← Back

Qt

qt

Vendor: Digia • 9 CVEs

CVEs (9)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Digia
FedoraprojectQt
3Fedora
QtQt
May 6, 2026
May 12, 2015
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple buffer overflows in gui/image/qgifhandler.cpp in the QtBase module in Qt before 4.8.7 and 5.x before 5.4.2 allow remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary...Show more
Multiple buffer overflows in gui/image/qgifhandler.cpp in the QtBase module in Qt before 4.8.7 and 5.x before 5.4.2 allow remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a crafted GIF image.Show less
3Digia
FedoraprojectQt
3Fedora
QtQt
May 6, 2026
May 12, 2015
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple buffer overflows in plugins/imageformats/ico/qicohandler.cpp in the QtBase module in Qt before 4.8.7 and 5.x before 5.4.2 allow remote attackers to cause a denial of service (segmentation fault and crash) and po...Show more
Multiple buffer overflows in plugins/imageformats/ico/qicohandler.cpp in the QtBase module in Qt before 4.8.7 and 5.x before 5.4.2 allow remote attackers to cause a denial of service (segmentation fault and crash) and possibly execute arbitrary code via a crafted ICO image.Show less
3Digia
FedoraprojectQt
3Fedora
QtQt
May 6, 2026
May 12, 2015
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple buffer overflows in gui/image/qbmphandler.cpp in the QtBase module in Qt before 4.8.7 and 5.x before 5.4.2 allow remote attackers to cause a denial of service (segmentation fault and crash) and possibly execute...Show more
Multiple buffer overflows in gui/image/qbmphandler.cpp in the QtBase module in Qt before 4.8.7 and 5.x before 5.4.2 allow remote attackers to cause a denial of service (segmentation fault and crash) and possibly execute arbitrary code via a crafted BMP image.Show less
3Digia
FedoraprojectOpensuse
3Fedora
OpensuseQt
May 6, 2026
Mar 25, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The BMP decoder in QtGui in QT before 5.5 does not properly calculate the masks used to extract the color components, which allows remote attackers to cause a denial of service (divide-by-zero and crash) via a crafted BM...Show more
The BMP decoder in QtGui in QT before 5.5 does not properly calculate the masks used to extract the color components, which allows remote attackers to cause a denial of service (divide-by-zero and crash) via a crafted BMP file.Show less
2Digia
Qt
2Qt
Qt
Apr 29, 2026
Dec 23, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
QXmlSimpleReader in Qt before 5.2 allows context-dependent attackers to cause a denial of service (memory consumption) via an XML Entity Expansion (XEE) attack.
3Canonical
DigiaQt
3Qt
QtUbuntu Linux
Apr 29, 2026
Feb 24, 2013
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The XMLHttpRequest object in Qt before 4.8.4 enables http redirection to the file scheme, which allows man-in-the-middle attackers to force the read of arbitrary local files and possibly obtain sensitive information via...Show more
The XMLHttpRequest object in Qt before 4.8.4 enables http redirection to the file scheme, which allows man-in-the-middle attackers to force the read of arbitrary local files and possibly obtain sensitive information via a file: URL to a QML application.Show less
2Digia
Qt
2Qt
Qt
Apr 29, 2026
Jun 29, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
QSslSocket in Qt before 4.7.0-rc1 recognizes a wildcard IP address in the subject's Common Name field of an X.509 certificate, which might allow man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted ce...Show more
QSslSocket in Qt before 4.7.0-rc1 recognizes a wildcard IP address in the subject's Common Name field of an X.509 certificate, which might allow man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority.Show less
2Digia
Webkit
2Qt
Webkit
Apr 29, 2026
Jul 22, 2010
N/A· v4
N/A· v3
7.5 HIGH· v2
Off-by-one error in the WebSocketHandshake::readServerHandshake function in websockets/WebSocketHandshake.cpp in WebCore in WebKit before r56380, as used in Qt and other products, allows remote websockets servers to caus...Show more
Off-by-one error in the WebSocketHandshake::readServerHandshake function in websockets/WebSocketHandshake.cpp in WebCore in WebKit before r56380, as used in Qt and other products, allows remote websockets servers to cause a denial of service (memory corruption) or possibly have unspecified other impact via an upgrade header that is long and invalid.Show less
2Digia
Qt
2Qt
Qt
Apr 29, 2026
Jul 2, 2010
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The QSslSocketBackendPrivate::transmit function in src_network_ssl_qsslsocket_openssl.cpp in Qt 4.6.3 and earlier allows remote attackers to cause a denial of service (infinite loop) via a malformed request.