Skip to main content

Vendor archive

qt CVEs

Beta · best-effort

63 CVEs tagged to vendor qt7 Critical, 22 High, 33 Medium, 1 Low, 0 Unrated.

CVE-2025-14576

Published Apr 30, 2026

Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaScript code injection when loading malicious SVG files through the VectorImage component in Qt Quick.…

CVSS 7.4 · High
evidence mentions
8
Buzz score
38.5
Vendor/product tagsBeta · best-effort

CVE-2025-5683

Published Jun 5, 2025

When loading a specifically crafted ICNS format image file in QImage then it will trigger a crash.  This issue affects Qt from versions 6.3.0 through 6.5.9, from 6.6.0 through 6.…

CVSS 5.1 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2025-30348

Published Mar 21, 2025

encodeText in QDom in Qt before 6.8.0 has a complex algorithm involving XML string copy and inline replacement of parts of a string (with relocation of later data).

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-39936

Published Jul 4, 2024

An issue was discovered in HTTP2 in Qt before 5.15.18, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.7, and 6.6.x through 6.7.x before 6.7.3. Code to make security-relevant de…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2024-36048

Published May 18, 2024

QAbstractOAuth in Qt Network Authorization in Qt before 5.15.17, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.6, and 6.6.x through 6.7.x before 6.7.1 uses only the time to se…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-25580

Published Mar 27, 2024

An issue was discovered in gui/util/qktxhandler.cpp in Qt before 5.15.17, 6.x before 6.2.12, 6.3.x through 6.5.x before 6.5.5, and 6.6.x before 6.6.2. A buffer overflow and applic…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-30161

Published Mar 24, 2024

In Qt 6.5.4, 6.5.5, and 6.6.2, QNetworkReply header data might be accessed via a dangling pointer in Qt for WebAssembly (wasm). (Earlier and later versions are unaffected.)

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-51714

Published Dec 24, 2023

An issue was discovered in the HTTP2 implementation in Qt before 5.15.17, 6.x before 6.2.11, 6.3.x through 6.5.x before 6.5.4, and 6.6.x before 6.6.2. network/access/http2/hpackta…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-43114

Published Sep 18, 2023

An issue was discovered in Qt before 5.15.16, 6.x before 6.2.10, and 6.3.x through 6.5.x before 6.5.3 on Windows. When using the GDI font engine, if a corrupted font is loaded via…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-37369

Published Aug 20, 2023

In Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.2, there can be an application crash in QXmlStreamReader via a crafted XML string that triggers a situat…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-28025

Published Aug 11, 2023

Integer Overflow vulnerability in qsvghandler.cpp in Qt qtsvg versions 5.15.1, 6.0.0, 6.0.2, and 6.2, allows local attackers to cause a denial of service (DoS).

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-38197

Published Jul 13, 2023

An issue was discovered in Qt before 5.15.15, 6.x before 6.2.10, and 6.3.x through 6.5.x before 6.5.3. There are infinite loops in recursive entity expansion.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-32763

Published May 28, 2023

An issue was discovered in Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1. When a SVG file with an image inside it is rendered, a QTextLayout buffer ove…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-32762

Published May 28, 2023

An issue was discovered in Qt before 5.15.14, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1. Qt Network incorrectly parses the strict-transport-security (HSTS) header, al…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-33285

Published May 22, 2023

An issue was discovered in Qt 5.x before 5.15.14, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1. QDnsLookup has a buffer over-read via a crafted reply from a DNS server.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-32573

Published May 10, 2023

In Qt before 5.15.14, 6.0.x through 6.2.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1, QtSvg QSvgFont m_unitsPerEm initialization is mishandled.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-24607

Published Apr 15, 2023

Qt before 6.4.3 allows a denial of service via a crafted string when the SQL ODBC driver plugin is used and the size of SQLTCHAR is 4. The affected versions are 5.x before 5.15.13…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-43591

Published Jan 12, 2023

A buffer overflow vulnerability exists in the QML QtScript Reflect API of Qt Project Qt 6.3.2. A specially-crafted javascript code can trigger an out-of-bounds memory access, whic…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-40983

Published Jan 12, 2023

An integer overflow vulnerability exists in the QML QtScript Reflect API of Qt Project Qt 6.3.2. A specially-crafted javascript code can trigger an integer overflow during memory…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-3481

Published Aug 22, 2022

A flaw was found in Qt. An out-of-bounds read vulnerability was found in QRadialFetchSimd in qt/qtbase/src/gui/painting/qdrawhelper_p.h in Qt/Qtbase. While rendering and displayin…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2022-25634

Published Mar 2, 2022

Qt through 5.15.8 and 6.x through 6.2.3 can load system library files from an unintended working directory.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-25255

Published Feb 16, 2022

In Qt 5.9.x through 5.15.x before 5.15.9 and 6.x before 6.2.4 on Linux and UNIX, QProcess could execute a binary from the current working directory when not found in the PATH.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-38593

Published Aug 12, 2021

Qt 5.x before 5.15.6 and 6.x through 6.1.2 has an out-of-bounds write in QOutlineMapper::convertPath (called from QRasterPaintEngine::fill and QPaintEngineEx::stroke).

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 63 CVEsPage 1 of 3