CVE-2015-9541 PUBLISHED

Qt through 5.14 allows an exponential XML entity expansion attack via a crafted SVG document that is mishandled in QXmlStreamReader, a related issue to CVE-2003-1564.

EPSS 0.90% · 75.5th percentile

Risk Scores

EPSS Score
0.90%
75.5th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSpyside1.2.1-1, 1.2.1-4build1, 1.2.1-4
Ubuntu:16.04:LTSqt4-x114:4.8.7+dfsg-5ubuntu2, 0, 4:4.8.6+git64-g5dc8b2b+dfsg-3~ubuntu8
Ubuntu:20.04:LTSphantomjs2.1.1+dfsg-2, 2.1.1+dfsg-2ubuntu1, 0
Ubuntu:18.04:LTSqt4-x110, 4:4.8.7+dfsg-7ubuntu1
Ubuntu:18.04:LTSpyside0, 1.2.2+source1-2, 1.2.2+source1-3
Ubuntu:24.04:LTSpyside25.15.12-6.1build3, 5.15.13-1, 5.15.12-6.1build2
Ubuntu:18.04:LTSphantomjs2.1.1+dfsg-2, 0
Ubuntu:20.04:LTSpyside25.11.2-3ubuntu1, 5.11.2-3build2, 0
Ubuntu:16.04:LTSpyside1.2.2-2build2, 0, 1.2.2-2
Ubuntu:25.10pyside25.15.16-3.1build1, 0, 5.15.16-3.1build3
Ubuntu:Pro:18.04:LTSqtbase-opensource-src5.9.5+dfsg-0ubuntu2.6, 0, 5.9.1+dfsg-10ubuntu1
Ubuntu:16.04:LTSphantomjs2.0.0+dfsg-1, 1.9.0-1, 0
Ubuntu:22.04:LTSpyside20, 5.15.2-2build2, 5.15.2-1
Ubuntu:Pro:16.04:LTSqtbase-opensource-src5.5.1+dfsg-16ubuntu1, 5.5.1+dfsg-15ubuntu1, 5.5.1+dfsg-14ubuntu3
Ubuntu:14.04:LTSqt4-x114:4.8.5+git192-g085f851+dfsg-2ubuntu4.1, 4:4.8.5+git192-g085f851+dfsg-2ubuntu4, 4:4.8.5+git192-g085f851+dfsg-2ubuntu3

Timeline

References

Open in Interactive Console →