rpm package
suse/libqt5-qtbase&distro=SUSE Linux Enterprise Server for SAP Applications 12 SP5
pkg:rpm/suse/libqt5-qtbase&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5
Vulnerabilities (9)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2023-38197 | — | < 5.6.2-6.36.1 | 5.6.2-6.36.1 | Jul 13, 2023 | An issue was discovered in Qt before 5.15.15, 6.x before 6.2.10, and 6.3.x through 6.5.x before 6.5.3. There are infinite loops in recursive entity expansion. | ||
| CVE-2023-34410 | — | < 5.6.2-6.36.1 | 5.6.2-6.36.1 | Jun 5, 2023 | An issue was discovered in Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.2. Certificate validation for TLS does not always consider whether the root of a chain is a configured CA certificate. | ||
| CVE-2023-32763 | — | < 5.6.2-6.33.1 | 5.6.2-6.33.1 | May 28, 2023 | An issue was discovered in Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1. When a SVG file with an image inside it is rendered, a QTextLayout buffer overflow can be triggered. | ||
| CVE-2023-33285 | — | < 5.6.2-6.36.1 | 5.6.2-6.36.1 | May 22, 2023 | An issue was discovered in Qt 5.x before 5.15.14, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1. QDnsLookup has a buffer over-read via a crafted reply from a DNS server. | ||
| CVE-2023-24607 | — | < 5.6.2-6.36.1 | 5.6.2-6.36.1 | Apr 15, 2023 | Qt before 6.4.3 allows a denial of service via a crafted string when the SQL ODBC driver plugin is used and the size of SQLTCHAR is 4. The affected versions are 5.x before 5.15.13, 6.x before 6.2.8, and 6.3.x before 6.4.3. | ||
| CVE-2020-0569 | — | < 5.6.2-6.22.1 | 5.6.2-6.22.1 | Nov 23, 2020 | Out of bounds write in Intel(R) PROSet/Wireless WiFi products on Windows 10 may allow an authenticated user to potentially enable denial of service via local access. | ||
| CVE-2020-17507 | — | < 5.6.2-6.25.1 | 5.6.2-6.25.1 | Aug 12, 2020 | An issue was discovered in Qt through 5.12.9, and 5.13.x through 5.15.x before 5.15.1. read_xbm_body in gui/image/qxbmhandler.cpp has a buffer over-read. | ||
| CVE-2018-19872 | — | < 5.6.2-6.22.1 | 5.6.2-6.22.1 | Mar 15, 2019 | An issue was discovered in Qt 5.11. A malformed PPM image causes a division by zero and a crash in qppmhandler.cpp. | ||
| CVE-2018-19870 | — | < 5.6.2-6.22.1 | 5.6.2-6.22.1 | Dec 26, 2018 | An issue was discovered in Qt before 5.11.3. A malformed GIF image causes a NULL pointer dereference in QGifHandler resulting in a segmentation fault. |
- CVE-2023-38197Jul 13, 2023affected < 5.6.2-6.36.1fixed 5.6.2-6.36.1
An issue was discovered in Qt before 5.15.15, 6.x before 6.2.10, and 6.3.x through 6.5.x before 6.5.3. There are infinite loops in recursive entity expansion.
- CVE-2023-34410Jun 5, 2023affected < 5.6.2-6.36.1fixed 5.6.2-6.36.1
An issue was discovered in Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.2. Certificate validation for TLS does not always consider whether the root of a chain is a configured CA certificate.
- CVE-2023-32763May 28, 2023affected < 5.6.2-6.33.1fixed 5.6.2-6.33.1
An issue was discovered in Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1. When a SVG file with an image inside it is rendered, a QTextLayout buffer overflow can be triggered.
- CVE-2023-33285May 22, 2023affected < 5.6.2-6.36.1fixed 5.6.2-6.36.1
An issue was discovered in Qt 5.x before 5.15.14, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1. QDnsLookup has a buffer over-read via a crafted reply from a DNS server.
- CVE-2023-24607Apr 15, 2023affected < 5.6.2-6.36.1fixed 5.6.2-6.36.1
Qt before 6.4.3 allows a denial of service via a crafted string when the SQL ODBC driver plugin is used and the size of SQLTCHAR is 4. The affected versions are 5.x before 5.15.13, 6.x before 6.2.8, and 6.3.x before 6.4.3.
- CVE-2020-0569Nov 23, 2020affected < 5.6.2-6.22.1fixed 5.6.2-6.22.1
Out of bounds write in Intel(R) PROSet/Wireless WiFi products on Windows 10 may allow an authenticated user to potentially enable denial of service via local access.
- CVE-2020-17507Aug 12, 2020affected < 5.6.2-6.25.1fixed 5.6.2-6.25.1
An issue was discovered in Qt through 5.12.9, and 5.13.x through 5.15.x before 5.15.1. read_xbm_body in gui/image/qxbmhandler.cpp has a buffer over-read.
- CVE-2018-19872Mar 15, 2019affected < 5.6.2-6.22.1fixed 5.6.2-6.22.1
An issue was discovered in Qt 5.11. A malformed PPM image causes a division by zero and a crash in qppmhandler.cpp.
- CVE-2018-19870Dec 26, 2018affected < 5.6.2-6.22.1fixed 5.6.2-6.22.1
An issue was discovered in Qt before 5.11.3. A malformed GIF image causes a NULL pointer dereference in QGifHandler resulting in a segmentation fault.