Vulnerabilidades en Qt
19 resultadosAnálisis Vexday
Qt possui 4 vulnerabilidades catalogadas, sendo 2 publicadas nos últimos 90 dias, porém nenhuma está sob ataque ativo no momento. A fraqueza predominante é leitura fora dos limites (CWE-125), típica de questões de memory safety, e não há vulnerabilidades críticas registradas, reduzindo o risco imediato para organizações que utilizam o framework.
CVE-2025-6338CRITICALPossible denial of service with multiple incoming connections to a Schannel based server with a TLS backendEPSS 0.4%CVE-2025-30348MEDIUMencodeText in QDom in Qt before 6.8.0 has a complex algorithm involving XML string copy and inline replacement of parts of a string (with reEPSS 0.3%CVE-2025-5455HIGHPossible denial of service when passing malformed data in a URL to qDecodeDataUrlEPSS 0.3%CVE-2025-12385HIGHImproper validation of <img> tag size in Text component parserEPSS 0.3%CVE-2026-9499MEDIUMOut-of-bounds read in QTextCodec::codecForName() in QtEPSS 0.3%CVE-2026-12593HIGHPrivilege escalation via forged API token creation in Axivion Dashboard OIDC/OAuth2/SSO subsystemEPSS 0.3%CVE-2026-6210HIGHType confusion and heap-buffer-overflow in Qt SVG marker handling causing application crashEPSS 0.3%CVE-2025-5992LOWPassing values outside of expected range to QColorTransferGenericFunction can cause a denial of serviceEPSS 0.3%CVE-2026-15037LOWXML injection vulnerability in QDom comment, CDATA and processing-instruction serializationEPSS 0.3%CVE-2025-3512MEDIUMBuffer overflow in QTextMarkdownImporterEPSS 0.2%CVE-2025-14576HIGHPossible QML code injection in VectorImage componentEPSS 0.2%CVE-2025-5683MEDIUMWhen loading a specifically crafted ICNS format image file in QImage then it will trigger a crash.
This issue affects Qt from versions 6.3EPSS 0.2%CVE-2025-10729CRITICALUse-after-free vulnerability in Qt SVG qsvghandler.cpp allows denial of service via crafted SVGEPSS 0.2%CVE-2025-10728CRITICALUncontrolled recursion in Qt SVG moduleEPSS 0.2%CVE-2025-4211HIGHImproper Link Resolution Before File Access in QFileSystemEngine on WindowsEPSS 0.2%CVE-2025-23050LOWQLowEnergyController in Qt before 6.8.2 mishandles malformed Bluetooth ATT commands, leading to an out-of-bounds read (or division by zero).EPSS 0.2%CVE-2026-12379MEDIUMURL Redirection to Untrusted Site ('Open Redirect') vulnerability in the Dashboard OAuth/OIDC implementation of AxivionEPSS 0.1%CVE-2025-5991LOWUse after free in QHttp2ProtocolHandlerEPSS 0.1%CVE-2025-14575LOWUncontrolled Search Path Element in Qt Network OpenSSL TLS backend allows rogue CA certificate loadingEPSS 0.1%