← Back

Qt

qt

63 CVEs • 6 products

Products (6)

Click to collapse
Toggle
Qt
qt
Qtwebkit
qtwebkit
Qtbase
qtbase
Qtsvg
qtsvg
Qtdeclarative
qtdeclarative

CVEs (63)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Qt
1Qt
Jun 17, 2026
Aug 22, 2022
N/A· v4
7.1 HIGH· v3
N/A· v2
A flaw was found in Qt. An out-of-bounds read vulnerability was found in QRadialFetchSimd in qt/qtbase/src/gui/painting/qdrawhelper_p.h in Qt/Qtbase. While rendering and displaying a crafted Scalable Vector Graphics (SVG...Show more
A flaw was found in Qt. An out-of-bounds read vulnerability was found in QRadialFetchSimd in qt/qtbase/src/gui/painting/qdrawhelper_p.h in Qt/Qtbase. While rendering and displaying a crafted Scalable Vector Graphics (SVG) file this flaw may lead to an unauthorized memory access. The highest threat from this vulnerability is to data confidentiality and the application availability.Show less
1Qt
1Qt
Jun 17, 2026
Mar 2, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Qt through 5.15.8 and 6.x through 6.2.3 can load system library files from an unintended working directory.
1Qt
1Qt
Jun 17, 2026
Feb 16, 2022
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
In Qt 5.9.x through 5.15.x before 5.15.9 and 6.x before 6.2.4 on Linux and UNIX, QProcess could execute a binary from the current working directory when not found in the PATH.
3Debian
FedoraprojectQt
3Debian Linux
FedoraQtsvg
Jun 17, 2026
Jan 1, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Qt SVG in Qt 5.0.0 through 5.15.2 and 6.0.0 through 6.2.1 has an out-of-bounds write in QtPrivate::QCommonArrayOps<QPainterPath::Element>::growAppend (called from QPainterPath::addPath and QPathClipper::intersect).
2Fedoraproject
Qt
2Fedora
Qt
Jun 17, 2026
Aug 12, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Qt 5.x before 5.15.6 and 6.x through 6.1.2 has an out-of-bounds write in QOutlineMapper::convertPath (called from QRasterPaintEngine::fill and QPaintEngineEx::stroke).
1Qt
1Qt
Jun 17, 2026
Aug 9, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
An issue has been fixed in Qt versions 5.14.0 where QPluginLoader attempts to load plugins relative to the working directory, allowing attackers to execute arbitrary code via crafted files.
5Canonical
DebianIntel+2 more
157265 Firmware
Ac 3165 FirmwareAc 3168 Firmware+12 more
Jun 17, 2026
Nov 23, 2020
N/A· v4
5.7 MEDIUM· v3
2.7 LOW· v2
Out of bounds write in Intel(R) PROSet/Wireless WiFi products on Windows 10 may allow an authenticated user to potentially enable denial of service via local access.
2Qt
Redhat
2Enterprise Linux
Qt
Jun 17, 2026
Sep 14, 2020
N/A· v4
7.3 HIGH· v3
4.4 MEDIUM· v2
Uncontrolled search path in the QT Library before 5.14.0, 5.12.7 and 5.9.10 may allow an authenticated user to potentially enable elevation of privilege via local access.
3Debian
FedoraprojectQt
3Debian Linux
FedoraQt
Jun 17, 2026
Aug 12, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered in Qt through 5.12.9, and 5.13.x through 5.15.x before 5.15.1. read_xbm_body in gui/image/qxbmhandler.cpp has a buffer over-read.
4Fedoraproject
MumbleOpensuse+1 more
4Fedora
LeapMumble+1 more
Jun 17, 2026
Jun 9, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Qt 5.12.2 through 5.14.2, as used in unofficial builds of Mumble 1.3.0 and other products, mishandles OpenSSL's error queue, which can cause a denial of service to QSslSocket users. Because errors leak in unrelated TLS s...Show more
Qt 5.12.2 through 5.14.2, as used in unofficial builds of Mumble 1.3.0 and other products, mishandles OpenSSL's error queue, which can cause a denial of service to QSslSocket users. Because errors leak in unrelated TLS sessions, an unrelated session may be disconnected when any handshake fails. (Mumble 1.3.1 is not affected, regardless of the Qt version.)Show less
1Qt
1Qt
Jun 17, 2026
Apr 27, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
setMarkdown in Qt before 5.14.2 has a use-after-free related to QTextMarkdownImporter::insertBlock.
1Qt
1Qt
Nov 21, 2024
Feb 28, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Qt through 5.14.1, the WebSocket implementation accepts up to 2GB for frames and 2GB for messages. Smaller limits cannot be configured. This makes it easier for attackers to cause a denial of service (memory consumpti...Show more
In Qt through 5.14.1, the WebSocket implementation accepts up to 2GB for frames and 2GB for messages. Smaller limits cannot be configured. This makes it easier for attackers to cause a denial of service (memory consumption).Show less
2Fedoraproject
Qt
2Fedora
Qt
Nov 21, 2024
Jan 24, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Qt through 5.14 allows an exponential XML entity expansion attack via a crafted SVG document that is mishandled in QXmlStreamReader, a related issue to CVE-2003-1564.
2Debian
Qt
2Debian Linux
Qtbase
Jun 17, 2026
Oct 23, 2019
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
An out-of-bounds memory access in the generateDirectionalRuns() function in qtextengine.cpp in Qt qtbase 5.11.x and 5.12.x before 5.12.5 allows attackers to cause a denial of service by crashing an application via a text...Show more
An out-of-bounds memory access in the generateDirectionalRuns() function in qtextengine.cpp in Qt qtbase 5.11.x and 5.12.x before 5.12.5 allows attackers to cause a denial of service by crashing an application via a text file containing many directional characters.Show less
3Fedoraproject
OpensuseQt
3Fedora
LeapQt
Nov 21, 2024
Mar 21, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Qt 5.11. A malformed PPM image causes a division by zero and a crash in qppmhandler.cpp.
4Canonical
DebianOpensuse+1 more
5Backports
Debian LinuxLeap+2 more
Feb 11, 2025
Dec 26, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in Qt before 5.11.3. QBmpHandler has a buffer overflow via BMP data.
2Opensuse
Qt
2Leap
Qt
Nov 21, 2024
Dec 26, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Qt before 5.11.3. There is QTgaFile Uncontrolled Resource Consumption.
3Debian
OpensuseQt
3Debian Linux
LeapQt
Nov 21, 2024
Dec 26, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in Qt before 5.11.3. A malformed GIF image causes a NULL pointer dereference in QGifHandler resulting in a segmentation fault.
2Opensuse
Qt
2Leap
Qt
Nov 21, 2024
Dec 26, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Qt before 5.11.3. A malformed SVG image causes a segmentation fault in qsvghandler.cpp.
3Debian
OpensuseQt
3Debian Linux
LeapQt
Nov 21, 2024
Dec 26, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
QXmlStream in Qt 5.x before 5.11.3 has a double-free or corruption during parsing of a specially crafted illegal XML document.