CRITICAL 9.8 Microsoft

CVE-2024-36048

QAbstractOAuth in Qt Network Authorization in Qt before 5.15.17, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.6, and 6.6.x through 6.7.x before 6.7.1 uses only the time to seed the PRNG, which may result in guessable values.

Microsoft Security Update 2024-May: QAbstractOAuth in Qt Network Authorization in Qt before 5.15.17, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.6, and 6.6.x through 6.7.x before 6.7.1 uses only the time to seed the PRNG, which may result in guessable values.

Affected Products

References

Published: 2024-05-14 · Source: Microsoft · Feed updated: 2026-09-30
This critical severity vulnerability with a CVSS score of 9.8 was published on 2024-05-14 via Microsoft. Affected: cbl2 qt5-qtbase 5.12.11-16.

Risk Timeline

CVE Disclosed2024-05-14 · 868 days ago

Remediation Resources

Related Vulnerabilities

CVETitleSeverityCVSS
CVE-2022-49043xmlXIncludeAddNode in xinclude.c in libxml2 before 2.11.0 has a use-after-free.CRITICAL10.0
CVE-2025-49844 PoCRedis Lua Use-After-Free may lead to remote code executionCRITICAL9.9
CVE-2024-29157HDF5 through 1.14.3 contains a heap buffer overflow in H5HG_read resulting in thCRITICAL9.8
CVE-2024-29159HDF5 through 1.14.3 contains a buffer overflow in H5Z__filter_scaleoffset resultCRITICAL9.8
CVE-2024-29164HDF5 through 1.14.3 contains a stack buffer overflow in H5R__decode_heap resultiCRITICAL9.8
CVE-2024-32611HDF5 Library through 1.14.3 may use an uninitialized value in H5A__attr_release_CRITICAL9.8
vulnfeed aggregates 9449 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.