Логотип exploitDog
bind:"BDU:2025-06498" OR bind:"CVE-2025-5455"
Консоль
Логотип exploitDog

exploitDog

bind:"BDU:2025-06498" OR bind:"CVE-2025-5455"

Количество 11

Количество 11

fstec логотип

BDU:2025-06498

5 месяцев назад

Уязвимость функции qDecodeDataUrl() модуля QtCore кроссплатформенного фреймворка для разработки программного обеспечения Qt, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 9.3
EPSS: Низкий
ubuntu логотип

CVE-2025-5455

5 месяцев назад

An issue was found in the private API function qDecodeDataUrl() in QtCore, which is used in QTextDocument and QNetworkReply, and, potentially, in user code. If the function was called with malformed data, for example, an URL that contained a "charset" parameter that lacked a value (such as "data:charset,"), and Qt was built with assertions enabled, then it would hit an assertion, resulting in a denial of service (abort). This impacts Qt up to 5.15.18, 6.0.0->6.5.8, 6.6.0->6.8.3 and 6.9.0. This has been fixed in 5.15.19, 6.5.9, 6.8.4 and 6.9.1.

EPSS: Низкий
redhat логотип

CVE-2025-5455

5 месяцев назад

An issue was found in the private API function qDecodeDataUrl() in QtCore, which is used in QTextDocument and QNetworkReply, and, potentially, in user code. If the function was called with malformed data, for example, an URL that contained a "charset" parameter that lacked a value (such as "data:charset,"), and Qt was built with assertions enabled, then it would hit an assertion, resulting in a denial of service (abort). This impacts Qt up to 5.15.18, 6.0.0->6.5.8, 6.6.0->6.8.3 and 6.9.0. This has been fixed in 5.15.19, 6.5.9, 6.8.4 and 6.9.1.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2025-5455

5 месяцев назад

An issue was found in the private API function qDecodeDataUrl() in QtCore, which is used in QTextDocument and QNetworkReply, and, potentially, in user code. If the function was called with malformed data, for example, an URL that contained a "charset" parameter that lacked a value (such as "data:charset,"), and Qt was built with assertions enabled, then it would hit an assertion, resulting in a denial of service (abort). This impacts Qt up to 5.15.18, 6.0.0->6.5.8, 6.6.0->6.8.3 and 6.9.0. This has been fixed in 5.15.19, 6.5.9, 6.8.4 and 6.9.1.

EPSS: Низкий
msrc логотип

CVE-2025-5455

3 месяца назад

EPSS: Низкий
debian логотип

CVE-2025-5455

5 месяцев назад

An issue was found in the private API function qDecodeDataUrl() in QtC ...

EPSS: Низкий
rocky логотип

RLSA-2025:9486

около 1 месяца назад

Moderate: qt6-qtbase security update

EPSS: Низкий
github логотип

GHSA-5cfg-qhv9-4842

5 месяцев назад

An issue was found in the private API function qDecodeDataUrl() in QtCore, which is used in QTextDocument and QNetworkReply, and, potentially, in user code. If the function was called with malformed data, for example, an URL that contained a "charset" parameter that lacked a value (such as "data:charset,"), and Qt was built with assertions enabled, then it would hit an assertion, resulting in a denial of service (abort). This impacts Qt up to 5.15.18, 6.0.0->6.5.8, 6.6.0->6.8.3 and 6.9.0. This has been fixed in 5.15.19, 6.5.9, 6.8.4 and 6.9.1.

EPSS: Низкий
oracle-oval логотип

ELSA-2025-9486

4 месяца назад

ELSA-2025-9486: qt6-qtbase security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-9462

4 месяца назад

ELSA-2025-9462: qt5-qtbase security update (MODERATE)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02968-1

2 месяца назад

Security update for libqt4

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2025-06498

Уязвимость функции qDecodeDataUrl() модуля QtCore кроссплатформенного фреймворка для разработки программного обеспечения Qt, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 9.3
0%
Низкий
5 месяцев назад
ubuntu логотип
CVE-2025-5455

An issue was found in the private API function qDecodeDataUrl() in QtCore, which is used in QTextDocument and QNetworkReply, and, potentially, in user code. If the function was called with malformed data, for example, an URL that contained a "charset" parameter that lacked a value (such as "data:charset,"), and Qt was built with assertions enabled, then it would hit an assertion, resulting in a denial of service (abort). This impacts Qt up to 5.15.18, 6.0.0->6.5.8, 6.6.0->6.8.3 and 6.9.0. This has been fixed in 5.15.19, 6.5.9, 6.8.4 and 6.9.1.

0%
Низкий
5 месяцев назад
redhat логотип
CVE-2025-5455

An issue was found in the private API function qDecodeDataUrl() in QtCore, which is used in QTextDocument and QNetworkReply, and, potentially, in user code. If the function was called with malformed data, for example, an URL that contained a "charset" parameter that lacked a value (such as "data:charset,"), and Qt was built with assertions enabled, then it would hit an assertion, resulting in a denial of service (abort). This impacts Qt up to 5.15.18, 6.0.0->6.5.8, 6.6.0->6.8.3 and 6.9.0. This has been fixed in 5.15.19, 6.5.9, 6.8.4 and 6.9.1.

CVSS3: 5.3
0%
Низкий
5 месяцев назад
nvd логотип
CVE-2025-5455

An issue was found in the private API function qDecodeDataUrl() in QtCore, which is used in QTextDocument and QNetworkReply, and, potentially, in user code. If the function was called with malformed data, for example, an URL that contained a "charset" parameter that lacked a value (such as "data:charset,"), and Qt was built with assertions enabled, then it would hit an assertion, resulting in a denial of service (abort). This impacts Qt up to 5.15.18, 6.0.0->6.5.8, 6.6.0->6.8.3 and 6.9.0. This has been fixed in 5.15.19, 6.5.9, 6.8.4 and 6.9.1.

0%
Низкий
5 месяцев назад
msrc логотип
0%
Низкий
3 месяца назад
debian логотип
CVE-2025-5455

An issue was found in the private API function qDecodeDataUrl() in QtC ...

0%
Низкий
5 месяцев назад
rocky логотип
RLSA-2025:9486

Moderate: qt6-qtbase security update

0%
Низкий
около 1 месяца назад
github логотип
GHSA-5cfg-qhv9-4842

An issue was found in the private API function qDecodeDataUrl() in QtCore, which is used in QTextDocument and QNetworkReply, and, potentially, in user code. If the function was called with malformed data, for example, an URL that contained a "charset" parameter that lacked a value (such as "data:charset,"), and Qt was built with assertions enabled, then it would hit an assertion, resulting in a denial of service (abort). This impacts Qt up to 5.15.18, 6.0.0->6.5.8, 6.6.0->6.8.3 and 6.9.0. This has been fixed in 5.15.19, 6.5.9, 6.8.4 and 6.9.1.

0%
Низкий
5 месяцев назад
oracle-oval логотип
ELSA-2025-9486

ELSA-2025-9486: qt6-qtbase security update (MODERATE)

4 месяца назад
oracle-oval логотип
ELSA-2025-9462

ELSA-2025-9462: qt5-qtbase security update (MODERATE)

4 месяца назад
suse-cvrf логотип
SUSE-SU-2025:02968-1

Security update for libqt4

2 месяца назад

Уязвимостей на страницу