← back
CVE-2025-3512

Buffer overflow in QTextMarkdownImporter

CVSS 4.8 MEDIUMEPSS 0.2%CWE-122
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 4.8EPSS 0.2%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
11 Apr 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
There is a Heap-based Buffer Overflow vulnerability in QTextMarkdownImporter. This requires an incorrectly formatted markdown file to be passed to QTextMarkdownImporter to trigger the overflow.This issue affects Qt from 6.8.0 to 6.8.4. Versions up to 6.6.0 are known to be unaffected, and the fix is in 6.8.4 and later.
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/U:Clear
Affected products
The Qt Company · Qt

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →