Vulnerability index

Browse CVEs

29 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Qtdeclarative HIGH 7.8
CVE-2025-14576

Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaScript code injection when loading malicious SVG files through the Vect…

Fix: 6.8.6 / 6.10.1+
Fix from $1,950 2026-04-30
Qt MEDIUM 5.5
CVE-2025-5683

When loading a specifically crafted ICNS format image file in QImage then it will trigger a crash.  This issue affects Qt from versions 6.3.0 throug…

Fix: 6.5.10 / 6.8.5+
Fix from $1,600 2025-06-05
Qt MEDIUM 5.3
CVE-2025-30348

encodeText in QDom in Qt before 6.8.0 has a complex algorithm involving XML string copy and inline replacement of parts of a string (with relocation …

Fix: 5.15.19 / 6.5.9+
Fix from $1,600 2025-03-21
Qt MEDIUM 5.9
CVE-2024-39936

An issue was discovered in HTTP2 in Qt before 5.15.18, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.7, and 6.6.x through 6.7.x before 6.7.3. Cod…

Fix: 5.15.18 / 6.2.13+
Fix from $1,600 2024-07-04
Qt MEDIUM 6.2
CVE-2024-25580

An issue was discovered in gui/util/qktxhandler.cpp in Qt before 5.15.17, 6.x before 6.2.12, 6.3.x through 6.5.x before 6.5.5, and 6.6.x before 6.6.2…

Fix: 5.15.17 / 6.2.12+
Fix from $1,600 2024-03-27
Qt MEDIUM 6.5
CVE-2024-30161

In Qt 6.5.4, 6.5.5, and 6.6.2, QNetworkReply header data might be accessed via a dangling pointer in Qt for WebAssembly (wasm). (Earlier and later ve…

Patch available
Fix from $1,600 2024-03-24
Qt MEDIUM 5.5
CVE-2023-43114

An issue was discovered in Qt before 5.15.16, 6.x before 6.2.10, and 6.3.x through 6.5.x before 6.5.3 on Windows. When using the GDI font engine, if …

Fix: 5.15.16 / 6.2.10+
Fix from $1,600 2023-09-18
Qt MEDIUM 5.5
CVE-2021-28025

Integer Overflow vulnerability in qsvghandler.cpp in Qt qtsvg versions 5.15.1, 6.0.0, 6.0.2, and 6.2, allows local attackers to cause a denial of ser…

No fix yet
Fix from $1,600 2023-08-11
Qt HIGH 7.5
CVE-2023-38197

An issue was discovered in Qt before 5.15.15, 6.x before 6.2.10, and 6.3.x through 6.5.x before 6.5.3. There are infinite loops in recursive entity e…

Fix: 5.15.15 / 6.2.10+
Fix from $1,950 2023-07-13
Qt HIGH 7.5
CVE-2023-32763

An issue was discovered in Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1. When a SVG file with an image inside it is rend…

Fix: 5.15.15 / 6.2.9+
Fix from $1,950 2023-05-28
Qt MEDIUM 5.3
CVE-2023-33285

An issue was discovered in Qt 5.x before 5.15.14, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1. QDnsLookup has a buffer over-read via a cra…

Fix: 5.15.4 / 6.2.9+
Fix from $1,600 2023-05-22
Qt HIGH 7.5
CVE-2023-24607

Qt before 6.4.3 allows a denial of service via a crafted string when the SQL ODBC driver plugin is used and the size of SQLTCHAR is 4. The affected v…

Fix: 5.15.13 / 6.2.8+
Fix from $1,950 2023-04-15
Qt HIGH 8.8
CVE-2022-40983

An integer overflow vulnerability exists in the QML QtScript Reflect API of Qt Project Qt 6.3.2. A specially-crafted javascript code can trigger an i…

No fix yet
Fix from $1,950 2023-01-12
Qt HIGH 8.8
CVE-2022-43591

A buffer overflow vulnerability exists in the QML QtScript Reflect API of Qt Project Qt 6.3.2. A specially-crafted javascript code can trigger an out…

No fix yet
Fix from $1,950 2023-01-12
Qt HIGH 7.1
CVE-2021-3481

A flaw was found in Qt. An out-of-bounds read vulnerability was found in QRadialFetchSimd in qt/qtbase/src/gui/painting/qdrawhelper_p.h in Qt/Qtbase.…

No fix yet
Fix from $1,950 2022-08-22
Qt HIGH 7.5
CVE-2022-25634

Qt through 5.15.8 and 6.x through 6.2.3 can load system library files from an unintended working directory.

Fix: after 6.2.3
Fix from $1,950 2022-03-02
Qt HIGH 7.8
CVE-2022-25255

In Qt 5.9.x through 5.15.x before 5.15.9 and 6.x before 6.2.4 on Linux and UNIX, QProcess could execute a binary from the current working directory w…

Fix: 5.15.9 / 6.2.4+
Fix from $1,950 2022-02-16
Qt HIGH 7.8
CVE-2020-24742

An issue has been fixed in Qt versions 5.14.0 where QPluginLoader attempts to load plugins relative to the working directory, allowing attackers to e…

Fix: 5.12.7+
Fix from $1,950 2021-08-09
Qt CRITICAL 9.8
CVE-2020-12267

setMarkdown in Qt before 5.14.2 has a use-after-free related to QTextMarkdownImporter::insertBlock.

Patch available
Fix from $2,300 2020-04-27
Qt HIGH 7.5
CVE-2018-21035

In Qt through 5.14.1, the WebSocket implementation accepts up to 2GB for frames and 2GB for messages. Smaller limits cannot be configured. This makes…

Fix: after 5.14.1
Fix from $1,950 2020-02-28
Qt MEDIUM 6.5
CVE-2018-19869

An issue was discovered in Qt before 5.11.3. A malformed SVG image causes a segmentation fault in qsvghandler.cpp.

Fix: 5.11.3+
Fix from $1,600 2018-12-26
Qt MEDIUM 6.5
CVE-2018-19871

An issue was discovered in Qt before 5.11.3. There is QTgaFile Uncontrolled Resource Consumption.

Fix: 5.11.3+
Fix from $1,600 2018-12-26
Qt HIGH 7.5
CVE-2018-19865

A keystroke logging issue was discovered in Virtual Keyboard in Qt 5.7.x, 5.8.x, 5.9.x, 5.10.x, and 5.11.x before 5.11.3.

Fix: 5.11.3+
Fix from $1,950 2018-12-05
Qt CRITICAL 9.8
CVE-2017-10904

Qt for Android prior to 5.9.0 allows remote attackers to execute arbitrary OS commands via unspecified vectors.

Fix: 5.9.0+
Fix from $2,300 2017-12-16
Qt MEDIUM 5.3
CVE-2017-10905

A vulnerability in applications created using Qt for Android prior to 5.9.3 allows attackers to alter environment variables via unspecified vectors.

Fix: 5.9.3+
Fix from $1,600 2017-12-16
Qt HIGH 7.5
CVE-2017-15011

The named pipes in qtsingleapp in Qt 5.x, as used in qBittorrent and SugarSync, are configured for remote access and allow remote attackers to cause …

Mitigation only
Fix from $1,950 2017-10-04
Qtwebkit MEDIUM 5.3
CVE-2015-8079

qt5-qtwebkit before 5.4 records private browsing URLs to its favicon database, WebpageIcons.db.

Fix: after 5.3.2
Fix from $1,600 2017-09-07
Qxmlsimplereader MEDIUM 5.5
CVE-2016-10040

Stack-based buffer overflow in QXmlSimpleReader in Qt 4.8.5 allows remote attackers to cause a denial of service (application crash) via a xml file w…

Patch available
Fix from $1,600 2017-03-07
Qt HIGH 9.3
CVE-2011-3194EPSS 7%

Buffer overflow in the TIFF reader in gui/image/qtiffhandler.cpp in Qt 4.7.4 allows remote attackers to cause a denial of service (crash) and possibl…

Mitigation only
Fix from $1,950 2012-06-16