CVE-2015-1858: Digia Qt
Medium severity, CVSS 6.8. EPSS: 7.2% chance of exploitation in the next 30 days.
Multiple buffer overflows in gui/image/qbmphandler.cpp in the QtBase module in Qt before 4.8.7 and 5.x before 5.4.2 allow remote attackers to cause a denial of service (segmentation fault and crash) and possibly execute arbitrary code via a crafted BMP image.
Affected products
- Digia Qt: up to and including 4.8.6
- Fedoraproject Fedora: version 20 only; version 21 only; version 22 only
- Qt Qt: version 5.0.0 only; version 5.0.1 only; version 5.0.2 only; version 5.1.0 only; version 5.2.0 only; version 5.2.1 only; …
Published 2015-05-12. Last modified 2026-06-17.