Trolltech develops the Qt framework and related tools, a widely embedded cross-platform application development library and toolkit whose vulnerabilities reach prominence in the landscape disproportionate to its volume because of deep integration across graphical applications and services. Its disclosures center on the core Qt library and components such as QSslSocket and Qt Assistant, and recur through memory-safety weaknesses including buffer-boundary violations that are characteristic of native C++ codebases. Vulnerabilities affecting this vendor frequently acquire public exploit code, reflecting the appeal of toolkit flaws to developers of weaponized exploits; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Trolltech over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2004-0691HIGH Heap-based buffer overflow in the BMP image format parser for the QT library (qt3) before 3.3.3 allows remote attackers to cause a denial of service (application crash) and possibl | Sep 28, 2004 | 7.5 | 35 | NO | YES |
CVE-2001-1113HIGH Buffer overflow in TrollFTPD 1.26 and earlier allows local users to execute arbitrary code by creating a series of deeply nested directories with long names, then running the ls -R | Aug 13, 2001 | 10.0 | 26 | NO | NO |
CVE-2007-4137HIGH Off-by-one error in the QUtf8Decoder::toUnicode function in Trolltech Qt 3 allows context-dependent attackers to cause a denial of service (crash) via a crafted Unicode string that | Sep 18, 2007 | 7.5 | 20 | NO | NO |
CVE-2007-3388MEDIUM Multiple format string vulnerabilities in (1) qtextedit.cpp, (2) qdatatable.cpp, (3) qsqldatabase.cpp, (4) qsqlindex.cpp, (5) qsqlrecord.cpp, (6) qglobal.cpp, and (7) qsvgdevice.cp | Aug 3, 2007 | 6.8 | 19 | NO | NO |
CVE-2002-1883MEDIUM Trolltech Qt Assistant 1.0 in Trolltech Qt 3.0.3, when loaded from the Designer, opens port 7358 for interprocess communication, which allows remote attackers to open arbitrary HTM | Dec 31, 2002 | 6.4 | 17 | NO | NO |
CVE-2004-0692MEDIUM The XPM parser in the QT library (qt3) before 3.3.3 allows remote attackers to cause a denial of service (application crash) via a malformed image file that triggers a null derefer | Sep 28, 2004 | 5.0 | 16 | NO | NO |
CVE-2004-0693MEDIUM The GIF parser in the QT library (qt3) before 3.3.3 allows remote attackers to cause a denial of service (application crash) via a malformed image file that triggers a null derefer | Sep 28, 2004 | 5.0 | 16 | NO | NO |
CVE-2007-5965MEDIUM QSslSocket in Trolltech Qt 4.3.0 through 4.3.2 does not properly verify SSL certificates, which might make it easier for remote attackers to trick a user into accepting an invalid | Jan 8, 2008 | 4.3 | 14 | NO | NO |
CVE-2005-0627MEDIUM Qt before 3.3.4 searches the BUILD_PREFIX directory, which could be world-writable, to load shared libraries regardless of the LD_LIBRARY_PATH environment variable, which allows lo | May 2, 2005 | 4.6 | 14 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Trolltech.
Media articles that mention a CVE ID that affects a product developed by Trolltech — matched by CVE ID, not by vendor name.