Qt

Qt

59 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.44%
  • Published 28.02.2020 21:15:12
  • Last modified 21.11.2024 04:02:44

In Qt through 5.14.1, the WebSocket implementation accepts up to 2GB for frames and 2GB for messages. Smaller limits cannot be configured. This makes it easier for attackers to cause a denial of service (memory consumption).

  • EPSS 1.07%
  • Published 24.01.2020 22:15:12
  • Last modified 21.11.2024 02:40:53

Qt through 5.14 allows an exponential XML entity expansion attack via a crafted SVG document that is mishandled in QXmlStreamReader, a related issue to CVE-2003-1564.

Exploit
  • EPSS 0.28%
  • Published 21.03.2019 16:00:32
  • Last modified 21.11.2024 03:58:43

An issue was discovered in Qt 5.11. A malformed PPM image causes a division by zero and a crash in qppmhandler.cpp.

  • EPSS 13.42%
  • Published 26.12.2018 21:29:02
  • Last modified 11.02.2025 20:11:38

An issue was discovered in Qt before 5.11.3. QBmpHandler has a buffer overflow via BMP data.

  • EPSS 1.54%
  • Published 26.12.2018 21:29:02
  • Last modified 21.11.2024 03:58:43

An issue was discovered in Qt before 5.11.3. There is QTgaFile Uncontrolled Resource Consumption.

  • EPSS 2.62%
  • Published 26.12.2018 21:29:02
  • Last modified 21.11.2024 03:58:43

An issue was discovered in Qt before 5.11.3. A malformed GIF image causes a NULL pointer dereference in QGifHandler resulting in a segmentation fault.

  • EPSS 0.91%
  • Published 26.12.2018 21:29:02
  • Last modified 21.11.2024 03:58:43

An issue was discovered in Qt before 5.11.3. A malformed SVG image causes a segmentation fault in qsvghandler.cpp.

  • EPSS 2.18%
  • Published 26.12.2018 21:29:00
  • Last modified 21.11.2024 03:50:59

QXmlStream in Qt 5.x before 5.11.3 has a double-free or corruption during parsing of a specially crafted illegal XML document.

  • EPSS 0.8%
  • Published 05.12.2018 11:29:06
  • Last modified 21.11.2024 03:58:43

A keystroke logging issue was discovered in Virtual Keyboard in Qt 5.7.x, 5.8.x, 5.9.x, 5.10.x, and 5.11.x before 5.11.3.

  • EPSS 1.04%
  • Published 09.01.2018 16:29:00
  • Last modified 21.11.2024 02:25:05

The Google V8 engine, as used in Google Chrome before 44.0.2403.89 and QtWebEngineCore in Qt before 5.5.1, allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a crafted web site.