SEGGER software products may include or make use of third-party software components.
The presence of a third-party component does not necessarily mean that all functionality of that component is used by the SEGGER software.
Likewise, a publicly disclosed vulnerability affecting a third-party component does not necessarily affect the SEGGER product in which the component is used.
SEGGER evaluates relevant publicly disclosed vulnerabilities of third-party components with respect to their actual use in SEGGER software.
J-Link / Flasher Software and Documentation Pack
Qt
Some SEGGER host applications use the Qt4.8.7 framework for their graphical user interface and other application functionality, see SEGGER Qt usage.
CVE-2025-30348
| CVE ID
|
CVE-2025-30348
|
| Affected component
|
Qt XML module
|
| Product version(s)
|
Qt 4.8, used in V6.30 and later
|
| Status
|
Fixed
|
| Fixed version
|
V9.73 (RC) / V9.74
|
| Discovery date
|
2025/03/21
|
| Publication date
|
2026/09/02
|
| References
|
|
| Impact assessment
|
Availability impact only. Processing specially crafted large XML text during QDom serialization may cause excessive CPU usage, resulting in denial of service.
|
| Severity and exploitability
|
None. J-Link and Flasher software does not use nor ship Qt's XML module.
|
CVE-2025-4211
| CVE ID
|
CVE-2025-4211
|
| Affected component
|
Qt core module
|
| Product version(s)
|
Qt 4.8, used in V6.30 and later
|
| Status
|
Fixed
|
| Fixed version
|
V9.73 (RC) / V9.74
|
| Discovery date
|
2025/05/16
|
| Publication date
|
2026/09/02
|
| References
|
|
| Impact assessment
|
An unprivileged local attacker could potentially exploit insecure temporary-directory handling by privileged processes to influence file operations, potentially resulting in local privilege escalation.
|
| Severity and exploitability
|
Moderate. Exploitation requires local access and a privileged process using the affected Qt APIs, which limits the attack surface. However, successful exploitation could allow privilege escalation.
|
CVE-2023-43114
| CVE ID
|
CVE-2023-43114
|
| Affected component
|
Qt GUI module
|
| Product version(s)
|
Qt 4.8, used in V6.30 and later
|
| Status
|
Fixed
|
| Fixed version
|
V9.73 (RC) / V9.74
|
| Discovery date
|
2023/07/13
|
| Publication date
|
2026/09/02
|
| References
|
|
| Impact assessment
|
Malformed font data may trigger an out-of-bounds read in the Windows font parser, causing application crash (denial of service). Potential information disclosure cannot be ruled out but has not been demonstrated.
|
| Severity and exploitability
|
Low. Requires attacker-controlled font input. J-Link and Flasher applications do not explicitly load any user fonts. Primarily affects availability; no demonstrated arbitrary code execution.
|
CVE-2023-38197
| CVE ID
|
CVE-2023-38197
|
| Affected component
|
Qt Core module
|
| Product version(s)
|
Qt 4.8, used in V6.30 and later
|
| Status
|
Fixed
|
| Fixed version
|
V9.73 (RC) / V9.74
|
| Discovery date
|
2023/07/12
|
| Publication date
|
2026/09/02
|
| References
|
|
| Impact assessment
|
None:
- Not applicable in the intended use of our software, as our software does not invoke
QXmlStreamReader.
- Even when attempting to force the vulnerability to occur with our builds using the reproducer that is provided in the respective Qt bug report, the described behavior cannot be observed.
|
| Severity and exploitability
|
None. The vulnerable code may exist in the shipped library, but it...
- ... is not reachable in the intended application
- ... is not even used by the Qt libraries, internally
- ... does not show a vulnerability when using the reported reproducer project
|
CVE-2023-37369
| CVE ID
|
CVE-2023-37369
|
| Affected component
|
Qt Core module
|
| Product version(s)
|
Qt 4.8, used in V6.30 and later
|
| Status
|
Fixed
|
| Fixed version
|
V9.73 (RC) / V9.74
|
| Discovery date
|
2023/07/07
|
| Publication date
|
2026/09/02
|
| References
|
|
| Impact assessment
|
Practically none:
- Vulnerable library code (the whole affected class) is not used by our applications.
- Qt libraries do not use the class internally, either.
- SVG support, which uses vulnerable class, has been fully disabled and removed from the libraries.
Therefore, the vulnerable code path is not reachable in our applications.
|
| Severity and exploitability
|
Low:
- Specially crafted XML file is required to run into vulnerability
- Vulnerable code path is not reachable in our application
|
CVE-2023-32763
| CVE ID
|
CVE-2023-32763
|
| Affected component
|
Qt Gui module
|
| Product version(s)
|
Qt 4.8, used in V6.30 and later
|
| Status
|
Fixed
|
| Fixed version
|
V9.73 (RC) / V9.74
|
| Discovery date
|
2023/05/28
|
| Publication date
|
2026/09/02
|
| References
|
|
| Impact assessment
|
None:
- Not applicable in the intended use of our software.
- Even when attempting to force the vulnerability to occur with our builds using the reproducer that is provided in the respective Qt bug report, the described behavior cannot be observed.
|
| Severity and exploitability
|
Practically none. The vulnerable code may exist in the shipped library, but it does not show a vulnerability when using the reported reproducer project.
|
CVE-2020-17507
| CVE ID
|
CVE-2020-17507
|
| Affected component
|
Qt Gui module
|
| Product version(s)
|
Qt 4.8, used in V6.30 and later
|
| Status
|
Fixed
|
| Fixed version
|
V9.73 (RC) / V9.74
|
| Discovery date
|
2020/12/08
|
| Publication date
|
2026/09/02
|
| References
|
|
| Impact assessment
|
Malformed .xbm file may trigger an out-of-bounds read in the file payload data parser. Potential information disclosure cannot be ruled out but has not been demonstrated.
|
| Severity and exploitability
|
Low. Requires attacker-controlled .xbm data input. J-Link and Flasher applications do not explicitly load any user images or any .xbm files, at all. Primarily affects availability; no demonstrated arbitrary code execution.
|
CVE-2018-19873
| CVE ID
|
CVE-2018-19873
|
| Affected component
|
Qt Gui module
|
| Product version(s)
|
Qt 4.8, used in V6.30 and later
|
| Status
|
Fixed
|
| Fixed version
|
V9.73 (RC) / V9.74
|
| Discovery date
|
2018/12/26
|
| Publication date
|
None
|
| References
|
|
| Impact assessment
|
A malformed .bmp file may lead to unnecessary allocation of memory as well as attempt to decode corrupt image file. Potential information disclosure cannot be ruled out but has not been demonstrated.
|
| Severity and exploitability
|
Low. Requires attacker-controlled .bmp data input. J-Link and Flasher applications do not explicitly load any user images or any .bmp files, at all. Primarily affects availability; no demonstrated arbitrary code execution.
|
CVE-2018-19870
| CVE ID
|
CVE-2018-19870
|
| Affected component
|
Qt GIF module
|
| Product version(s)
|
Qt 4.8, used in V6.30 and later
|
| Status
|
Fixed
|
| Fixed version
|
V9.73 (RC) / V9.74
|
| Discovery date
|
2018/12/26
|
| Publication date
|
2026/09/02
|
| References
|
|
| Impact assessment
|
Availability impact only. Processing specially crafted large .gif file may NULL pointer dereference, resulting in segmentation fault / denial of service.
|
| Severity and exploitability
|
None. J-Link and Flasher software does not use nor ship Qt's GIF module.
|
CVE-2014-0190
| CVE ID
|
CVE-2014-0190
|
| Affected component
|
Qt GIF module
|
| Product version(s)
|
Qt 4.8, used in V6.30 and later
|
| Status
|
Fixed already in Qt 4.8.7.
|
| Fixed version
|
V6.30 and later
|
| Discovery date
|
2014/05/08
|
| Publication date
|
2026/09/02
|
| References
|
|
| Impact assessment
|
Availability impact only. Processing specially crafted large .gif file may NULL pointer dereference, resulting in segmentation fault / denial of service.
|
| Severity and exploitability
|
None. Vulnerability was patched from the beginning.
|
embOS
embOS does not use any third-party software.
The entire source code is written by SEGGER Microcontroller.
Board support packages
embOS board support packages might include third-party software like, e.g. CMSIS-Core and CMSIS-Device files.