VYPR

Qt

by Qt

Source repositories

CVEs (59)

  • CVE-2017-15011HigOct 4, 2017
    risk 0.49cvss 7.5epss 0.01

    The named pipes in qtsingleapp in Qt 5.x, as used in qBittorrent and SugarSync, are configured for remote access and allow remote attackers to cause a denial of service (application crash) via an unspecified string.

  • CVE-2020-0570HigSep 14, 2020
    risk 0.47cvss 7.3epss 0.01

    Uncontrolled search path in the QT Library before 5.14.0, 5.12.7 and 5.9.10 may allow an authenticated user to potentially enable elevation of privilege via local access.

  • CVE-2021-3481HigAug 22, 2022
    risk 0.46cvss 7.1epss 0.01

    A flaw was found in Qt. An out-of-bounds read vulnerability was found in QRadialFetchSimd in qt/qtbase/src/gui/painting/qdrawhelper_p.h in Qt/Qtbase. While rendering and displaying a crafted Scalable Vector Graphics (SVG) file this flaw may lead to an unauthorized memory access.…

  • CVE-2024-30161MedMar 24, 2024
    risk 0.42cvss 6.5epss 0.00

    In Qt 6.5.4, 6.5.5, and 6.6.2, QNetworkReply header data might be accessed via a dangling pointer in Qt for WebAssembly (wasm). (Earlier and later versions are unaffected.)

  • CVE-2023-32573MedMay 10, 2023
    risk 0.42cvss 6.5epss 0.01

    In Qt before 5.15.14, 6.0.x through 6.2.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1, QtSvg QSvgFont m_unitsPerEm initialization is mishandled.

  • CVE-2018-19871MedDec 26, 2018
    risk 0.42cvss 6.5epss 0.02

    An issue was discovered in Qt before 5.11.3. There is QTgaFile Uncontrolled Resource Consumption.

  • CVE-2018-19869MedDec 26, 2018
    risk 0.42cvss 6.5epss 0.02

    An issue was discovered in Qt before 5.11.3. A malformed SVG image causes a segmentation fault in qsvghandler.cpp.

  • CVE-2025-30348MedMar 21, 2025
    risk 0.38cvss 5.8epss 0.00

    encodeText in QDom in Qt before 6.8.0 has a complex algorithm involving XML string copy and inline replacement of parts of a string (with relocation of later data).

  • CVE-2020-0569MedNov 23, 2020
    risk 0.37cvss 5.7epss 0.01

    Out of bounds write in Intel(R) PROSet/Wireless WiFi products on Windows 10 may allow an authenticated user to potentially enable denial of service via local access.

  • CVE-2025-5683MedJun 5, 2025
    risk 0.36cvss 5.5epss 0.00

    When loading a specifically crafted ICNS format image file in QImage then it will trigger a crash.  This issue affects Qt from versions 6.3.0 through 6.5.9, from 6.6.0 through 6.8.4, 6.9.0. This is fixed in 6.5.10, 6.8.5 and 6.9.1.

  • CVE-2023-43114MedSep 18, 2023
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in Qt before 5.15.16, 6.x before 6.2.10, and 6.3.x through 6.5.x before 6.5.3 on Windows. When using the GDI font engine, if a corrupted font is loaded via QFontDatabase::addApplicationFont{FromData], then it can cause the application to crash because of…

  • CVE-2021-28025MedAug 11, 2023
    risk 0.36cvss 5.5epss 0.00

    Integer Overflow vulnerability in qsvghandler.cpp in Qt qtsvg versions 5.15.1, 6.0.0, 6.0.2, and 6.2, allows local attackers to cause a denial of service (DoS).

  • CVE-2018-19872MedMar 21, 2019
    risk 0.36cvss 5.5epss 0.01

    An issue was discovered in Qt 5.11. A malformed PPM image causes a division by zero and a crash in qppmhandler.cpp.

  • CVE-2023-34410MedJun 5, 2023
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.2. Certificate validation for TLS does not always consider whether the root of a chain is a configured CA certificate.

  • CVE-2023-33285MedMay 22, 2023
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in Qt 5.x before 5.15.14, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1. QDnsLookup has a buffer over-read via a crafted reply from a DNS server.

  • CVE-2020-17507MedAug 12, 2020
    risk 0.35cvss 5.3epss 0.04

    An issue was discovered in Qt through 5.12.9, and 5.13.x through 5.15.x before 5.15.1. read_xbm_body in gui/image/qxbmhandler.cpp has a buffer over-read.

  • CVE-2017-10905MedDec 16, 2017
    risk 0.34cvss 5.3epss 0.01

    A vulnerability in applications created using Qt for Android prior to 5.9.3 allows attackers to alter environment variables via unspecified vectors.

  • CVE-2024-25580MedMar 27, 2024
    risk 0.33cvss 6.2epss 0.00

    An issue was discovered in gui/util/qktxhandler.cpp in Qt before 5.15.17, 6.x before 6.2.12, 6.3.x through 6.5.x before 6.5.5, and 6.6.x before 6.6.2. A buffer overflow and application crash can occur via a crafted KTX image file.

  • CVE-2023-45935MedMar 27, 2024
    risk 0.27cvss 4.2epss 0.00

    Qt 6 through 6.6 was discovered to contain a NULL pointer dereference via the function QXcbConnection::initializeAllAtoms(). NOTE: this is disputed because it is not expected that an X application should continue to run when there is arbitrary anomalous behavior from the X…

  • CVE-2010-2621Jul 2, 2010
    risk 0.04cvss epss 0.11

    The QSslSocketBackendPrivate::transmit function in src_network_ssl_qsslsocket_openssl.cpp in Qt 4.6.3 and earlier allows remote attackers to cause a denial of service (infinite loop) via a malformed request.