Back to Database
Status published
Medium
CVE-2013-4549
QXmlSimpleReader in Qt before 5.2 allows context-dependent attackers to cause...
Vulnerability Description
QXmlSimpleReader in Qt before 5.2 allows context-dependent attackers to cause a denial of service (memory consumption) via an XML Entity Expansion (XEE) attack.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2013-4549
Credits & Attribution
No credits recorded in the NVD database.
References
- http://lists.qt-project.org/pipermail/announce/2013-December/000036.html
- http://secunia.com/advisories/56166
- http://lists.opensuse.org/opensuse-updates/2014-01/msg00104.html
- http://secunia.com/advisories/56008
- http://lists.opensuse.org/opensuse-updates/2014-01/msg00085.html
- https://codereview.qt-project.org/#change%2C71010
- http://lists.opensuse.org/opensuse-updates/2014-01/msg00106.html
- http://lists.opensuse.org/opensuse-updates/2014-01/msg00044.html
- http://blog.qt.digia.com/blog/2014/04/24/qt-4-8-6-released/
- http://www.ubuntu.com/usn/USN-2057-1
- https://codereview.qt-project.org/#change%2C71368
- http://lists.opensuse.org/opensuse-updates/2014-01/msg00047.html
- http://lists.fedoraproject.org/pipermail/package-announce/2014-May/132395.html
More from digia
View All →CVE-2015-1858
Multiple buffer overflows in gui/image/qbmphandler.cpp in the QtBase module in...
Medium
6.8
CVE-2012-5624
The XMLHttpRequest object in Qt before 4.8.4 enables http redirection...
Medium
4.3
CVE-2010-5076
QSslSocket in Qt before 4.7.0-rc1 recognizes a wildcard IP address...
Medium
4.3
CVE-2010-2621
The QSslSocketBackendPrivate::transmit function in src_network_ssl_qsslsocket_openssl.cpp in Qt 4.6.3 and earlier...
Medium
5
CVE-2010-1766
Off-by-one error in the WebSocketHandshake::readServerHandshake function in websockets/WebSocketHandshake.cpp in WebCore...
High
7.5
Affected Vendor
digia
View all reports →Affected Software
qt
Vulnerable Versions:
0, 5.0.2
Timeline
Official Publish:
December 23rd, 2013
Last Modified:
August 6th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.