Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-14576

Опубликовано: 30 апр. 2026
Источник: nvd
CVSS3: 7.8
EPSS Низкий

Описание

Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaScript code injection when loading malicious SVG files through the VectorImage component in Qt Quick. While QML execution is typically more restricted than native code execution, this could still lead to denial of service, information disclosure, or other impacts depending on the application's privilege level and data access.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:qt:qtdeclarative:*:*:*:*:*:*:*:*
Версия от 6.8.0 (включая) до 6.8.6 (исключая)
cpe:2.3:a:qt:qtdeclarative:*:*:*:*:*:*:*:*
Версия от 6.10.0 (включая) до 6.10.1 (исключая)

EPSS

Процентиль: 13%
0.00224
Низкий

7.8 High

CVSS3

Дефекты

CWE-20
CWE-94
CWE-94

Связанные уязвимости

CVSS3: 7.8
ubuntu
3 месяца назад

Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaScript code injection when loading malicious SVG files through the VectorImage component in Qt Quick. While QML execution is typically more restricted than native code execution, this could still lead to denial of service, information disclosure, or other impacts depending on the application's privilege level and data access.

CVSS3: 7.8
redhat
3 месяца назад

Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaScript code injection when loading malicious SVG files through the VectorImage component in Qt Quick. While QML execution is typically more restricted than native code execution, this could still lead to denial of service, information disclosure, or other impacts depending on the application's privilege level and data access.

CVSS3: 7.8
debian
3 месяца назад

Insufficient validation of node IDs in Qt SVG module allows arbitrary ...

rocky
около 2 месяцев назад

Important: qt6-qtdeclarative security update

CVSS3: 7.8
github
3 месяца назад

Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaScript code injection when loading malicious SVG files through the VectorImage component in Qt Quick. While QML execution is typically more restricted than native code execution, this could still lead to denial of service, information disclosure, or other impacts depending on the application's privilege level and data access.

EPSS

Процентиль: 13%
0.00224
Низкий

7.8 High

CVSS3

Дефекты

CWE-20
CWE-94
CWE-94