CVE-2015-9541 describes an exponential XML entity expansion vulnerability in Qt through version 5.14, specifically within the QXmlStreamReader when processing crafted SVG documents. This vulnerability, similar to CVE-2003-1564, primarily impacts Fedora and Qt products. It carries a CVSS v3.1 score of 7.5 (High), indicating a network-exploitable flaw with low attack complexity that could lead to high availability impact. There is currently no evidence of active exploitation, public exploit code (e.g., Metasploit, ExploitDB, Nuclei), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.5.0, < 5.12.8CPE matchmatch criteria | cpe:2.3:a:qt:qt:*:*:*:*:*:*:*:* | ||
31CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:* | ||
32CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2015-9541
Jul 13, 2021Qt through 5.14 allows an exponential XML entity expansion attack via a crafted SVG document that is mishandled in QXmlStreamReader a related issue to CVE-2003-1564.
Jan 14, 2020qt: XML entity expansion vulnerability
Jul 24, 2015