VDB

CVE-2024-36048

CVE-2024-36048 PUBLISHED CVSS 9.800000190734863 CRITICAL

QAbstractOAuth in Qt Network Authorization in Qt before 5.15.17, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.6, and 6.6.x through 6.7.x before 6.7.1 uses only the time to seed the PRNG, which may result in guessable values.

EPSS 0.48% · 65.6th percentile

Risk Scores

CVSS 3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.48%
65.6th percentile

Affected Products

VendorProductVersions
n/an/an/a
qtqt6.0.0, 0, 6.6.0
fedoraprojectfedora39, 40
qtqt_network_authorization0, 6.6x, 6.6x

Timeline

  • May 18, 2024 CVE Published
  • Jun 11, 2024 EPSS Score
  • Jul 4, 2024 EPSS Score
  • Jul 27, 2024 EPSS Score
  • Aug 19, 2024 EPSS Score
  • Sep 11, 2024 EPSS Score
  • Oct 4, 2024 Coalition ESS Score
  • Oct 27, 2024 EPSS Score
  • Nov 19, 2024 EPSS Score
  • Dec 13, 2024 EPSS Score
  • Jan 5, 2025 EPSS Score
  • Jan 28, 2025 EPSS Score

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›