CVE-2026-6210
- EPSS 0.28%
- Veröffentlicht 06.05.2026 11:59:01
- Zuletzt bearbeitet 29.07.2026 10:16:44
A type confusion vulnerability in Qt SVG allows an attacker to cause an application crash via a crafted SVG image. When processing SVG marker references, the renderer retrieves a node by its id attribute and casts it to QSvgMarker* without verifyi...
CVE-2025-12385
- EPSS 0.31%
- Veröffentlicht 03.12.2025 19:38:53
- Zuletzt bearbeitet 29.07.2026 10:16:34
Allocation of Resources Without Limits or Throttling, Improper Validation of Specified Quantity in Input vulnerability in The Qt Company Qt on Windows, MacOS, Linux, iOS, Android, x86, ARM, 64 bit, 32 bit allows Excessive Allocation. This issue aff...
CVE-2025-23050
- EPSS 0.18%
- Veröffentlicht 31.10.2025 00:00:00
- Zuletzt bearbeitet 15.04.2026 00:35:42
QLowEnergyController in Qt before 6.8.2 mishandles malformed Bluetooth ATT commands, leading to an out-of-bounds read (or division by zero). This is fixed in 5.15.19, 6.5.9, and 6.8.2.
CVE-2025-6338
- EPSS 0.4%
- Veröffentlicht 16.10.2025 09:22:14
- Zuletzt bearbeitet 29.07.2026 10:16:38
There is an incomplete cleanup vulnerability in Qt Network's Schannel support on Windows which can lead to a Denial of Service over a long period. This issue affects Qt from 5.15.0 through 6.8.3, from 6.9.0 before 6.9.2.
CVE-2025-10729
- EPSS 0.2%
- Veröffentlicht 03.10.2025 14:39:20
- Zuletzt bearbeitet 30.09.2026 23:10:00
The module will parse a <pattern> node which is not a child of a structural node. The node will be deleted after creation but might be accessed later leading to a use after free.
CVE-2025-10728
- EPSS 0.2%
- Veröffentlicht 03.10.2025 14:35:02
- Zuletzt bearbeitet 29.07.2026 10:16:32
When the module renders a Svg file that contains a <pattern> element, it might end up rendering it recursively leading to stack overflow DoS
CVE-2025-5992
- EPSS 0.28%
- Veröffentlicht 11.07.2025 06:45:15
- Zuletzt bearbeitet 29.07.2026 10:16:37
When passing values outside of the expected range to QColorTransferGenericFunction it can cause a denial of service, for example, this can happen when passing a specifically crafted ICC profile to QColorSpace::fromICCProfile. This issue affects Qt f...
CVE-2025-5991
- EPSS 0.12%
- Veröffentlicht 11.06.2025 07:33:41
- Zuletzt bearbeitet 29.07.2026 10:16:36
There is a "Use After Free" vulnerability in Qt's QHttp2ProtocolHandler in the QtNetwork module. This only affects HTTP/2 handling, HTTP handling is not affected by this at all. This happens due to a race condition between how QHttp2Stream uploads th...
CVE-2025-5683
- EPSS 0.2%
- Veröffentlicht 05.06.2025 05:31:13
- Zuletzt bearbeitet 29.07.2026 09:16:28
When loading a specifically crafted ICNS format image file in QImage then it will trigger a crash. This issue affects Qt from versions 6.3.0 through 6.5.9, from 6.6.0 through 6.8.4, 6.9.0. This is fixed in 6.5.10, 6.8.5 and 6.9.1.
CVE-2025-5455
- EPSS 0.32%
- Veröffentlicht 02.06.2025 08:46:20
- Zuletzt bearbeitet 29.07.2026 09:16:28
An issue was found in the private API function qDecodeDataUrl() in QtCore, which is used in QTextDocument and QNetworkReply, and, potentially, in user code. If the function was called with malformed data, for example, an URL that contained a "char...