VYPR

Vendor CVEs

Qt

All CVEs

87 total · sorted by risk
  • CVE-2023-51714CriDec 24, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in the HTTP2 implementation in Qt before 5.15.17, 6.x before 6.2.11, 6.3.x through 6.5.x before 6.5.4, and 6.6.x before 6.6.2. network/access/http2/hpacktable.cpp has an incorrect HPack integer overflow check.

  • CVE-2020-12267CriApr 27, 2020
    risk 0.64cvss 9.8epss 0.02

    setMarkdown in Qt before 5.14.2 has a use-after-free related to QTextMarkdownImporter::insertBlock.

  • CVE-2018-19873CriDec 26, 2018
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered in Qt before 5.11.3. QBmpHandler has a buffer overflow via BMP data.

  • CVE-2017-10904CriDec 16, 2017
    risk 0.64cvss 9.8epss 0.02

    Qt for Android prior to 5.9.0 allows remote attackers to execute arbitrary OS commands via unspecified vectors.

  • CVE-2025-10729CriOct 3, 2025
    risk 0.61cvss —epss 0.00

    The module will parse a node which is not a child of a structural node. The node will be deleted after creation but might be accessed later leading to a use after free.

  • CVE-2025-10728CriOct 3, 2025
    risk 0.61cvss —epss 0.00

    When the module renders a Svg file that contains a element, it might end up rendering it recursively leading to stack overflow DoS

  • CVE-2025-6338CriOct 16, 2025
    risk 0.60cvss —epss 0.00

    There is an incomplete cleanup vulnerability in Qt Network's Schannel support on Windows which can lead to a Denial of Service over a long period. This issue affects Qt from 5.15.0 through 6.8.3, from 6.9.0 before 6.9.2.

  • CVE-2026-6210HigMay 6, 2026
    risk 0.57cvss —epss 0.00

    A type confusion vulnerability in Qt SVG allows an attacker to cause an application crash via a crafted SVG image. When processing SVG marker references, the renderer retrieves a node by its id attribute and casts it to QSvgMarker* without verifying the node type. A…

  • CVE-2025-12385HigDec 3, 2025
    risk 0.57cvss —epss 0.00

    Allocation of Resources Without Limits or Throttling, Improper Validation of Specified Quantity in Input vulnerability in The Qt Company Qt on Windows, MacOS, Linux, iOS, Android, x86, ARM, 64 bit, 32 bit allows Excessive Allocation. This issue affects users of the Text…

  • CVE-2024-36048CriMay 18, 2024
    risk 0.57cvss 9.8epss 0.01

    QAbstractOAuth in Qt Network Authorization in Qt before 5.15.17, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.6, and 6.6.x through 6.7.x before 6.7.1 uses only the time to seed the PRNG, which may result in guessable values.

  • CVE-2022-43591HigJan 12, 2023
    risk 0.57cvss 8.8epss 0.01

    A buffer overflow vulnerability exists in the QML QtScript Reflect API of Qt Project Qt 6.3.2. A specially-crafted javascript code can trigger an out-of-bounds memory access, which can lead to arbitrary code execution. Target application would need to access a malicious web page…

  • CVE-2022-40983HigJan 12, 2023
    risk 0.57cvss 8.8epss 0.01

    An integer overflow vulnerability exists in the QML QtScript Reflect API of Qt Project Qt 6.3.2. A specially-crafted javascript code can trigger an integer overflow during memory allocation, which can lead to arbitrary code execution. Target application would need to access a…

  • CVE-2015-1290HigJan 9, 2018
    risk 0.57cvss 8.8epss 0.03

    The Google V8 engine, as used in Google Chrome before 44.0.2403.89 and QtWebEngineCore in Qt before 5.5.1, allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a crafted web site.

  • CVE-2025-5455HigJun 2, 2025
    risk 0.55cvss —epss 0.00

    An issue was found in the private API function qDecodeDataUrl() in QtCore, which is used in QTextDocument and QNetworkReply, and, potentially, in user code. If the function was called with malformed data, for example, an URL that contained a "charset" parameter that lacked a…

  • CVE-2022-25255HigFeb 16, 2022
    risk 0.51cvss 7.8epss 0.00

    In Qt 5.9.x through 5.15.x before 5.15.9 and 6.x before 6.2.4 on Linux and UNIX, QProcess could execute a binary from the current working directory when not found in the PATH.

  • CVE-2020-24742HigAug 9, 2021
    risk 0.51cvss 7.8epss 0.01

    An issue has been fixed in Qt versions 5.14.0 where QPluginLoader attempts to load plugins relative to the working directory, allowing attackers to execute arbitrary code via crafted files.

  • CVE-2018-19870HigDec 26, 2018
    risk 0.50cvss 8.8epss 0.02

    An issue was discovered in Qt before 5.11.3. A malformed GIF image causes a NULL pointer dereference in QGifHandler resulting in a segmentation fault.

  • CVE-2018-15518HigDec 26, 2018
    risk 0.50cvss 8.8epss 0.03

    QXmlStream in Qt 5.x before 5.11.3 has a double-free or corruption during parsing of a specially crafted illegal XML document.

  • CVE-2024-39936HigJul 4, 2024
    risk 0.49cvss 8.6epss 0.00

    An issue was discovered in HTTP2 in Qt before 5.15.18, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.7, and 6.6.x through 6.7.x before 6.7.3. Code to make security-relevant decisions about an established connection may execute too early, because the encrypted() signal has…

  • CVE-2023-37369HigAug 20, 2023
    risk 0.49cvss 7.5epss 0.02

    In Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.2, there can be an application crash in QXmlStreamReader via a crafted XML string that triggers a situation in which a prefix is greater than a length.

  • CVE-2023-38197HigJul 13, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Qt before 5.15.15, 6.x before 6.2.10, and 6.3.x through 6.5.x before 6.5.3. There are infinite loops in recursive entity expansion.

  • CVE-2023-32763HigMay 28, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1. When a SVG file with an image inside it is rendered, a QTextLayout buffer overflow can be triggered.

  • CVE-2022-25634HigMar 2, 2022
    risk 0.49cvss 7.5epss 0.02

    Qt through 5.15.8 and 6.x through 6.2.3 can load system library files from an unintended working directory.

  • CVE-2021-38593HigAug 12, 2021
    risk 0.49cvss 7.5epss 0.03

    Qt 5.x before 5.15.6 and 6.x through 6.1.2 has an out-of-bounds write in QOutlineMapper::convertPath (called from QRasterPaintEngine::fill and QPaintEngineEx::stroke).

  • CVE-2020-13962HigJun 9, 2020
    risk 0.49cvss 7.5epss 0.03

    Qt 5.12.2 through 5.14.2, as used in unofficial builds of Mumble 1.3.0 and other products, mishandles OpenSSL's error queue, which can cause a denial of service to QSslSocket users. Because errors leak in unrelated TLS sessions, an unrelated session may be disconnected when any…

  • CVE-2018-21035HigFeb 28, 2020
    risk 0.49cvss 7.5epss 0.02

    In Qt through 5.14.1, the WebSocket implementation accepts up to 2GB for frames and 2GB for messages. Smaller limits cannot be configured. This makes it easier for attackers to cause a denial of service (memory consumption).

  • CVE-2015-9541HigJan 24, 2020
    risk 0.49cvss 7.5epss 0.02

    Qt through 5.14 allows an exponential XML entity expansion attack via a crafted SVG document that is mishandled in QXmlStreamReader, a related issue to CVE-2003-1564.

  • CVE-2018-19865HigDec 5, 2018
    risk 0.49cvss 7.5epss 0.02

    A keystroke logging issue was discovered in Virtual Keyboard in Qt 5.7.x, 5.8.x, 5.9.x, 5.10.x, and 5.11.x before 5.11.3.

  • CVE-2017-15011HigOct 4, 2017
    risk 0.49cvss 7.5epss 0.01

    The named pipes in qtsingleapp in Qt 5.x, as used in qBittorrent and SugarSync, are configured for remote access and allow remote attackers to cause a denial of service (application crash) via an unspecified string.

  • CVE-2025-4211HigMay 16, 2025
    risk 0.47cvss —epss 0.00

    Improper Link Resolution Before File Access ('Link Following') vulnerability in QFileSystemEngine in the Qt corelib module on Windows which potentially allows Symlink Attacks and the use of Malicious Files. Issue originates from CVE-2024-38081. The vulnerability arises from the…

  • CVE-2020-0570HigSep 14, 2020
    risk 0.47cvss 7.3epss 0.01

    Uncontrolled search path in the QT Library before 5.14.0, 5.12.7 and 5.9.10 may allow an authenticated user to potentially enable elevation of privilege via local access.

  • CVE-2026-19248HigSep 16, 2026
    risk 0.46cvss —epss 0.00

    QDomDocument XML parsing is vulnerable to a remotely-triggerable denial-of-service crash when processing untrusted input.

  • CVE-2026-11573HigSep 8, 2026
    risk 0.46cvss —epss 0.00

    Uncontrolled recursion (CWE-674) in the QDomDocument/QDomNode serialization path of the Qt XML module (QtXml, qtbase). QDomElementPrivate::save() and QDomNodePrivate::save() recurse mutually, consuming one stack frame per level of element nesting with no depth limit, no…

  • CVE-2021-3481HigAug 22, 2022
    risk 0.46cvss 7.1epss 0.01

    A flaw was found in Qt. An out-of-bounds read vulnerability was found in QRadialFetchSimd in qt/qtbase/src/gui/painting/qdrawhelper_p.h in Qt/Qtbase. While rendering and displaying a crafted Scalable Vector Graphics (SVG) file this flaw may lead to an unauthorized memory access.…

  • CVE-2026-13326MedSep 11, 2026
    risk 0.45cvss —epss 0.00

    An out-of-bounds read in Qt NFC's language code length parsing allows a physically proximate attacker to cause a denial of service or limited memory disclosure via a crafted NFC tag.

  • CVE-2025-14576HigApr 30, 2026
    risk 0.44cvss 7.8epss 0.00

    Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaScript code injection when loading malicious SVG files through the VectorImage component in Qt Quick. While QML execution is typically more restricted than native code execution, this could still lead…

  • CVE-2023-45872MedOct 9, 2024
    risk 0.42cvss 6.5epss 0.00

    An issue was discovered in Qt before 6.2.11 and 6.3.x through 6.6.x before 6.6.1. When a QML image refers to an image whose content is not known yet, there is an assumption that it is an SVG document, leading to a denial of service (application crash) if it is not actually an…

  • CVE-2024-30161MedMar 24, 2024
    risk 0.42cvss 6.5epss 0.00

    In Qt 6.5.4, 6.5.5, and 6.6.2, QNetworkReply header data might be accessed via a dangling pointer in Qt for WebAssembly (wasm). (Earlier and later versions are unaffected.)

  • CVE-2023-32573MedMay 10, 2023
    risk 0.42cvss 6.5epss 0.01

    In Qt before 5.15.14, 6.0.x through 6.2.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1, QtSvg QSvgFont m_unitsPerEm initialization is mishandled.

  • CVE-2016-11034MedApr 7, 2020
    risk 0.42cvss 6.5epss 0.00

    An issue was discovered on Samsung mobile devices with L(5.0/5.1) and M(6.0) software. The decode function in Qjpeg in Qt 5.7 allows attackers to trigger a system crash via a malformed image. The Samsung ID is SVE-2016-6560 (October 2016).

  • CVE-2018-19871MedDec 26, 2018
    risk 0.42cvss 6.5epss 0.02

    An issue was discovered in Qt before 5.11.3. There is QTgaFile Uncontrolled Resource Consumption.

  • CVE-2018-19869MedDec 26, 2018
    risk 0.42cvss 6.5epss 0.02

    An issue was discovered in Qt before 5.11.3. A malformed SVG image causes a segmentation fault in qsvghandler.cpp.

  • CVE-2026-9499MedJul 21, 2026
    risk 0.41cvss —epss 0.00

    An out-of-bounds read (buffer over-read) vulnerability exists in QTextCodec::codecForName() in Qt. When the function is called with a QByteArray that is not NUL-terminated (for example, one created with QByteArray::fromRawData()), the codec-name matching routine reads past the…

  • CVE-2025-30348MedMar 21, 2025
    risk 0.38cvss 5.8epss 0.00

    encodeText in QDom in Qt before 6.8.0 has a complex algorithm involving XML string copy and inline replacement of parts of a string (with relocation of later data).

  • CVE-2020-0569MedNov 23, 2020
    risk 0.37cvss 5.7epss 0.01

    Out of bounds write in Intel(R) PROSet/Wireless WiFi products on Windows 10 may allow an authenticated user to potentially enable denial of service via local access.

  • CVE-2025-5683MedJun 5, 2025
    risk 0.36cvss 5.5epss 0.00

    When loading a specifically crafted ICNS format image file in QImage then it will trigger a crash.  This issue affects Qt from versions 6.3.0 through 6.5.9, from 6.6.0 through 6.8.4, 6.9.0. This is fixed in 6.5.10, 6.8.5 and 6.9.1.

  • CVE-2023-43114MedSep 18, 2023
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in Qt before 5.15.16, 6.x before 6.2.10, and 6.3.x through 6.5.x before 6.5.3 on Windows. When using the GDI font engine, if a corrupted font is loaded via QFontDatabase::addApplicationFont{FromData], then it can cause the application to crash because of…

  • CVE-2021-28025MedAug 11, 2023
    risk 0.36cvss 5.5epss 0.00

    Integer Overflow vulnerability in qsvghandler.cpp in Qt qtsvg versions 5.15.1, 6.0.0, 6.0.2, and 6.2, allows local attackers to cause a denial of service (DoS).

  • CVE-2018-19872MedMar 21, 2019
    risk 0.36cvss 5.5epss 0.01

    An issue was discovered in Qt 5.11. A malformed PPM image causes a division by zero and a crash in qppmhandler.cpp.

  • CVE-2016-10040MedMar 7, 2017
    risk 0.36cvss 5.5epss 0.02

    Stack-based buffer overflow in QXmlSimpleReader in Qt 4.8.5 allows remote attackers to cause a denial of service (application crash) via a xml file with multiple nested open tags.

Page 1 of 2