Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 16

Количество 16

github логотип

GHSA-5cfg-qhv9-4842

около 1 года назад

An issue was found in the private API function qDecodeDataUrl() in QtCore, which is used in QTextDocument and QNetworkReply, and, potentially, in user code. If the function was called with malformed data, for example, an URL that contained a "charset" parameter that lacked a value (such as "data:charset,"), and Qt was built with assertions enabled, then it would hit an assertion, resulting in a denial of service (abort). This impacts Qt up to 5.15.18, 6.0.0->6.5.8, 6.6.0->6.8.3 and 6.9.0. This has been fixed in 5.15.19, 6.5.9, 6.8.4 and 6.9.1.

EPSS: Низкий
ubuntu логотип

CVE-2025-5455

около 1 года назад

An issue was found in the private API function qDecodeDataUrl() in QtCore, which is used in QTextDocument and QNetworkReply, and, potentially, in user code. If the function was called with malformed data, for example, an URL that contained a "charset" parameter that lacked a value (such as "data:charset,"), and Qt was built with assertions enabled, then it would hit an assertion, resulting in a denial of service (abort). This impacts Qt up to 5.15.18, 6.0.0->6.5.8, 6.6.0->6.8.3 and 6.9.0. This has been fixed in 5.15.19, 6.5.9, 6.8.4 and 6.9.1.

EPSS: Низкий
redhat логотип

CVE-2025-5455

около 1 года назад

An issue was found in the private API function qDecodeDataUrl() in QtCore, which is used in QTextDocument and QNetworkReply, and, potentially, in user code. If the function was called with malformed data, for example, an URL that contained a "charset" parameter that lacked a value (such as "data:charset,"), and Qt was built with assertions enabled, then it would hit an assertion, resulting in a denial of service (abort). This impacts Qt up to 5.15.18, 6.0.0->6.5.8, 6.6.0->6.8.3 and 6.9.0. This has been fixed in 5.15.19, 6.5.9, 6.8.4 and 6.9.1.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2025-5455

около 1 года назад

An issue was found in the private API function qDecodeDataUrl() in QtCore, which is used in QTextDocument and QNetworkReply, and, potentially, in user code. If the function was called with malformed data, for example, an URL that contained a "charset" parameter that lacked a value (such as "data:charset,"), and Qt was built with assertions enabled, then it would hit an assertion, resulting in a denial of service (abort). This impacts Qt up to 5.15.18, 6.0.0->6.5.8, 6.6.0->6.8.3 and 6.9.0. This has been fixed in 5.15.19, 6.5.9, 6.8.4 and 6.9.1.

EPSS: Низкий
msrc логотип

CVE-2025-5455

12 месяцев назад

Possible denial of service when passing malformed data in a URL to qDecodeDataUrl

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2025-5455

около 1 года назад

An issue was found in the private API function qDecodeDataUrl() in QtC ...

EPSS: Низкий
rocky логотип

RLSA-2025:9486

10 месяцев назад

Moderate: qt6-qtbase security update

EPSS: Низкий
rocky логотип

RLSA-2025:9462

10 месяцев назад

Moderate: qt5-qtbase security update

EPSS: Низкий
oracle-oval логотип

ELSA-2025-9486

около 1 года назад

ELSA-2025-9486: qt6-qtbase security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-9462

около 1 года назад

ELSA-2025-9462: qt5-qtbase security update (MODERATE)

EPSS: Низкий
fstec логотип

BDU:2025-06498

около 1 года назад

Уязвимость функции qDecodeDataUrl() модуля QtCore кроссплатформенного фреймворка для разработки программного обеспечения Qt, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 9.3
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:3723-1

9 месяцев назад

Security update for libqt5-qtbase

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:03599-1

10 месяцев назад

Security update for qt6-base

EPSS: Низкий
redos логотип

ROS-20251030-10

9 месяцев назад

Уязвимость qt5-qtbase

CVSS3: 9.3
EPSS: Низкий
redos логотип

ROS-20251030-09

9 месяцев назад

Уязвимость qt6-qtbase

CVSS3: 9.3
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02968-1

11 месяцев назад

Security update for libqt4

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-5cfg-qhv9-4842

An issue was found in the private API function qDecodeDataUrl() in QtCore, which is used in QTextDocument and QNetworkReply, and, potentially, in user code. If the function was called with malformed data, for example, an URL that contained a "charset" parameter that lacked a value (such as "data:charset,"), and Qt was built with assertions enabled, then it would hit an assertion, resulting in a denial of service (abort). This impacts Qt up to 5.15.18, 6.0.0->6.5.8, 6.6.0->6.8.3 and 6.9.0. This has been fixed in 5.15.19, 6.5.9, 6.8.4 and 6.9.1.

0%
Низкий
около 1 года назад
ubuntu логотип
CVE-2025-5455

An issue was found in the private API function qDecodeDataUrl() in QtCore, which is used in QTextDocument and QNetworkReply, and, potentially, in user code. If the function was called with malformed data, for example, an URL that contained a "charset" parameter that lacked a value (such as "data:charset,"), and Qt was built with assertions enabled, then it would hit an assertion, resulting in a denial of service (abort). This impacts Qt up to 5.15.18, 6.0.0->6.5.8, 6.6.0->6.8.3 and 6.9.0. This has been fixed in 5.15.19, 6.5.9, 6.8.4 and 6.9.1.

0%
Низкий
около 1 года назад
redhat логотип
CVE-2025-5455

An issue was found in the private API function qDecodeDataUrl() in QtCore, which is used in QTextDocument and QNetworkReply, and, potentially, in user code. If the function was called with malformed data, for example, an URL that contained a "charset" parameter that lacked a value (such as "data:charset,"), and Qt was built with assertions enabled, then it would hit an assertion, resulting in a denial of service (abort). This impacts Qt up to 5.15.18, 6.0.0->6.5.8, 6.6.0->6.8.3 and 6.9.0. This has been fixed in 5.15.19, 6.5.9, 6.8.4 and 6.9.1.

CVSS3: 5.3
0%
Низкий
около 1 года назад
nvd логотип
CVE-2025-5455

An issue was found in the private API function qDecodeDataUrl() in QtCore, which is used in QTextDocument and QNetworkReply, and, potentially, in user code. If the function was called with malformed data, for example, an URL that contained a "charset" parameter that lacked a value (such as "data:charset,"), and Qt was built with assertions enabled, then it would hit an assertion, resulting in a denial of service (abort). This impacts Qt up to 5.15.18, 6.0.0->6.5.8, 6.6.0->6.8.3 and 6.9.0. This has been fixed in 5.15.19, 6.5.9, 6.8.4 and 6.9.1.

0%
Низкий
около 1 года назад
msrc логотип
CVE-2025-5455

Possible denial of service when passing malformed data in a URL to qDecodeDataUrl

CVSS3: 6.5
0%
Низкий
12 месяцев назад
debian логотип
CVE-2025-5455

An issue was found in the private API function qDecodeDataUrl() in QtC ...

0%
Низкий
около 1 года назад
rocky логотип
RLSA-2025:9486

Moderate: qt6-qtbase security update

0%
Низкий
10 месяцев назад
rocky логотип
RLSA-2025:9462

Moderate: qt5-qtbase security update

0%
Низкий
10 месяцев назад
oracle-oval логотип
ELSA-2025-9486

ELSA-2025-9486: qt6-qtbase security update (MODERATE)

0%
Низкий
около 1 года назад
oracle-oval логотип
ELSA-2025-9462

ELSA-2025-9462: qt5-qtbase security update (MODERATE)

0%
Низкий
около 1 года назад
fstec логотип
BDU:2025-06498

Уязвимость функции qDecodeDataUrl() модуля QtCore кроссплатформенного фреймворка для разработки программного обеспечения Qt, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 9.3
0%
Низкий
около 1 года назад
suse-cvrf логотип
SUSE-SU-2025:3723-1

Security update for libqt5-qtbase

9 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:03599-1

Security update for qt6-base

10 месяцев назад
redos логотип
ROS-20251030-10

Уязвимость qt5-qtbase

CVSS3: 9.3
0%
Низкий
9 месяцев назад
redos логотип
ROS-20251030-09

Уязвимость qt6-qtbase

CVSS3: 9.3
0%
Низкий
9 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:02968-1

Security update for libqt4

11 месяцев назад

Уязвимостей на страницу