Skip to main content

Vendor archive

qt CVEs

Beta · best-effort

63 CVEs tagged to vendor qt7 Critical, 22 High, 33 Medium, 1 Low, 0 Unrated.

CVE-2020-24742

Published Aug 9, 2021

An issue has been fixed in Qt versions 5.14.0 where QPluginLoader attempts to load plugins relative to the working directory, allowing attackers to execute arbitrary code via craf…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-0570

Published Sep 14, 2020

Uncontrolled search path in the QT Library before 5.14.0, 5.12.7 and 5.9.10 may allow an authenticated user to potentially enable elevation of privilege via local access.

CVSS 7.3 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-12267

Published Apr 27, 2020

setMarkdown in Qt before 5.14.2 has a use-after-free related to QTextMarkdownImporter::insertBlock.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-21035

Published Feb 28, 2020

In Qt through 5.14.1, the WebSocket implementation accepts up to 2GB for frames and 2GB for messages. Smaller limits cannot be configured. This makes it easier for attackers to ca…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-9541

Published Jan 24, 2020

Qt through 5.14 allows an exponential XML entity expansion attack via a crafted SVG document that is mishandled in QXmlStreamReader, a related issue to CVE-2003-1564.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-18281

Published Oct 23, 2019

An out-of-bounds memory access in the generateDirectionalRuns() function in qtextengine.cpp in Qt qtbase 5.11.x and 5.12.x before 5.12.5 allows attackers to cause a denial of serv…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-19871

Published Dec 26, 2018

An issue was discovered in Qt before 5.11.3. There is QTgaFile Uncontrolled Resource Consumption.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-19869

Published Dec 26, 2018

An issue was discovered in Qt before 5.11.3. A malformed SVG image causes a segmentation fault in qsvghandler.cpp.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-19865

Published Dec 5, 2018

A keystroke logging issue was discovered in Virtual Keyboard in Qt 5.7.x, 5.8.x, 5.9.x, 5.10.x, and 5.11.x before 5.11.3.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-1290

Published Jan 9, 2018

The Google V8 engine, as used in Google Chrome before 44.0.2403.89 and QtWebEngineCore in Qt before 5.5.1, allows remote attackers to cause a denial of service (memory corruption)…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-10905

Published Dec 16, 2017

A vulnerability in applications created using Qt for Android prior to 5.9.3 allows attackers to alter environment variables via unspecified vectors.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-10904

Published Dec 16, 2017

Qt for Android prior to 5.9.0 allows remote attackers to execute arbitrary OS commands via unspecified vectors.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-15011

Published Oct 4, 2017

The named pipes in qtsingleapp in Qt 5.x, as used in qBittorrent and SugarSync, are configured for remote access and allow remote attackers to cause a denial of service (applicati…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-8079

Published Sep 7, 2017

qt5-qtwebkit before 5.4 records private browsing URLs to its favicon database, WebpageIcons.db.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-10040

Published Mar 7, 2017

Stack-based buffer overflow in QXmlSimpleReader in Qt 4.8.5 allows remote attackers to cause a denial of service (application crash) via a xml file with multiple nested open tags.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-7298

Published Oct 26, 2015

ownCloud Desktop Client before 2.0.1, when compiled with a Qt release after 5.3.x, does not call QNetworkReply::ignoreSslErrors with the list of errors to be ignored, which makes…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1860

Published May 12, 2015

Multiple buffer overflows in gui/image/qgifhandler.cpp in the QtBase module in Qt before 4.8.7 and 5.x before 5.4.2 allow remote attackers to cause a denial of service (segmentati…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1859

Published May 12, 2015

Multiple buffer overflows in plugins/imageformats/ico/qicohandler.cpp in the QtBase module in Qt before 4.8.7 and 5.x before 5.4.2 allow remote attackers to cause a denial of serv…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1858

Published May 12, 2015

Multiple buffer overflows in gui/image/qbmphandler.cpp in the QtBase module in Qt before 4.8.7 and 5.x before 5.4.2 allow remote attackers to cause a denial of service (segmentati…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 26-50 of 63 CVEsPage 2 of 3