CVE-2015-1859: Digia Qt
Medium severity, CVSS 6.8. EPSS: 7.1% chance of exploitation in the next 30 days.
Multiple buffer overflows in plugins/imageformats/ico/qicohandler.cpp in the QtBase module in Qt before 4.8.7 and 5.x before 5.4.2 allow remote attackers to cause a denial of service (segmentation fault and crash) and possibly execute arbitrary code via a crafted ICO image.
Affected products
- Digia Qt: up to and including 4.8.6
- Fedoraproject Fedora: version 20 only; version 21 only; version 22 only
- Qt Qt: version 5.0.0 only; version 5.0.1 only; version 5.0.2 only; version 5.1.0 only; version 5.2.0 only; version 5.2.1 only; …
Published 2015-05-12. Last modified 2026-06-17.