load plugins relative to the working directory, allowing attacqt · qt | Высокая7,8 | — | 1,2 % | 9 авг. 2021 г. |
31Наблюдать | CVE-2022-25255Эксплойта нет | In Qt 5.9.x through 5.15.x before 5.15.9 and 6.x before 6.2.4 on Linux and UNIX, QProcess could execute a binary from the current working diqt · qt | Высокая7,8 | — | 0,3 % | 16 февр. 2022 г. |
30Наблюдать | CVE-2015-1860Эксплойта нет | Multiple buffer overflows in gui/image/qgifhandler.cpp in the QtBase module in Qt before 4.8.7 and 5.x before 5.4.2 allow remote attackers tqt · qt · CWE-119 | Средняя6,8 | — | 8,7 % | 12 мая 2015 г. |
30Наблюдать | CVE-2023-37369Эксплойта нет | In Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.2, there can be an application crash in QXmlStreamReader via a crqt · qt | Высокая7,5 | — | 1,6 % | 20 авг. 2023 г. |
30Наблюдать | CVE-2017-15011Эксплойта нет | The named pipes in qtsingleapp in Qt 5.x, as used in qBittorrent and SugarSync, are configured for remote access and allow remote attackers qt · qt · CWE-119 | Высокая7,5 | — | 1,4 % | 3 окт. 2017 г. |
30Наблюдать | CVE-2023-24607Эксплойта нет | Qt before 6.4.3 allows a denial of service via a crafted string when the SQL ODBC driver plugin is used and the size of SQLTCHAR is 4.qt · qt | Высокая7,5 | — | 1,3 % | 14 апр. 2023 г. |
30Наблюдать | CVE-2023-32763Эксплойта нет | An issue was discovered in Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1.qt · qt · CWE-120 | Высокая7,5 | — | 1,3 % | 28 мая 2023 г. |
- CVE-2018-1987340В плане
An issue was discovered in Qt before 5.11.3.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %qt · qt26 дек. 2018 г.
- CVE-2020-1226740В плане
setMarkdown in Qt before 5.14.2 has a use-after-free related to QTextMarkdownImporter::insertBlock.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %qt · qt26 апр. 2020 г.
- CVE-2017-1090440В плане
Qt for Android prior to 5.9.0 allows remote attackers to execute arbitrary OS commands via unspecified vectors.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %qt · qt15 дек. 2017 г.
- CVE-2011-319339Наблюдать
Heap-based buffer overflow in the Lookup_MarkMarkPos function in the HarfBuzz module (harfbuzz-gpos.c), as used by Qt before 4.7.4 and Pango
КритическаяCVSS 9,3Эксплойта нетEPSS 7 %qt · qt15 июн. 2012 г.
- CVE-2011-319439Наблюдать
Buffer overflow in the TIFF reader in gui/image/qtiffhandler.cpp in Qt 4.7.4 allows remote attackers to cause a denial of service (crash) an
КритическаяCVSS 9,3Эксплойта нетEPSS 7 %qt · qt15 июн. 2012 г.
- CVE-2023-5171439Наблюдать
An issue was discovered in the HTTP2 implementation in Qt before 5.15.17, 6.x before 6.2.11, 6.3.x through 6.5.x before 6.5.4, and 6.6.x bef
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %qt · qt24 дек. 2023 г.
- CVE-2024-3604839Наблюдать
QAbstractOAuth in Qt Network Authorization in Qt before 5.15.17, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.6, and 6.6.x through 6.7.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %qt · qt18 мая 2024 г.
- CVE-2015-129036Наблюдать
The Google V8 engine, as used in Google Chrome before 44.0.2403.89 and QtWebEngineCore in Qt before 5.5.1, allows remote attackers to cause
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %google · chrome9 янв. 2018 г.
- CVE-2018-1551836Наблюдать
QXmlStream in Qt 5.x before 5.11.3 has a double-free or corruption during parsing of a specially crafted illegal XML document.
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %qt · qt26 дек. 2018 г.
- CVE-2018-1987036Наблюдать
An issue was discovered in Qt before 5.11.3.
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %qt · qt26 дек. 2018 г.
- CVE-2022-4359135Наблюдать
A buffer overflow vulnerability exists in the QML QtScript Reflect API of Qt Project Qt 6.3.2.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %qt · qt12 янв. 2023 г.
- CVE-2022-4098335Наблюдать
An integer overflow vulnerability exists in the QML QtScript Reflect API of Qt Project Qt 6.3.2.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %qt · qt12 янв. 2023 г.
- CVE-2021-3859331Наблюдать
Qt 5.x before 5.15.6 and 6.x through 6.1.2 has an out-of-bounds write in QOutlineMapper::convertPath (called from QRasterPaintEngine::fill a
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %qt · qt11 авг. 2021 г.
- CVE-2020-1396231Наблюдать
Qt 5.12.2 through 5.14.2, as used in unofficial builds of Mumble 1.3.0 and other products, mishandles OpenSSL's error queue, which can cause
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %mumble · mumble8 июн. 2020 г.
- CVE-2015-954131Наблюдать
Qt through 5.14 allows an exponential XML entity expansion attack via a crafted SVG document that is mishandled in QXmlStreamReader, a relat
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %qt · qt24 янв. 2020 г.
- CVE-2018-2103531Наблюдать
In Qt through 5.14.1, the WebSocket implementation accepts up to 2GB for frames and 2GB for messages.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %qt · qt28 февр. 2020 г.
- CVE-2018-1986531Наблюдать
A keystroke logging issue was discovered in Virtual Keyboard in Qt 5.7.x, 5.8.x, 5.9.x, 5.10.x, and 5.11.x before 5.11.3.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %qt · qt5 дек. 2018 г.
- CVE-2022-2563431Наблюдать
Qt through 5.15.8 and 6.x through 6.2.3 can load system library files from an unintended working directory.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %qt · qt2 мар. 2022 г.
- CVE-2020-2474231Наблюдать
An issue has been fixed in Qt versions 5.14.0 where QPluginLoader attempts to load plugins relative to the working directory, allowing attac
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %qt · qt9 авг. 2021 г.
- CVE-2022-2525531Наблюдать
In Qt 5.9.x through 5.15.x before 5.15.9 and 6.x before 6.2.4 on Linux and UNIX, QProcess could execute a binary from the current working di
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %qt · qt16 февр. 2022 г.
- CVE-2015-186030Наблюдать
Multiple buffer overflows in gui/image/qgifhandler.cpp in the QtBase module in Qt before 4.8.7 and 5.x before 5.4.2 allow remote attackers t
СредняяCVSS 6,8Эксплойта нетEPSS 9 %qt · qt12 мая 2015 г.
- CVE-2023-3736930Наблюдать
In Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.2, there can be an application crash in QXmlStreamReader via a cr
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %qt · qt20 авг. 2023 г.
- CVE-2017-1501130Наблюдать
The named pipes in qtsingleapp in Qt 5.x, as used in qBittorrent and SugarSync, are configured for remote access and allow remote attackers
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %qt · qt3 окт. 2017 г.
- CVE-2023-2460730Наблюдать
Qt before 6.4.3 allows a denial of service via a crafted string when the SQL ODBC driver plugin is used and the size of SQLTCHAR is 4.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %qt · qt14 апр. 2023 г.
- CVE-2023-3276330Наблюдать
An issue was discovered in Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %qt · qt28 мая 2023 г.