HIGH 7.5 Microsoft

CVE-2018-21035

In Qt through 5.14.1 the WebSocket implementation accepts up to 2GB for frames and 2GB for messages. Smaller limits cannot be configured. This makes it easier for attackers to cause a denial of service (memory consumption).

Microsoft Security Update 2020-Feb: In Qt through 5.14.1 the WebSocket implementation accepts up to 2GB for frames and 2GB for messages. Smaller limits cannot be configured. This makes it easier for attackers to cause a denial of service (memory consumption).

Affected Products

References

Published: 2020-02-11 · Source: Microsoft · Feed updated: 2026-09-17
This high severity vulnerability with a CVSS score of 7.5 was published on 2020-02-11 via Microsoft. Affected: cm1 qt5-qtsvg 5.12.11-2 on CBL Mariner 1.0, cbl2 qt5-qtsvg 5.12.11-3 on CBL Mariner 2.0.
vulnfeed aggregates 8294 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.