QT
QT · 65 CVEs
Authentication bypass vulnerability in the password authentication mechanism of the Qt VNC Server module
Sep 24, 2026
Denial-of-service (stack-exhaustion) vulnerability in QXmlStreamReader::readElementText() impacts Qt
Sep 23, 2026
Out-of-bounds read vulnerability in Context2D.path and PathSvg.path properties impacts Qt Quick
Sep 23, 2026
Out-of-bounds read (buffer over-read) vulnerability in HTTP Cache-Control response header parsing impacts Qt Framework…
Sep 16, 2026
Unbounded recursion vulnerability in the QDomNode destructor of Qt XML impacts Qt
Sep 16, 2026
Out-of-bounds read and integer underflow vulnerability in QNdefNfcTextRecord impacts Qt NFC module
Sep 11, 2026
Uncontrolled recursion in QDomDocument/QDomNode serialization causes stack exhaustion (QtXml)
Sep 8, 2026
XML injection vulnerability in QDom comment, CDATA and processing-instruction serialization
Jul 23, 2026
Out-of-bounds read in QTextCodec::codecForName() in Qt
Jul 21, 2026
Uncontrolled Search Path Element in Qt Network OpenSSL TLS backend allows rogue CA certificate loading
May 19, 2026
Type confusion and heap-buffer-overflow in Qt SVG marker handling causing application crash
May 6, 2026
Possible QML code injection in VectorImage component
Apr 30, 2026
Improper validation of <img> tag size in Text component parser
Dec 3, 2025
qt: qt5: qt6: Qt missing length checks
Oct 31, 2025
Possible denial of service with multiple incoming connections to a Schannel based server with a TLS backend
Oct 16, 2025
Use-after-free vulnerability in Qt SVG qsvghandler.cpp allows denial of service via crafted SVG
Oct 3, 2025
Uncontrolled recursion in Qt SVG module
Oct 3, 2025
Passing values outside of expected range to QColorTransferGenericFunction can cause a denial of service
Jul 11, 2025
Use after free in QHttp2ProtocolHandler
Jun 11, 2025
qt: Qt ICNS Image Crash Vulnerability
Jun 5, 2025
Possible denial of service when passing malformed data in a URL to qDecodeDataUrl
Jun 2, 2025
Improper Link Resolution Before File Access in QFileSystemEngine on Windows
May 16, 2025
Buffer overflow in QTextMarkdownImporter
Apr 11, 2025
encodeText in QDom in Qt before 6.8.0 has a complex algorithm involving XML string copy and inline replacement of parts…
Mar 21, 2025
qtbase: qtbase: Delay any communication until encrypted() can be responded to
Jul 4, 2024
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-79680 | Authentication bypass vulnerability in the password authentication mechanism of the Qt VNC Server module | MEDIUM | 0.34% | Sep 24, 2026 |
| CVE-2026-78253 | Denial-of-service (stack-exhaustion) vulnerability in QXmlStreamReader::readElementText() impacts Qt | LOW | 0.25% | Sep 23, 2026 |
| CVE-2026-79616 | Out-of-bounds read vulnerability in Context2D.path and PathSvg.path properties impacts Qt Quick | LOW | 0.10% | Sep 23, 2026 |
| CVE-2026-76151 | Out-of-bounds read (buffer over-read) vulnerability in HTTP Cache-Control response header parsing impacts Qt Framework (QtNetwork module) | MEDIUM | 0.67% | Sep 16, 2026 |
| CVE-2026-19248 | Unbounded recursion vulnerability in the QDomNode destructor of Qt XML impacts Qt | HIGH | 0.41% | Sep 16, 2026 |
| CVE-2026-13326 | Out-of-bounds read and integer underflow vulnerability in QNdefNfcTextRecord impacts Qt NFC module | MEDIUM | 0.15% | Sep 11, 2026 |
| CVE-2026-11573 | Uncontrolled recursion in QDomDocument/QDomNode serialization causes stack exhaustion (QtXml) | HIGH | 0.39% | Sep 8, 2026 |
| CVE-2026-15037 | XML injection vulnerability in QDom comment, CDATA and processing-instruction serialization | LOW | 0.44% | Jul 23, 2026 |
| CVE-2026-9499 | Out-of-bounds read in QTextCodec::codecForName() in Qt | MEDIUM | 0.30% | Jul 21, 2026 |
| CVE-2025-14575 | Uncontrolled Search Path Element in Qt Network OpenSSL TLS backend allows rogue CA certificate loading | LOW | 0.09% | May 19, 2026 |
| CVE-2026-6210 | Type confusion and heap-buffer-overflow in Qt SVG marker handling causing application crash | HIGH | 0.47% | May 6, 2026 |
| CVE-2025-14576 | Possible QML code injection in VectorImage component | HIGH | 0.22% | Apr 30, 2026 |
| CVE-2025-12385 | Improper validation of <img> tag size in Text component parser | HIGH | 0.32% | Dec 3, 2025 |
| CVE-2025-23050 | qt: qt5: qt6: Qt missing length checks | LOW | 0.19% | Oct 31, 2025 |
| CVE-2025-6338 | Possible denial of service with multiple incoming connections to a Schannel based server with a TLS backend | CRITICAL | 0.43% | Oct 16, 2025 |
| CVE-2025-10729 | Use-after-free vulnerability in Qt SVG qsvghandler.cpp allows denial of service via crafted SVG | CRITICAL | 0.22% | Oct 3, 2025 |
| CVE-2025-10728 | Uncontrolled recursion in Qt SVG module | CRITICAL | 0.22% | Oct 3, 2025 |
| CVE-2025-5992 | Passing values outside of expected range to QColorTransferGenericFunction can cause a denial of service | LOW | 0.29% | Jul 11, 2025 |
| CVE-2025-5991 | Use after free in QHttp2ProtocolHandler | LOW | 0.14% | Jun 11, 2025 |
| CVE-2025-5683 | qt: Qt ICNS Image Crash Vulnerability | MEDIUM | 0.24% | Jun 5, 2025 |
| CVE-2025-5455 | Possible denial of service when passing malformed data in a URL to qDecodeDataUrl | HIGH | 0.38% | Jun 2, 2025 |
| CVE-2025-4211 | Improper Link Resolution Before File Access in QFileSystemEngine on Windows | HIGH | 0.20% | May 16, 2025 |
| CVE-2025-3512 | Buffer overflow in QTextMarkdownImporter | MEDIUM | 0.23% | Apr 11, 2025 |
| CVE-2025-30348 | encodeText in QDom in Qt before 6.8.0 has a complex algorithm involving XML string copy and inline replacement of parts of a string (with relocation of later d… | MEDIUM | 0.36% | Mar 21, 2025 |
| CVE-2024-39936 | qtbase: qtbase: Delay any communication until encrypted() can be responded to | HIGH | 0.49% | Jul 4, 2024 |
Showing 1 to 25 of 65 CVEs