Msrc Cbl2 Qt5-Qtsvg 5.12.11-3 On Cbl Mariner 2.0 vulnerabilities
8 known vulnerabilities affecting msrc/cbl2_qt5-qtsvg_5.12.11-3_on_cbl_mariner_2.0.
Total CVEs
8
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH7MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2022-25634HIGHCVSS 7.52022-03-08
CVE-2022-25634 [HIGH] CWE-22 Qt through 5.15.8 and 6.x through 6.2.3 can load system library files from an unintended working directory.
Qt through 5.15.8 and 6.x through 6.2.3 can load system library files from an unintended working directory.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to kee
msrc
CVE-2021-38593HIGHCVSS 7.52021-08-10
CVE-2021-38593 [HIGH] CWE-787 Qt 5.x before 5.15.6 and 6.x through 6.1.2 has an out-of-bounds write in QOutlineMapper::convertPath (called from QRasterPaintEngine::fill and QPaintEngineEx::stroke).
Qt 5.x before 5.15.6 and 6.x through 6.1.2 has an out-of-bounds write in QOutlineMapper::convertPath (called from QRasterPaintEngine::fill and QPaintEngineEx::stroke).
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this v
msrc
CVE-2020-24742HIGHCVSS 7.82021-08-10
CVE-2020-24742 [HIGH] An issue has been fixed in Qt versions 5.14.0 where QPluginLoader attempts to load plugins relative to the working directory allowing attackers to execute arbitrary code via crafted files.
An issue has been fixed in Qt versions 5.14.0 where QPluginLoader attempts to load plugins relative to the working directory allowing attackers to execute arbitrary code via crafted files.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is theref
msrc
CVE-2020-0570HIGHCVSS 7.32020-09-08
CVE-2020-0570 [HIGH] CWE-426 Uncontrolled search path in the QT Library before 5.14.0 5.12.7 and 5.9.10 may allow an authenticated user to potentially enable elevation of privilege via local access.
Uncontrolled search path in the QT Library before 5.14.0 5.12.7 and 5.9.10 may allow an authenticated user to potentially enable elevation of privilege via local access.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by thi
msrc
CVE-2020-17507MEDIUMCVSS 5.32020-08-11
CVE-2020-17507 [MEDIUM] CWE-125 An issue was discovered in Qt through 5.12.9 and 5.13.x through 5.15.x before 5.15.1. read_xbm_body in gui/image/qxbmhandler.cpp has a buffer over-read.
An issue was discovered in Qt through 5.12.9 and 5.13.x through 5.15.x before 5.15.1. read_xbm_body in gui/image/qxbmhandler.cpp has a buffer over-read.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the mai
msrc
CVE-2020-13962HIGHCVSS 7.52020-06-09
CVE-2020-13962 [HIGH] Qt 5.12.2 through 5.14.2 as used in unofficial builds of Mumble 1.3.0 and other products mishandles OpenSSL's error queue which can cause a denial of service to QSslSocket users. Because errors leak i
Qt 5.12.2 through 5.14.2 as used in unofficial builds of Mumble 1.3.0 and other products mishandles OpenSSL's error queue which can cause a denial of service to QSslSocket users. Because errors leak in unrelated TLS sessions an unrelated session may be disconnected when any ha
msrc
CVE-2018-21035HIGHCVSS 7.52020-02-11
CVE-2018-21035 [HIGH] CWE-770 In Qt through 5.14.1 the WebSocket implementation accepts up to 2GB for frames and 2GB for messages. Smaller limits cannot be configured. This makes it easier for attackers to cause a denial of servic
In Qt through 5.14.1 the WebSocket implementation accepts up to 2GB for frames and 2GB for messages. Smaller limits cannot be configured. This makes it easier for attackers to cause a denial of service (memory consumption).
FAQ: Is Azure Linux the only Microsoft produ
msrc
CVE-2015-9541HIGHCVSS 7.52020-01-14
CVE-2015-9541 [MEDIUM] CWE-776 Qt through 5.14 allows an exponential XML entity expansion attack via a crafted SVG document that is mishandled in QXmlStreamReader a related issue to CVE-2003-1564.
Qt through 5.14 allows an exponential XML entity expansion attack via a crafted SVG document that is mishandled in QXmlStreamReader a related issue to CVE-2003-1564.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vuln
msrc