« List of all CVEs

CVE-2007-0242

Published: 4/3/2007 Last updated: 8/7/2024 Reserved: 1/16/2007

The UTF-8 decoder in codecs/qutfcodec.cpp in Qt 3.3.8 and 4.2.3 does not reject long UTF-8 sequences as required by the standard, which allows remote attackers to conduct cross-site scripting (XSS) and directory traversal attacks via long sequences that decode to dangerous metacharacters.

CNA assigner: mitre (8254265b-2729-46b6-b9e3-3dfca2d5bfca) Requested by: n/a

Opam packages affected (2)

conf-qt oqamldebug

Products affected (0)

No product listed.

References (72)