← Back

Qt

qt

Vendor: Qt • 58 CVEs

CVEs (58)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Qt
1Qt
Jun 17, 2026
Mar 2, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Qt through 5.15.8 and 6.x through 6.2.3 can load system library files from an unintended working directory.
1Qt
1Qt
Jun 17, 2026
Feb 16, 2022
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
In Qt 5.9.x through 5.15.x before 5.15.9 and 6.x before 6.2.4 on Linux and UNIX, QProcess could execute a binary from the current working directory when not found in the PATH.
2Fedoraproject
Qt
2Fedora
Qt
Jun 17, 2026
Aug 12, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Qt 5.x before 5.15.6 and 6.x through 6.1.2 has an out-of-bounds write in QOutlineMapper::convertPath (called from QRasterPaintEngine::fill and QPaintEngineEx::stroke).
1Qt
1Qt
Jun 17, 2026
Aug 9, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
An issue has been fixed in Qt versions 5.14.0 where QPluginLoader attempts to load plugins relative to the working directory, allowing attackers to execute arbitrary code via crafted files.
5Canonical
DebianIntel+2 more
157265 Firmware
Ac 3165 FirmwareAc 3168 Firmware+12 more
Jun 17, 2026
Nov 23, 2020
N/A· v4
5.7 MEDIUM· v3
2.7 LOW· v2
Out of bounds write in Intel(R) PROSet/Wireless WiFi products on Windows 10 may allow an authenticated user to potentially enable denial of service via local access.
2Qt
Redhat
2Enterprise Linux
Qt
Jun 17, 2026
Sep 14, 2020
N/A· v4
7.3 HIGH· v3
4.4 MEDIUM· v2
Uncontrolled search path in the QT Library before 5.14.0, 5.12.7 and 5.9.10 may allow an authenticated user to potentially enable elevation of privilege via local access.
3Debian
FedoraprojectQt
3Debian Linux
FedoraQt
Jun 17, 2026
Aug 12, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered in Qt through 5.12.9, and 5.13.x through 5.15.x before 5.15.1. read_xbm_body in gui/image/qxbmhandler.cpp has a buffer over-read.
4Fedoraproject
MumbleOpensuse+1 more
4Fedora
LeapMumble+1 more
Jun 17, 2026
Jun 9, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Qt 5.12.2 through 5.14.2, as used in unofficial builds of Mumble 1.3.0 and other products, mishandles OpenSSL's error queue, which can cause a denial of service to QSslSocket users. Because errors leak in unrelated TLS s...Show more
Qt 5.12.2 through 5.14.2, as used in unofficial builds of Mumble 1.3.0 and other products, mishandles OpenSSL's error queue, which can cause a denial of service to QSslSocket users. Because errors leak in unrelated TLS sessions, an unrelated session may be disconnected when any handshake fails. (Mumble 1.3.1 is not affected, regardless of the Qt version.)Show less
1Qt
1Qt
Jun 17, 2026
Apr 27, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
setMarkdown in Qt before 5.14.2 has a use-after-free related to QTextMarkdownImporter::insertBlock.
1Qt
1Qt
Nov 21, 2024
Feb 28, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Qt through 5.14.1, the WebSocket implementation accepts up to 2GB for frames and 2GB for messages. Smaller limits cannot be configured. This makes it easier for attackers to cause a denial of service (memory consumpti...Show more
In Qt through 5.14.1, the WebSocket implementation accepts up to 2GB for frames and 2GB for messages. Smaller limits cannot be configured. This makes it easier for attackers to cause a denial of service (memory consumption).Show less
2Fedoraproject
Qt
2Fedora
Qt
Nov 21, 2024
Jan 24, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Qt through 5.14 allows an exponential XML entity expansion attack via a crafted SVG document that is mishandled in QXmlStreamReader, a related issue to CVE-2003-1564.
3Fedoraproject
OpensuseQt
3Fedora
LeapQt
Nov 21, 2024
Mar 21, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Qt 5.11. A malformed PPM image causes a division by zero and a crash in qppmhandler.cpp.
4Canonical
DebianOpensuse+1 more
5Backports
Debian LinuxLeap+2 more
Feb 11, 2025
Dec 26, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in Qt before 5.11.3. QBmpHandler has a buffer overflow via BMP data.
2Opensuse
Qt
2Leap
Qt
Nov 21, 2024
Dec 26, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Qt before 5.11.3. There is QTgaFile Uncontrolled Resource Consumption.
3Debian
OpensuseQt
3Debian Linux
LeapQt
Nov 21, 2024
Dec 26, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in Qt before 5.11.3. A malformed GIF image causes a NULL pointer dereference in QGifHandler resulting in a segmentation fault.
2Opensuse
Qt
2Leap
Qt
Nov 21, 2024
Dec 26, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Qt before 5.11.3. A malformed SVG image causes a segmentation fault in qsvghandler.cpp.
3Debian
OpensuseQt
3Debian Linux
LeapQt
Nov 21, 2024
Dec 26, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
QXmlStream in Qt 5.x before 5.11.3 has a double-free or corruption during parsing of a specially crafted illegal XML document.
2Opensuse
Qt
2Leap
Qt
Nov 21, 2024
Dec 5, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A keystroke logging issue was discovered in Virtual Keyboard in Qt 5.7.x, 5.8.x, 5.9.x, 5.10.x, and 5.11.x before 5.11.3.
3Google
OpensuseQt
3Chrome
LeapQt
Nov 21, 2024
Jan 9, 2018
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
The Google V8 engine, as used in Google Chrome before 44.0.2403.89 and QtWebEngineCore in Qt before 5.5.1, allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a crafted...Show more
The Google V8 engine, as used in Google Chrome before 44.0.2403.89 and QtWebEngineCore in Qt before 5.5.1, allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a crafted web site.Show less
1Qt
1Qt
May 13, 2026
Dec 16, 2017
N/A· v4
5.3 MEDIUM· v3
6.8 MEDIUM· v2
A vulnerability in applications created using Qt for Android prior to 5.9.3 allows attackers to alter environment variables via unspecified vectors.