Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x9vj-67g7-457m

Опубликовано: 03 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.7

Описание

Allocation of Resources Without Limits or Throttling, Improper Validation of Specified Quantity in Input vulnerability in The Qt Company Qt on Windows, MacOS, Linux, iOS, Android, x86, ARM, 64 bit, 32 bit allows Excessive Allocation. This issue affects users of the Text component in Qt Quick. Missing validation of the width and height in the tag could cause an application to become unresponsive.

This issue affects Qt: from 5.0.0 through 6.5.10, from 6.6.0 through 6.8.5, from 6.9.0 through 6.10.0.

Allocation of Resources Without Limits or Throttling, Improper Validation of Specified Quantity in Input vulnerability in The Qt Company Qt on Windows, MacOS, Linux, iOS, Android, x86, ARM, 64 bit, 32 bit allows Excessive Allocation. This issue affects users of the Text component in Qt Quick. Missing validation of the width and height in the tag could cause an application to become unresponsive.

This issue affects Qt: from 5.0.0 through 6.5.10, from 6.6.0 through 6.8.5, from 6.9.0 through 6.10.0.

EPSS

Процентиль: 23%
0.00308
Низкий

8.7 High

CVSS4

Дефекты

CWE-770

Связанные уязвимости

ubuntu
8 месяцев назад

Allocation of Resources Without Limits or Throttling, Improper Validation of Specified Quantity in Input vulnerability in The Qt Company Qt on Windows, MacOS, Linux, iOS, Android, x86, ARM, 64 bit, 32 bit allows Excessive Allocation. This issue affects users of the Text component in Qt Quick. Missing validation of the width and height in the <img> tag could cause an application to become unresponsive. This issue affects Qt: from 5.0.0 through 6.5.10, from 6.6.0 through 6.8.5, from 6.9.0 through 6.10.0.

nvd
8 месяцев назад

Allocation of Resources Without Limits or Throttling, Improper Validation of Specified Quantity in Input vulnerability in The Qt Company Qt on Windows, MacOS, Linux, iOS, Android, x86, ARM, 64 bit, 32 bit allows Excessive Allocation. This issue affects users of the Text component in Qt Quick. Missing validation of the width and height in the <img> tag could cause an application to become unresponsive. This issue affects Qt: from 5.0.0 through 6.5.10, from 6.6.0 through 6.8.5, from 6.9.0 through 6.10.0.

msrc
8 месяцев назад

Improper validation of <img> tag size in Text component parser

debian
8 месяцев назад

Allocation of Resources Without Limits or Throttling, Improper Validat ...

CVSS3: 4.3
fstec
9 месяцев назад

Уязвимость тега <img> набора плагинов QML и Qt Quick для Qt6 Qt6 Declarative, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 23%
0.00308
Низкий

8.7 High

CVSS4

Дефекты

CWE-770