Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 16

Количество 16

ubuntu логотип

CVE-2025-5455

больше 1 года назад

An issue was found in the private API function qDecodeDataUrl() in QtCore, which is used in QTextDocument and QNetworkReply, and, potentially, in user code. If the function was called with malformed data, for example, an URL that contained a "charset" parameter that lacked a value (such as "data:charset,"), and Qt was built with assertions enabled, then it would hit an assertion, resulting in a denial of service (abort). This impacts Qt up to 5.15.18, 6.0.0->6.5.8, 6.6.0->6.8.3 and 6.9.0. This has been fixed in 5.15.19, 6.5.9, 6.8.4 and 6.9.1.

EPSS: Низкий
redhat логотип

CVE-2025-5455

больше 1 года назад

An issue was found in the private API function qDecodeDataUrl() in QtCore, which is used in QTextDocument and QNetworkReply, and, potentially, in user code. If the function was called with malformed data, for example, an URL that contained a "charset" parameter that lacked a value (such as "data:charset,"), and Qt was built with assertions enabled, then it would hit an assertion, resulting in a denial of service (abort). This impacts Qt up to 5.15.18, 6.0.0->6.5.8, 6.6.0->6.8.3 and 6.9.0. This has been fixed in 5.15.19, 6.5.9, 6.8.4 and 6.9.1.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2025-5455

больше 1 года назад

An issue was found in the private API function qDecodeDataUrl() in QtCore, which is used in QTextDocument and QNetworkReply, and, potentially, in user code. If the function was called with malformed data, for example, an URL that contained a "charset" parameter that lacked a value (such as "data:charset,"), and Qt was built with assertions enabled, then it would hit an assertion, resulting in a denial of service (abort). This impacts Qt up to 5.15.18, 6.0.0->6.5.8, 6.6.0->6.8.3 and 6.9.0. This has been fixed in 5.15.19, 6.5.9, 6.8.4 and 6.9.1.

EPSS: Низкий
msrc логотип

CVE-2025-5455

около 1 года назад

Possible denial of service when passing malformed data in a URL to qDecodeDataUrl

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2025-5455

больше 1 года назад

An issue was found in the private API function qDecodeDataUrl() in QtC ...

EPSS: Низкий
rocky логотип

RLSA-2025:9486

12 месяцев назад

Moderate: qt6-qtbase security update

EPSS: Низкий
rocky логотип

RLSA-2025:9462

12 месяцев назад

Moderate: qt5-qtbase security update

EPSS: Низкий
github логотип

GHSA-5cfg-qhv9-4842

больше 1 года назад

An issue was found in the private API function qDecodeDataUrl() in QtCore, which is used in QTextDocument and QNetworkReply, and, potentially, in user code. If the function was called with malformed data, for example, an URL that contained a "charset" parameter that lacked a value (such as "data:charset,"), and Qt was built with assertions enabled, then it would hit an assertion, resulting in a denial of service (abort). This impacts Qt up to 5.15.18, 6.0.0->6.5.8, 6.6.0->6.8.3 and 6.9.0. This has been fixed in 5.15.19, 6.5.9, 6.8.4 and 6.9.1.

EPSS: Низкий
oracle-oval логотип

ELSA-2025-9486

около 1 года назад

ELSA-2025-9486: qt6-qtbase security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-9462

больше 1 года назад

ELSA-2025-9462: qt5-qtbase security update (MODERATE)

EPSS: Низкий
fstec логотип

BDU:2025-06498

больше 1 года назад

Уязвимость функции qDecodeDataUrl() модуля QtCore кроссплатформенного фреймворка для разработки программного обеспечения Qt, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 9.3
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:3723-1

11 месяцев назад

Security update for libqt5-qtbase

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:03599-1

12 месяцев назад

Security update for qt6-base

EPSS: Низкий
redos логотип

ROS-20251030-10

11 месяцев назад

Уязвимость qt5-qtbase

CVSS3: 9.3
EPSS: Низкий
redos логотип

ROS-20251030-09

11 месяцев назад

Уязвимость qt6-qtbase

CVSS3: 9.3
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02968-1

около 1 года назад

Security update for libqt4

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-5455

An issue was found in the private API function qDecodeDataUrl() in QtCore, which is used in QTextDocument and QNetworkReply, and, potentially, in user code. If the function was called with malformed data, for example, an URL that contained a "charset" parameter that lacked a value (such as "data:charset,"), and Qt was built with assertions enabled, then it would hit an assertion, resulting in a denial of service (abort). This impacts Qt up to 5.15.18, 6.0.0->6.5.8, 6.6.0->6.8.3 and 6.9.0. This has been fixed in 5.15.19, 6.5.9, 6.8.4 and 6.9.1.

0%
Низкий
больше 1 года назад
redhat логотип
CVE-2025-5455

An issue was found in the private API function qDecodeDataUrl() in QtCore, which is used in QTextDocument and QNetworkReply, and, potentially, in user code. If the function was called with malformed data, for example, an URL that contained a "charset" parameter that lacked a value (such as "data:charset,"), and Qt was built with assertions enabled, then it would hit an assertion, resulting in a denial of service (abort). This impacts Qt up to 5.15.18, 6.0.0->6.5.8, 6.6.0->6.8.3 and 6.9.0. This has been fixed in 5.15.19, 6.5.9, 6.8.4 and 6.9.1.

CVSS3: 5.3
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2025-5455

An issue was found in the private API function qDecodeDataUrl() in QtCore, which is used in QTextDocument and QNetworkReply, and, potentially, in user code. If the function was called with malformed data, for example, an URL that contained a "charset" parameter that lacked a value (such as "data:charset,"), and Qt was built with assertions enabled, then it would hit an assertion, resulting in a denial of service (abort). This impacts Qt up to 5.15.18, 6.0.0->6.5.8, 6.6.0->6.8.3 and 6.9.0. This has been fixed in 5.15.19, 6.5.9, 6.8.4 and 6.9.1.

0%
Низкий
больше 1 года назад
msrc логотип
CVE-2025-5455

Possible denial of service when passing malformed data in a URL to qDecodeDataUrl

CVSS3: 6.5
0%
Низкий
около 1 года назад
debian логотип
CVE-2025-5455

An issue was found in the private API function qDecodeDataUrl() in QtC ...

0%
Низкий
больше 1 года назад
rocky логотип
RLSA-2025:9486

Moderate: qt6-qtbase security update

0%
Низкий
12 месяцев назад
rocky логотип
RLSA-2025:9462

Moderate: qt5-qtbase security update

0%
Низкий
12 месяцев назад
github логотип
GHSA-5cfg-qhv9-4842

An issue was found in the private API function qDecodeDataUrl() in QtCore, which is used in QTextDocument and QNetworkReply, and, potentially, in user code. If the function was called with malformed data, for example, an URL that contained a "charset" parameter that lacked a value (such as "data:charset,"), and Qt was built with assertions enabled, then it would hit an assertion, resulting in a denial of service (abort). This impacts Qt up to 5.15.18, 6.0.0->6.5.8, 6.6.0->6.8.3 and 6.9.0. This has been fixed in 5.15.19, 6.5.9, 6.8.4 and 6.9.1.

0%
Низкий
больше 1 года назад
oracle-oval логотип
ELSA-2025-9486

ELSA-2025-9486: qt6-qtbase security update (MODERATE)

0%
Низкий
около 1 года назад
oracle-oval логотип
ELSA-2025-9462

ELSA-2025-9462: qt5-qtbase security update (MODERATE)

0%
Низкий
больше 1 года назад
fstec логотип
BDU:2025-06498

Уязвимость функции qDecodeDataUrl() модуля QtCore кроссплатформенного фреймворка для разработки программного обеспечения Qt, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 9.3
0%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2025:3723-1

Security update for libqt5-qtbase

11 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:03599-1

Security update for qt6-base

12 месяцев назад
redos логотип
ROS-20251030-10

Уязвимость qt5-qtbase

CVSS3: 9.3
0%
Низкий
11 месяцев назад
redos логотип
ROS-20251030-09

Уязвимость qt6-qtbase

CVSS3: 9.3
0%
Низкий
11 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:02968-1

Security update for libqt4

около 1 года назад

Уязвимостей на страницу