Qtweb is a web application framework with a narrowly scoped product portfolio centered on its core web server and application platform. The durable signal in its disclosure profile reflects its role as a web-facing component, with observed weakness classes centered on input-handling and output-encoding issues such as cross-site scripting. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Qtweb over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-5247MEDIUM Untrusted search path vulnerability in QtWeb Browser 3.3 build 043 allows local users to gain privileges via a Trojan horse wintab32.dll file in the current working directory, as d | Sep 7, 2012 | 6.9 | 20 | NO | NO |
CVE-2009-3015MEDIUM QtWeb 3.0 Builds 001 and 003 does not properly block javascript: and data: URIs in Refresh and Location headers in HTTP responses, which allows remote attackers to conduct cross-si | Aug 31, 2009 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Qtweb.
Media articles that mention a CVE ID that affects a product developed by Qtweb — matched by CVE ID, not by vendor name.