Show filters
92 Total Results
Displaying 31-40 of 92
Sort by:
Attacker Value
Unknown

CVE-2020-13849

Disclosure Date: June 04, 2020 (last updated November 28, 2024)
The MQTT protocol 3.1.1 requires a server to set a timeout value of 1.5 times the Keep-Alive value specified by a client, which allows remote attackers to cause a denial of service (loss of the ability to establish new connections), as demonstrated by SlowITe.
Attacker Value
Unknown

CVE-2020-12267

Disclosure Date: April 27, 2020 (last updated November 27, 2024)
setMarkdown in Qt before 5.14.2 has a use-after-free related to QTextMarkdownImporter::insertBlock.
Attacker Value
Unknown

CVE-2018-21035

Disclosure Date: February 28, 2020 (last updated November 28, 2024)
In Qt through 5.14.1, the WebSocket implementation accepts up to 2GB for frames and 2GB for messages. Smaller limits cannot be configured. This makes it easier for attackers to cause a denial of service (memory consumption).
Attacker Value
Unknown

CVE-2015-9541

Disclosure Date: January 24, 2020 (last updated November 08, 2023)
Qt through 5.14 allows an exponential XML entity expansion attack via a crafted SVG document that is mishandled in QXmlStreamReader, a related issue to CVE-2003-1564.
Attacker Value
Unknown

CVE-2011-2916

Disclosure Date: November 15, 2019 (last updated November 27, 2024)
qtnx 0.9 stores non-custom SSH keys in a world-readable configuration file. If a user has a world-readable or world-executable home directory, another local system user could obtain the private key used to connect to remote NX sessions.
Attacker Value
Unknown

CVE-2018-19151

Disclosure Date: October 29, 2019 (last updated November 08, 2023)
qtum through 0.16 (a chain-based proof-of-stake cryptocurrency) allows a remote denial of service. The attacker sends invalid headers/blocks. The attack requires no stake and can fill the victim's disk and RAM.
Attacker Value
Unknown

CVE-2010-3375

Disclosure Date: October 29, 2019 (last updated November 27, 2024)
qtparted has insecure library loading which may allow arbitrary code execution
Attacker Value
Unknown

CVE-2019-18281

Disclosure Date: October 23, 2019 (last updated November 27, 2024)
An out-of-bounds memory access in the generateDirectionalRuns() function in qtextengine.cpp in Qt qtbase 5.11.x and 5.12.x before 5.12.5 allows attackers to cause a denial of service by crashing an application via a text file containing many directional characters.
Attacker Value
Unknown

CVE-2015-9431

Disclosure Date: September 26, 2019 (last updated November 27, 2024)
The qtranslate-x plugin before 3.4.4 for WordPress has CSRF with resultant XSS via the wp-admin/options-general.php?page=qtranslate-x json_config_files or json_custom_i18n_config parameter.
Attacker Value
Unknown

CVE-2019-5432

Disclosure Date: May 06, 2019 (last updated November 27, 2024)
A specifically malformed MQTT Subscribe packet crashes MQTT Brokers using the mqtt-packet module versions < 3.5.1, 4.0.0 - 4.1.3, 5.0.0 - 5.6.1, 6.0.0 - 6.1.2 for decoding.