CRITICAL 9.8 Microsoft
CVE-2024-36048
QAbstractOAuth in Qt Network Authorization in Qt before 5.15.17, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.6, and 6.6.x through 6.7.x before 6.7.1 uses only the time to seed the PRNG, which may result in guessable values.
Microsoft Security Update 2024-May: QAbstractOAuth in Qt Network Authorization in Qt before 5.15.17, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.6, and 6.6.x through 6.7.x before 6.7.1 uses only the time to seed the PRNG, which may result in guessable values.
Affected Products
- cbl2 qt5-qtbase 5.12.11-16
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-36048
- https://nvd.nist.gov/vuln/detail/CVE-2024-36048
This critical severity vulnerability with a CVSS score of 9.8 was published on 2024-05-14 via Microsoft. Affected: cbl2 qt5-qtbase 5.12.11-16.
Risk Timeline
CVE Disclosed2024-05-14 · 868 days ago
Remediation Resources
Official Advisory
msrc.microsoft.com/update-guide/vulnerability/CVE-2024-36048NVD / MITRE
nvd.nist.gov/vuln/detail/CVE-2024-36048Related Vulnerabilities
| CVE | Title | Severity | CVSS |
|---|---|---|---|
| CVE-2022-49043 | xmlXIncludeAddNode in xinclude.c in libxml2 before 2.11.0 has a use-after-free. | CRITICAL | 10.0 |
| CVE-2025-49844 PoC | Redis Lua Use-After-Free may lead to remote code execution | CRITICAL | 9.9 |
| CVE-2024-29157 | HDF5 through 1.14.3 contains a heap buffer overflow in H5HG_read resulting in th | CRITICAL | 9.8 |
| CVE-2024-29159 | HDF5 through 1.14.3 contains a buffer overflow in H5Z__filter_scaleoffset result | CRITICAL | 9.8 |
| CVE-2024-29164 | HDF5 through 1.14.3 contains a stack buffer overflow in H5R__decode_heap resulti | CRITICAL | 9.8 |
| CVE-2024-32611 | HDF5 Library through 1.14.3 may use an uninitialized value in H5A__attr_release_ | CRITICAL | 9.8 |
vulnfeed aggregates 9449 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.