Qt 5.9.10

CPE Details

Qt 5.9.10
5.9.10
2020-09-22
13h34 +00:00
2020-09-22
13h34 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:qt:qt:5.9.10:*:*:*:*:*:*:*

Informations

Vendor

qt

Product

qt

Version

5.9.10

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2024-39936 2024-07-03 22h00 +00:00 An issue was discovered in HTTP2 in Qt before 5.15.18, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.7, and 6.6.x through 6.7.x before 6.7.3. Code to make security-relevant decisions about an established connection may execute too early, because the encrypted() signal has not yet been emitted and processed..
8.6
High
CVE-2023-51714 2023-12-23 23h00 +00:00 An issue was discovered in the HTTP2 implementation in Qt before 5.15.17, 6.x before 6.2.11, 6.3.x through 6.5.x before 6.5.4, and 6.6.x before 6.6.2. network/access/http2/hpacktable.cpp has an incorrect HPack integer overflow check.
9.8
Critical
CVE-2023-43114 2023-09-17 22h00 +00:00 An issue was discovered in Qt before 5.15.16, 6.x before 6.2.10, and 6.3.x through 6.5.x before 6.5.3 on Windows. When using the GDI font engine, if a corrupted font is loaded via QFontDatabase::addApplicationFont{FromData], then it can cause the application to crash because of missing length checks.
5.5
Medium
CVE-2023-37369 2023-08-19 22h00 +00:00 In Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.2, there can be an application crash in QXmlStreamReader via a crafted XML string that triggers a situation in which a prefix is greater than a length.
7.5
High
CVE-2023-38197 2023-07-12 22h00 +00:00 An issue was discovered in Qt before 5.15.15, 6.x before 6.2.10, and 6.3.x through 6.5.x before 6.5.3. There are infinite loops in recursive entity expansion.
7.5
High
CVE-2023-34410 2023-06-04 22h00 +00:00 An issue was discovered in Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.2. Certificate validation for TLS does not always consider whether the root of a chain is a configured CA certificate.
5.3
Medium
CVE-2023-32762 2023-05-27 22h00 +00:00 An issue was discovered in Qt before 5.15.14, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1. Qt Network incorrectly parses the strict-transport-security (HSTS) header, allowing unencrypted connections to be established, even when explicitly prohibited by the server. This happens if the case used for this header does not exactly match.
5.3
Medium
CVE-2023-32763 2023-05-27 22h00 +00:00 An issue was discovered in Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1. When a SVG file with an image inside it is rendered, a QTextLayout buffer overflow can be triggered.
7.5
High
CVE-2023-33285 2023-05-21 22h00 +00:00 An issue was discovered in Qt 5.x before 5.15.14, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1. QDnsLookup has a buffer over-read via a crafted reply from a DNS server.
5.3
Medium
CVE-2023-32573 2023-05-10 00h00 +00:00 In Qt before 5.15.14, 6.0.x through 6.2.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1, QtSvg QSvgFont m_unitsPerEm initialization is mishandled.
6.5
Medium
CVE-2023-24607 2023-04-14 22h00 +00:00 Qt before 6.4.3 allows a denial of service via a crafted string when the SQL ODBC driver plugin is used and the size of SQLTCHAR is 4. The affected versions are 5.x before 5.15.13, 6.x before 6.2.8, and 6.3.x before 6.4.3.
7.5
High
CVE-2022-25634 2022-03-02 13h27 +00:00 Qt through 5.15.8 and 6.x through 6.2.3 can load system library files from an unintended working directory.
7.5
High
CVE-2022-25255 2022-02-16 17h48 +00:00 In Qt 5.9.x through 5.15.x before 5.15.9 and 6.x before 6.2.4 on Linux and UNIX, QProcess could execute a binary from the current working directory when not found in the PATH.
7.8
High
CVE-2021-38593 2021-08-11 22h00 +00:00 Qt 5.x before 5.15.6 and 6.x through 6.1.2 has an out-of-bounds write in QOutlineMapper::convertPath (called from QRasterPaintEngine::fill and QPaintEngineEx::stroke).
7.5
High
CVE-2020-24742 2021-08-09 19h18 +00:00 An issue has been fixed in Qt versions 5.14.0 where QPluginLoader attempts to load plugins relative to the working directory, allowing attackers to execute arbitrary code via crafted files.
7.8
High
CVE-2020-0569 2020-11-22 23h00 +00:00 Out of bounds write in Intel(R) PROSet/Wireless WiFi products on Windows 10 may allow an authenticated user to potentially enable denial of service via local access.
5.7
Medium
CVE-2020-17507 2020-08-12 15h35 +00:00 An issue was discovered in Qt through 5.12.9, and 5.13.x through 5.15.x before 5.15.1. read_xbm_body in gui/image/qxbmhandler.cpp has a buffer over-read.
5.3
Medium
CVE-2018-21035 2020-02-28 18h17 +00:00 In Qt through 5.14.1, the WebSocket implementation accepts up to 2GB for frames and 2GB for messages. Smaller limits cannot be configured. This makes it easier for attackers to cause a denial of service (memory consumption).
7.5
High
CVE-2015-9541 2020-01-24 20h53 +00:00 Qt through 5.14 allows an exponential XML entity expansion attack via a crafted SVG document that is mishandled in QXmlStreamReader, a related issue to CVE-2003-1564.
7.5
High
CVE-2018-15518 2018-12-26 19h00 +00:00 QXmlStream in Qt 5.x before 5.11.3 has a double-free or corruption during parsing of a specially crafted illegal XML document.
8.8
High
CVE-2018-19869 2018-12-26 19h00 +00:00 An issue was discovered in Qt before 5.11.3. A malformed SVG image causes a segmentation fault in qsvghandler.cpp.
6.5
Medium
CVE-2018-19870 2018-12-26 19h00 +00:00 An issue was discovered in Qt before 5.11.3. A malformed GIF image causes a NULL pointer dereference in QGifHandler resulting in a segmentation fault.
8.8
High
CVE-2018-19871 2018-12-26 19h00 +00:00 An issue was discovered in Qt before 5.11.3. There is QTgaFile Uncontrolled Resource Consumption.
6.5
Medium