Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2010-5076

17
FAUCET Score

CVE-2010-5076 describes a vulnerability in QSslSocket within Qt versions prior to 4.7.0-rc1, where it incorrectly validates X.509 certificates by recognizing wildcard IP addresses in the Common Name field. This flaw could enable man-in-the-middle attackers to spoof SSL servers using specially crafted certificates from legitimate Certificate Authorities. The vulnerability has a CVSS score of 4.3, indicating a medium attack complexity and potential for partial integrity impact, requiring no authentication. There is no evidence of active exploitation, readily available exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
<= 4.6.4CPE matchmatch criteria
cpe:2.3:a:digia:qt:*:*:*:*:*:*:*:*
4.0.0CPE matchmatch criteria
cpe:2.3:a:qt:qt:4.0.0:*:*:*:*:*:*:*
4.0.1CPE matchmatch criteria
cpe:2.3:a:qt:qt:4.0.1:*:*:*:*:*:*:*
4.1.0CPE matchmatch criteria
cpe:2.3:a:qt:qt:4.1.0:*:*:*:*:*:*:*
4.1.1CPE matchmatch criteria
cpe:2.3:a:qt:qt:4.1.1:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

4.3MEDIUM

AV:N/AC:M/Au:N/C:N/I:P/A:N

Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
NONE
Access Vector
NETWORK
Access Complexity
MEDIUM
Authentication
NONE
Exploitability Score
8.6
Impact Score
2.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
1.40%
Probability of exploitation in next 30 days
EPSS Percentile
69.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0140 is in the 41st percentile among its peer group of 19,955 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: qt-1:4.6.2-24.el6
View patch

Vendor Advisories (1)

redhatCVE-2010-5076Low

Qt: QSslSocket incorrect handling of IP wildcards in certificate Common Name

Jul 14, 2010

References

qt.gitorious.org / qt/qt/commit/5f6018564668d368f75e431c4cdac88d7421cff0
ExploitPatch
qt.gitorious.org / qt/qt/commit/846f1b44eea4bb34d080d055badb40a4a13d369e
Patch
rhn.redhat.com / errata/RHSA-2012-0880.html
bugreports.qt-project.org / browse/QTBUG-4455
secunia.com / advisories/41236
Vendor Advisory
secunia.com / advisories/49604
Vendor Advisory
secunia.com / advisories/49895
Vendor Advisory
ubuntu.com / usn/USN-1504-1
westpoint.ltd.uk / advisories/wp-10-0001.txt