Digia maintains the Qt framework, a widely embedded cross-platform application development library that reaches into a vast downstream ecosystem despite its narrow direct product scope. Vulnerabilities in Qt recur through input-validation and memory-safety issues—improper bounds checking and sensitive-information exposure—that reflect the parsing and data-handling complexity inherent to a large, feature-rich GUI toolkit, and the vendor's disclosures tend to acquire public exploit tooling. Defenders should inventory downstream applications and embedded systems that depend on Qt rather than tracking the library alone, since remediation typically flows through vendors that bundle or link it; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Digia over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-2621MEDIUM The QSslSocketBackendPrivate::transmit function in src_network_ssl_qsslsocket_openssl.cpp in Qt 4.6.3 and earlier allows remote attackers to cause a denial of service (infinite loo | Jul 2, 2010 | 5.0 | 32 | NO | YES |
CVE-2015-1860MEDIUM Multiple buffer overflows in gui/image/qgifhandler.cpp in the QtBase module in Qt before 4.8.7 and 5.x before 5.4.2 allow remote attackers to cause a denial of service (segmentatio | May 12, 2015 | 6.8 | 21 | NO | NO |
CVE-2015-0295MEDIUM The BMP decoder in QtGui in QT before 5.5 does not properly calculate the masks used to extract the color components, which allows remote attackers to cause a denial of service (di | Mar 25, 2015 | 5.0 | 21 | NO | NO |
CVE-2010-1766HIGH Off-by-one error in the WebSocketHandshake::readServerHandshake function in websockets/WebSocketHandshake.cpp in WebCore in WebKit before r56380, as used in Qt and other products, | Jul 22, 2010 | 7.5 | 21 | NO | NO |
CVE-2015-1859MEDIUM Multiple buffer overflows in plugins/imageformats/ico/qicohandler.cpp in the QtBase module in Qt before 4.8.7 and 5.x before 5.4.2 allow remote attackers to cause a denial of servi | May 12, 2015 | 6.8 | 20 | NO | NO |
CVE-2015-1858MEDIUM Multiple buffer overflows in gui/image/qbmphandler.cpp in the QtBase module in Qt before 4.8.7 and 5.x before 5.4.2 allow remote attackers to cause a denial of service (segmentatio | May 12, 2015 | 6.8 | 20 | NO | NO |
CVE-2013-4549MEDIUM QXmlSimpleReader in Qt before 5.2 allows context-dependent attackers to cause a denial of service (memory consumption) via an XML Entity Expansion (XEE) attack. | Dec 23, 2013 | 5.0 | 17 | NO | NO |
CVE-2012-5624MEDIUM The XMLHttpRequest object in Qt before 4.8.4 enables http redirection to the file scheme, which allows man-in-the-middle attackers to force the read of arbitrary local files and po | Feb 24, 2013 | 4.3 | 17 | NO | NO |
CVE-2010-5076MEDIUM QSslSocket in Qt before 4.7.0-rc1 recognizes a wildcard IP address in the subject's Common Name field of an X.509 certificate, which might allow man-in-the-middle attackers to spoo | Jun 29, 2012 | 4.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Digia.
Media articles that mention a CVE ID that affects a product developed by Digia — matched by CVE ID, not by vendor name.