Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 7

Количество 7

ubuntu логотип

CVE-2025-14576

3 месяца назад

Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaScript code injection when loading malicious SVG files through the VectorImage component in Qt Quick. While QML execution is typically more restricted than native code execution, this could still lead to denial of service, information disclosure, or other impacts depending on the application's privilege level and data access.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2025-14576

3 месяца назад

Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaScript code injection when loading malicious SVG files through the VectorImage component in Qt Quick. While QML execution is typically more restricted than native code execution, this could still lead to denial of service, information disclosure, or other impacts depending on the application's privilege level and data access.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2025-14576

3 месяца назад

Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaScript code injection when loading malicious SVG files through the VectorImage component in Qt Quick. While QML execution is typically more restricted than native code execution, this could still lead to denial of service, information disclosure, or other impacts depending on the application's privilege level and data access.

CVSS3: 7.8
EPSS: Низкий
debian логотип

CVE-2025-14576

3 месяца назад

Insufficient validation of node IDs in Qt SVG module allows arbitrary ...

CVSS3: 7.8
EPSS: Низкий
rocky логотип

RLSA-2026:20567

около 2 месяцев назад

Important: qt6-qtdeclarative security update

EPSS: Низкий
github логотип

GHSA-4hpm-v49g-rq7q

3 месяца назад

Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaScript code injection when loading malicious SVG files through the VectorImage component in Qt Quick. While QML execution is typically more restricted than native code execution, this could still lead to denial of service, information disclosure, or other impacts depending on the application's privilege level and data access.

CVSS3: 7.8
EPSS: Низкий
oracle-oval логотип

ELSA-2026-20567

17 дней назад

ELSA-2026-20567: qt6-qtdeclarative security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-14576

Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaScript code injection when loading malicious SVG files through the VectorImage component in Qt Quick. While QML execution is typically more restricted than native code execution, this could still lead to denial of service, information disclosure, or other impacts depending on the application's privilege level and data access.

CVSS3: 7.8
0%
Низкий
3 месяца назад
redhat логотип
CVE-2025-14576

Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaScript code injection when loading malicious SVG files through the VectorImage component in Qt Quick. While QML execution is typically more restricted than native code execution, this could still lead to denial of service, information disclosure, or other impacts depending on the application's privilege level and data access.

CVSS3: 7.8
0%
Низкий
3 месяца назад
nvd логотип
CVE-2025-14576

Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaScript code injection when loading malicious SVG files through the VectorImage component in Qt Quick. While QML execution is typically more restricted than native code execution, this could still lead to denial of service, information disclosure, or other impacts depending on the application's privilege level and data access.

CVSS3: 7.8
0%
Низкий
3 месяца назад
debian логотип
CVE-2025-14576

Insufficient validation of node IDs in Qt SVG module allows arbitrary ...

CVSS3: 7.8
0%
Низкий
3 месяца назад
rocky логотип
RLSA-2026:20567

Important: qt6-qtdeclarative security update

0%
Низкий
около 2 месяцев назад
github логотип
GHSA-4hpm-v49g-rq7q

Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaScript code injection when loading malicious SVG files through the VectorImage component in Qt Quick. While QML execution is typically more restricted than native code execution, this could still lead to denial of service, information disclosure, or other impacts depending on the application's privilege level and data access.

CVSS3: 7.8
0%
Низкий
3 месяца назад
oracle-oval логотип
ELSA-2026-20567

ELSA-2026-20567: qt6-qtdeclarative security update (IMPORTANT)

0%
Низкий
17 дней назад

Уязвимостей на страницу