CVE-2026-79680
- EPSS 0.34%
- Veröffentlicht 24.09.2026 10:56:08
- Zuletzt bearbeitet 24.09.2026 21:08:22
Authentication bypass vulnerability in the password authentication mechanism of the Qt VNC Server module. An attacker using a specially modified VNC client that violates the RFB protocol can bypass Qt VNC Server's password authentication and gain una...
CVE-2026-78253
- EPSS 0.25%
- Veröffentlicht 23.09.2026 11:39:03
- Zuletzt bearbeitet 24.09.2026 21:08:22
Uncontrolled recursion in QXmlStreamReader::readElementText() in Qt Group Qt allows attackers to cause a denial of service (application crash via stack exhaustion) via a crafted XML document.
CVE-2026-79616
- EPSS 0.11%
- Veröffentlicht 23.09.2026 09:51:47
- Zuletzt bearbeitet 24.09.2026 21:08:22
Out-of-bounds read while parsing untrusted SVG path strings in Qt Quick's Context2D.path / PathSvg.path.
CVE-2026-76151
- EPSS 0.64%
- Veröffentlicht 16.09.2026 10:16:52
- Zuletzt bearbeitet 18.09.2026 19:21:34
Out-of-bounds read (buffer over-read) in the HTTP Cache-Control response header parsing in the QtNetwork module in Qt Group Qt 6.0.0 through 6.8.8, and 6.9.0 through 6.11.1, allows remote attackers to cause a denial of service (application crash) via...
CVE-2026-19248
- EPSS 0.41%
- Veröffentlicht 16.09.2026 06:37:40
- Zuletzt bearbeitet 18.09.2026 19:21:34
QDomDocument XML parsing is vulnerable to a remotely-triggerable denial-of-service crash when processing untrusted input.
CVE-2026-13326
- EPSS 0.15%
- Veröffentlicht 11.09.2026 06:11:01
- Zuletzt bearbeitet 18.09.2026 19:21:34
An out-of-bounds read in Qt NFC's language code length parsing allows a physically proximate attacker to cause a denial of service or limited memory disclosure via a crafted NFC tag.
CVE-2026-11573
- EPSS 0.31%
- Veröffentlicht 08.09.2026 12:06:08
- Zuletzt bearbeitet 11.09.2026 10:16:50
Uncontrolled recursion (CWE-674) in the QDomDocument/QDomNode serialization path of the Qt XML module (QtXml, qtbase). QDomElementPrivate::save() and QDomNodePrivate::save() recurse mutually, consuming one stack frame per level of element nesting wit...
CVE-2026-15037
- EPSS 0.26%
- Veröffentlicht 23.07.2026 12:33:11
- Zuletzt bearbeitet 23.07.2026 15:25:49
Improper output neutralization (XML injection) in QDom comment, CDATA, and processing-instruction serialization in Qt XML from 4.0.0 through 6.11 allows untrusted text serialized by an application into those nodes to inject arbitrary XML markup, beca...
CVE-2026-9499
- EPSS 0.3%
- Veröffentlicht 21.07.2026 13:25:27
- Zuletzt bearbeitet 23.07.2026 15:25:49
An out-of-bounds read (buffer over-read) vulnerability exists in QTextCodec::codecForName() in Qt. When the function is called with a QByteArray that is not NUL-terminated (for example, one created with QByteArray::fromRawData()), the codec-name matc...
CVE-2025-14575
- EPSS 0.09%
- Veröffentlicht 19.05.2026 13:01:33
- Zuletzt bearbeitet 29.07.2026 10:16:35
An Uncontrolled Search Path Element vulnerability in the OpenSSL TLS backend of Qt Network (qtbase) in Qt Qt Framework (Unix) allows a local attacker to load a rogue CA certificate as a trusted system authority via a crafted certificate file placed i...