Multiple buffer overflows in the QtBase module in Qt before 4.8.7 and 5.x before 5.4.2 allow remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted ICO image. http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-1859