Search CVE reports


Toggle filters

21 – 30 of 46 results


CVE-2022-25634

Medium priority
Not affected

Qt through 5.15.8 and 6.x through 6.2.3 can load system library files from an unintended working directory.

2 affected packages

qtbase-opensource-src-gles, qtbase-opensource-src

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
qtbase-opensource-src-gles Not affected Not affected Not affected Not affected
qtbase-opensource-src Not affected Not affected Not affected Not affected Not affected
Show less packages

CVE-2022-25255

Medium priority

Some fixes available 1 of 11

In Qt 5.9.x through 5.15.x before 5.15.9 and 6.x before 6.2.4 on Linux and UNIX, QProcess could execute a binary from the current working directory when not found in the PATH.

2 affected packages

qt6-base, qtbase-opensource-src

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
qt6-base Needs evaluation Needs evaluation Needs evaluation
qtbase-opensource-src Not affected Not affected Not affected Fixed Not affected
Show less packages

CVE-2021-38593

Medium priority

Some fixes available 2 of 16

Qt 5.x before 5.15.6 and 6.x through 6.1.2 has an out-of-bounds write in QOutlineMapper::convertPath (called from QRasterPaintEngine::fill and QPaintEngineEx::stroke).

2 affected packages

qtbase-opensource-src-gles, qtbase-opensource-src

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
qtbase-opensource-src-gles Needs evaluation Needs evaluation Needs evaluation Needs evaluation Not in release
qtbase-opensource-src Not affected Not affected Not affected Fixed Fixed
Show less packages

CVE-2020-24742

Medium priority
Not affected

An issue has been fixed in Qt versions 5.14.0 where QPluginLoader attempts to load plugins relative to the working directory, allowing attackers to execute arbitrary code via crafted files.

2 affected packages

qtbase-opensource-src, qtbase-opensource-src-gles

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
qtbase-opensource-src Not affected Not affected Not affected
qtbase-opensource-src-gles Not affected Not affected Not in release
Show less packages

CVE-2020-24741

Medium priority
Not affected

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-0570. Reason: This candidate is a duplicate of CVE-2020-0570. A typo caused the wrong ID to be used. Notes: All CVE users should reference CVE-2020-0570...

2 affected packages

qtbase-opensource-src, qtbase-opensource-src-gles

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
qtbase-opensource-src Not affected Not affected
qtbase-opensource-src-gles Not affected Not in release
Show less packages

CVE-2020-15999

High priority
Fixed

Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

18 affected packages

android, chromium-browser, firefox, freetype, godot...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
android Not in release Not in release Not in release Not in release
chromium-browser Not affected Not affected Not in release Fixed
firefox Not affected Not affected Not in release Not affected
freetype Fixed Fixed Fixed Fixed
godot Not affected Not affected Not affected Not in release
graphicsmagick Not affected Not affected Not affected Not affected
musescore Not in release Not in release Not affected Not affected
openjdk-12 Not in release Not in release Not in release Not in release
openjdk-13 Not in release Not in release Not affected Not in release
openjdk-15 Not in release Not in release Not in release Not in release
openjdk-lts Not affected Not affected Not affected Not affected
oxide-qt Not in release Not in release Not in release Not in release
paraview Not affected Not affected Not affected Not affected
qtbase-opensource-src Not affected Not affected Not affected Not affected
qtbase-opensource-src-gles Not affected Not affected Not affected Not in release
texlive-bin Not affected Not affected Not affected Not affected
texmaker Not affected Not affected Not affected Not affected
thunderbird Not affected Not affected Not in release Not affected
Show all 18 packages Show less packages

CVE-2020-17507

Low priority

Some fixes available 3 of 6

An issue was discovered in Qt through 5.12.9, and 5.13.x through 5.15.x before 5.15.1. read_xbm_body in gui/image/qxbmhandler.cpp has a buffer over-read.

2 affected packages

qt4-x11, qtbase-opensource-src

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
qt4-x11 Not in release Not in release Not in release Not in release Vulnerable
qtbase-opensource-src Not affected Not affected Not affected Fixed Fixed
Show less packages

CVE-2020-13962

Medium priority

Some fixes available 1 of 2

Qt 5.12.2 through 5.14.2, as used in unofficial builds of Mumble 1.3.0 and other products, mishandles OpenSSL's error queue, which can cause a denial of service to QSslSocket users. Because errors leak in unrelated TLS sessions,...

1 affected package

qtbase-opensource-src

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
qtbase-opensource-src Not affected Not affected Fixed Not affected
Show less packages

CVE-2020-12267

Medium priority
Not affected

setMarkdown in Qt before 5.14.2 has a use-after-free related to QTextMarkdownImporter::insertBlock.

2 affected packages

qt4-x11, qtbase-opensource-src

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
qt4-x11 Not in release Not affected
qtbase-opensource-src Not affected Not affected
Show less packages

CVE-2020-0570

Medium priority
Fixed

Uncontrolled search path in the QT Library before 5.14.0, 5.12.7 and 5.9.10 may allow an authenticated user to potentially enable elevation of privilege via local access.

1 affected package

qtbase-opensource-src

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
qtbase-opensource-src Not affected
Show less packages