Vulnerabilities > QT > QT

DATE CVE VULNERABILITY TITLE RISK
2020-08-12 CVE-2020-17507 Out-of-bounds Read vulnerability in multiple products
An issue was discovered in Qt through 5.12.9, and 5.13.x through 5.15.x before 5.15.1.
network
low complexity
qt debian fedoraproject CWE-125
5.3
2020-06-09 CVE-2020-13962 Qt 5.12.2 through 5.14.2, as used in unofficial builds of Mumble 1.3.0 and other products, mishandles OpenSSL's error queue, which can cause a denial of service to QSslSocket users.
network
low complexity
mumble qt fedoraproject opensuse
7.5
2020-04-27 CVE-2020-12267 Use After Free vulnerability in QT 5.14.1
setMarkdown in Qt before 5.14.2 has a use-after-free related to QTextMarkdownImporter::insertBlock.
network
low complexity
qt CWE-416
critical
9.8
2020-02-28 CVE-2018-21035 Allocation of Resources Without Limits or Throttling vulnerability in QT
In Qt through 5.14.1, the WebSocket implementation accepts up to 2GB for frames and 2GB for messages.
network
low complexity
qt CWE-770
5.0
2020-01-24 CVE-2015-9541 XML Entity Expansion vulnerability in multiple products
Qt through 5.14 allows an exponential XML entity expansion attack via a crafted SVG document that is mishandled in QXmlStreamReader, a related issue to CVE-2003-1564.
network
low complexity
qt fedoraproject CWE-776
7.5
2019-03-21 CVE-2018-19872 Divide By Zero vulnerability in multiple products
An issue was discovered in Qt 5.11.
local
low complexity
qt opensuse fedoraproject CWE-369
5.5
2018-12-26 CVE-2018-19873 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
An issue was discovered in Qt before 5.11.3.
network
low complexity
qt debian opensuse CWE-119
7.5
2018-12-26 CVE-2018-19871 Resource Exhaustion vulnerability in multiple products
An issue was discovered in Qt before 5.11.3.
network
qt opensuse CWE-400
4.3
2018-12-26 CVE-2018-19870 NULL Pointer Dereference vulnerability in multiple products
An issue was discovered in Qt before 5.11.3.
6.8
2018-12-26 CVE-2018-19869 Improper Input Validation vulnerability in multiple products
An issue was discovered in Qt before 5.11.3.
network
qt opensuse CWE-20
4.3