PatchSiren

Qt CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Qt CVE published 2017-03-07

CVE-2016-10040

CVE-2016-10040 is a stack-based buffer overflow in Qt's QXmlSimpleReader affecting Qt 4.8.5. According to the NVD record, an XML file with multiple nested open tags can trigger an application crash, resulting in denial of service. The NVD CVSS vector rates the issue as medium severity and shows availability impact only.