Vulnerabilities > QT > QT > 4.3.4

DATE CVE VULNERABILITY TITLE RISK
2012-06-29 CVE-2010-5076 Improper Input Validation vulnerability in multiple products
QSslSocket in Qt before 4.7.0-rc1 recognizes a wildcard IP address in the subject's Common Name field of an X.509 certificate, which might allow man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority.
network
digia qt CWE-20
4.3
2012-06-16 CVE-2011-3193 Out-Of-Bounds Write vulnerability in multiple products
Heap-based buffer overflow in the Lookup_MarkMarkPos function in the HarfBuzz module (harfbuzz-gpos.c), as used by Qt before 4.7.4 and Pango, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted font file.
9.3
2010-07-02 CVE-2010-2621 Improper Input Validation vulnerability in multiple products
The QSslSocketBackendPrivate::transmit function in src_network_ssl_qsslsocket_openssl.cpp in Qt 4.6.3 and earlier allows remote attackers to cause a denial of service (infinite loop) via a malformed request.
network
low complexity
qt digia CWE-20
5.0
2009-09-02 CVE-2009-2700 Improper Input Validation vulnerability in QT
src/network/ssl/qsslcertificate.cpp in Nokia Trolltech Qt 4.x does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
network
qt CWE-20
4.3