Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2007-0242

Опубликовано: 03 апр. 2007
Источник: ubuntu
Приоритет: untriaged
EPSS Низкий
CVSS2: 4.3

Описание

The UTF-8 decoder in codecs/qutfcodec.cpp in Qt 3.3.8 and 4.2.3 does not reject long UTF-8 sequences as required by the standard, which allows remote attackers to conduct cross-site scripting (XSS) and directory traversal attacks via long sequences that decode to dangerous metacharacters.

РелизСтатусПримечание
dapper

released

3.5.2-0ubuntu18.5
devel

released

3.5.7-1ubuntu14
edgy

released

3.5.5-0ubuntu3.5
feisty

released

3.5.6-0ubuntu14.1
upstream

needs-triage

Показывать по

РелизСтатусПримечание
dapper

released

3.3.6-1ubuntu6.4
devel

released

3.3.8really3.3.7-0ubuntu10
edgy

released

3.3.6-3ubuntu3.3
feisty

released

3.3.8really3.3.7-0ubuntu5.2
upstream

needs-triage

Показывать по

РелизСтатусПримечание
dapper

not-affected

devel

released

4.3.1-0ubuntu2
edgy

not-affected

feisty

not-affected

upstream

needs-triage

Показывать по

EPSS

Процентиль: 76%
0.00984
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

redhat
около 18 лет назад

The UTF-8 decoder in codecs/qutfcodec.cpp in Qt 3.3.8 and 4.2.3 does not reject long UTF-8 sequences as required by the standard, which allows remote attackers to conduct cross-site scripting (XSS) and directory traversal attacks via long sequences that decode to dangerous metacharacters.

nvd
около 18 лет назад

The UTF-8 decoder in codecs/qutfcodec.cpp in Qt 3.3.8 and 4.2.3 does not reject long UTF-8 sequences as required by the standard, which allows remote attackers to conduct cross-site scripting (XSS) and directory traversal attacks via long sequences that decode to dangerous metacharacters.

debian
около 18 лет назад

The UTF-8 decoder in codecs/qutfcodec.cpp in Qt 3.3.8 and 4.2.3 does n ...

github
около 3 лет назад

The UTF-8 decoder in codecs/qutfcodec.cpp in Qt 3.3.8 and 4.2.3 does not reject long UTF-8 sequences as required by the standard, which allows remote attackers to conduct cross-site scripting (XSS) and directory traversal attacks via long sequences that decode to dangerous metacharacters.

fstec
около 18 лет назад

Уязвимости операционной системы Debian GNU/Linux, позволяющие удаленному злоумышленнику нарушить целостность защищаемой информации

EPSS

Процентиль: 76%
0.00984
Низкий

4.3 Medium

CVSS2

Уязвимость CVE-2007-0242