Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Digia

First CVE: Jul 2, 2010Active for: 16 yearsTotal CVEs: 9

Digia maintains the Qt framework, a widely embedded cross-platform application development library that reaches into a vast downstream ecosystem despite its narrow direct product scope. Vulnerabilities in Qt recur through input-validation and memory-safety issues—improper bounds checking and sensitive-information exposure—that reflect the parsing and data-handling complexity inherent to a large, feature-rich GUI toolkit, and the vendor's disclosures tend to acquire public exploit tooling. Defenders should inventory downstream applications and embedded systems that depend on Qt rather than tracking the library alone, since remediation typically flows through vendors that bundle or link it; current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
9
Total CVEs
More Total CVEs than 91% of tracked vendors
2.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 90% of tracked vendors
5.7
Avg CVSS Score
Higher Avg CVSS Score than 25% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Digia over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 2, 2010
16 years ago
Most Recent CVE
May 12, 2015
4,091 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2010-2621MEDIUM
The QSslSocketBackendPrivate::transmit function in src_network_ssl_qsslsocket_openssl.cpp in Qt 4.6.3 and earlier allows remote attackers to cause a denial of service (infinite loo
Jul 2, 20105.032NOYES
CVE-2015-1860MEDIUM
Multiple buffer overflows in gui/image/qgifhandler.cpp in the QtBase module in Qt before 4.8.7 and 5.x before 5.4.2 allow remote attackers to cause a denial of service (segmentatio
May 12, 20156.821NONO
CVE-2015-0295MEDIUM
The BMP decoder in QtGui in QT before 5.5 does not properly calculate the masks used to extract the color components, which allows remote attackers to cause a denial of service (di
Mar 25, 20155.021NONO
CVE-2010-1766HIGH
Off-by-one error in the WebSocketHandshake::readServerHandshake function in websockets/WebSocketHandshake.cpp in WebCore in WebKit before r56380, as used in Qt and other products,
Jul 22, 20107.521NONO
CVE-2015-1859MEDIUM
Multiple buffer overflows in plugins/imageformats/ico/qicohandler.cpp in the QtBase module in Qt before 4.8.7 and 5.x before 5.4.2 allow remote attackers to cause a denial of servi
May 12, 20156.820NONO
CVE-2015-1858MEDIUM
Multiple buffer overflows in gui/image/qbmphandler.cpp in the QtBase module in Qt before 4.8.7 and 5.x before 5.4.2 allow remote attackers to cause a denial of service (segmentatio
May 12, 20156.820NONO
CVE-2013-4549MEDIUM
QXmlSimpleReader in Qt before 5.2 allows context-dependent attackers to cause a denial of service (memory consumption) via an XML Entity Expansion (XEE) attack.
Dec 23, 20135.017NONO
CVE-2012-5624MEDIUM
The XMLHttpRequest object in Qt before 4.8.4 enables http redirection to the file scheme, which allows man-in-the-middle attackers to force the read of arbitrary local files and po
Feb 24, 20134.317NONO
CVE-2010-5076MEDIUM
QSslSocket in Qt before 4.7.0-rc1 recognizes a wildcard IP address in the subject's Common Name field of an X.509 certificate, which might allow man-in-the-middle attackers to spoo
Jun 29, 20124.317NONO
View all 9 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products9 CVEs
89%
11%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown9 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown9 (100.0%)
User Interaction
None0 (0.0%)
Unknown9 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown9 (100.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
11.1% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Digia.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Digia — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Digia's Products

View all 3 CNAs →

Top CWEs