Vulnerabilities > QT

DATE CVE VULNERABILITY TITLE RISK
2010-07-02 CVE-2010-2621 Improper Input Validation vulnerability in multiple products
The QSslSocketBackendPrivate::transmit function in src_network_ssl_qsslsocket_openssl.cpp in Qt 4.6.3 and earlier allows remote attackers to cause a denial of service (infinite loop) via a malformed request.
network
low complexity
qt digia CWE-20
5.0
2009-09-02 CVE-2009-2700 Improper Input Validation vulnerability in QT
src/network/ssl/qsslcertificate.cpp in Nokia Trolltech Qt 4.x does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
network
qt CWE-20
4.3
2006-10-18 CVE-2006-4811 Numeric Errors vulnerability in multiple products
Integer overflow in Qt 3.3 before 3.3.7, 4.1 before 4.1.5, and 4.2 before 4.2.1, as used in the KDE khtml library, kdelibs 3.1.3, and possibly other packages, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted pixmap image.
network
qt redhat CWE-189
6.8