Qt

Qt

74 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.26%
  • Veröffentlicht 23.07.2026 12:33:11
  • Zuletzt bearbeitet 23.07.2026 15:25:49

Improper output neutralization (XML injection) in QDom comment, CDATA, and processing-instruction serialization in Qt XML from 4.0.0 through 6.11 allows untrusted text serialized by an application into those nodes to inject arbitrary XML markup, beca...

  • EPSS 0.3%
  • Veröffentlicht 21.07.2026 13:25:27
  • Zuletzt bearbeitet 23.07.2026 15:25:49

An out-of-bounds read (buffer over-read) vulnerability exists in QTextCodec::codecForName() in Qt. When the function is called with a QByteArray that is not NUL-terminated (for example, one created with QByteArray::fromRawData()), the codec-name matc...

  • EPSS 0.09%
  • Veröffentlicht 19.05.2026 13:01:33
  • Zuletzt bearbeitet 29.07.2026 10:16:35

An Uncontrolled Search Path Element vulnerability in the OpenSSL TLS backend of Qt Network (qtbase) in Qt Qt Framework (Unix) allows a local attacker to load a rogue CA certificate as a trusted system authority via a crafted certificate file placed i...

  • EPSS 0.28%
  • Veröffentlicht 06.05.2026 11:59:01
  • Zuletzt bearbeitet 29.07.2026 10:16:44

A type confusion vulnerability in Qt SVG allows an attacker to cause an application crash via a crafted SVG image. When processing SVG marker references, the renderer retrieves a node by its id attribute and casts it to QSvgMarker* without verifyi...

  • EPSS 0.31%
  • Veröffentlicht 03.12.2025 19:38:53
  • Zuletzt bearbeitet 29.07.2026 10:16:34

Allocation of Resources Without Limits or Throttling, Improper Validation of Specified Quantity in Input vulnerability in The Qt Company Qt on Windows, MacOS, Linux, iOS, Android, x86, ARM, 64 bit, 32 bit allows Excessive Allocation. This issue aff...

  • EPSS 0.18%
  • Veröffentlicht 31.10.2025 00:00:00
  • Zuletzt bearbeitet 15.04.2026 00:35:42

QLowEnergyController in Qt before 6.8.2 mishandles malformed Bluetooth ATT commands, leading to an out-of-bounds read (or division by zero). This is fixed in 5.15.19, 6.5.9, and 6.8.2.

  • EPSS 0.4%
  • Veröffentlicht 16.10.2025 09:22:14
  • Zuletzt bearbeitet 29.07.2026 10:16:38

There is an incomplete cleanup vulnerability in Qt Network's Schannel support on Windows which can lead to a Denial of Service over a long period. This issue affects Qt from 5.15.0 through 6.8.3, from 6.9.0 before 6.9.2.

  • EPSS 0.2%
  • Veröffentlicht 03.10.2025 14:39:20
  • Zuletzt bearbeitet 29.07.2026 10:16:33

The module will parse a <pattern> node which is not a child of a structural node. The node will be deleted after creation but might be accessed later leading to a use after free.

  • EPSS 0.2%
  • Veröffentlicht 03.10.2025 14:35:02
  • Zuletzt bearbeitet 29.07.2026 10:16:32

When the module renders a Svg file that contains a <pattern> element, it might end up rendering it recursively leading to stack overflow DoS

  • EPSS 0.28%
  • Veröffentlicht 11.07.2025 06:45:15
  • Zuletzt bearbeitet 29.07.2026 10:16:37

When passing values outside of the expected range to QColorTransferGenericFunction it can cause a denial of service, for example, this can happen when passing a specifically crafted ICC profile to QColorSpace::fromICCProfile. This issue affects Qt f...