Vulnerability Database

289,599

Total vulnerabilities in the database

CVE-2007-0242

The UTF-8 decoder in codecs/qutfcodec.cpp in Qt 3.3.8 and 4.2.3 does not reject long UTF-8 sequences as required by the standard, which allows remote attackers to conduct cross-site scripting (XSS) and directory traversal attacks via long sequences that decode to dangerous metacharacters.

  • Published: Apr 3, 2007
  • Updated: Apr 13, 2023
  • CVE: CVE-2007-0242
  • Severity: Low
  • Exploit:

CVSS v2:

  • Severity: Low
  • Score: 4.3
  • AV:N/AC:M/Au:N/C:N/I:P/A:N

No CWE or OWASP classifications available.

Software From Fixed in
qt / qt 3.3.8 3.3.8.x
qt / qt 4.2.3 4.2.3.x