<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T22:36:40.937599+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2025:9462</id>
    <title>ALSA-2025:9462 — Moderate: qt5-qtbase security update</title>
    <updated>2026-10-02T22:36:40.950063+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: qt5-qtbase, AlmaLinux:9: qt5-qtbase-common, AlmaLinux:9: qt5-qtbase-devel, AlmaLinux:9: qt5-qtbase-examples, AlmaLinux:9: qt5-qtbase-gui, AlmaLinux:9: qt5-qtbase-mysql, AlmaLinux:9: qt5-qtbase-odbc, AlmaLinux:9: qt5-qtbase-postgresql, AlmaLinux:9: qt5-qtbase-private-devel, AlmaLinux:9: qt5-qtbase-static</p>
<p>Qt is a software toolkit for developing applications. The qt5-base packages contain base tools for string, xml, and network handling in Qt.</p>
<p>Security Fix(es):</p>
<p>* qt5: qt6: QtCore Assertion Failure Denial of Service (CVE-2025-5455)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2025:9462"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-06498</id>
    <title>bdu:2025-06498</title>
    <updated>2026-10-02T22:36:40.950137+00:00</updated>
    <content>bdu:2025-06498</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-06498"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-342265</id>
    <title>EUVD-2026-342265</title>
    <updated>2026-10-02T22:36:40.950155+00:00</updated>
    <content>EUVD-2026-342265</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-342265"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-5455</id>
    <title>fkie_cve-2025-5455</title>
    <updated>2026-10-02T22:36:40.950168+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>An issue was found in the private API function qDecodeDataUrl() in QtCore, which is used in QTextDocument and QNetworkReply, and, potentially, in user code.</p>
<p>If the function was called with malformed data, for example, an URL that
contained a "charset" parameter that lacked a value (such as
"data:charset,"), and Qt was built with assertions enabled, then it would hit an assertion, resulting in a denial of service
(abort).</p>
<p>This impacts Qt up to 5.15.18, 6.0.0-&gt;6.5.8, 6.6.0-&gt;6.8.3 and 6.9.0. This has been fixed in 5.15.19, 6.5.9, 6.8.4 and 6.9.1.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-5455"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-5cfg-qhv9-4842</id>
    <title>GHSA-5cfg-qhv9-4842</title>
    <updated>2026-10-02T22:36:40.950195+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>An issue was found in the private API function qDecodeDataUrl() in QtCore, which is used in QTextDocument and QNetworkReply, and, potentially, in user code.</p>
<p>If the function was called with malformed data, for example, an URL that
contained a "charset" parameter that lacked a value (such as
"data:charset,"), and Qt was built with assertions enabled, then it would hit an assertion, resulting in a denial of service
(abort).</p>
<p>This impacts Qt up to 5.15.18, 6.0.0-&gt;6.5.8, 6.6.0-&gt;6.8.3 and 6.9.0. This has been fixed in 5.15.19, 6.5.9, 6.8.4 and 6.9.1.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-5cfg-qhv9-4842"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2025-5455</id>
    <title>msrc_CVE-2025-5455 — Possible denial of service when passing malformed data in a URL to qDecodeDataUrl</title>
    <updated>2026-10-02T22:36:40.950215+00:00</updated>
    <content>msrc_CVE-2025-5455</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2025-5455"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-1654</id>
    <title>OESA-2025-1654 — qt5-qtbase security update</title>
    <updated>2026-10-02T22:36:40.950231+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP3: qt5-qtbase, openEuler:22.03-LTS-SP4: qt5-qtbase, openEuler:24.03-LTS: qt5-qtbase, openEuler:24.03-LTS-SP1: qt5-qtbase, openEuler:20.03-LTS-SP4: qt5-qtbase</p>
<p>Qt is a software toolkit for developing applications.

Security Fix(es):</p>
<p>An issue was found in the private API function qDecodeDataUrl() in QtCore, which is used in QTextDocument and QNetworkReply, and, potentially, in user code.</p>
<p>If the function was called with malformed data, for example, an URL that
contained a &amp;quot;charset&amp;quot; parameter that lacked a value (such as
&amp;quot;data:charset,&amp;quot;), and Qt was built with assertions enabled, then it would hit an assertion, resulting in a denial of service
(abort).</p>
<p>This impacts Qt up to 5.15.18, 6.0.0-&amp;gt;6.5.8, 6.6.0-&amp;gt;6.8.3 and 6.9.0. This has been fixed in 5.15.19, 6.5.9, 6.8.4 and 6.9.1.(CVE-2025-5455)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-1654"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:11841</id>
    <title>RHSA-2025:11841 — Red Hat Security Advisory: qt5-qtbase security update</title>
    <updated>2026-10-02T22:36:40.950263+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>qt6-qtbase: qt5-qtbase: QtCore Assertion Failure Denial of Service</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:11841"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:9462</id>
    <title>RHSA-2025:9462 — Red Hat Security Advisory: qt5-qtbase security update</title>
    <updated>2026-10-02T22:36:40.950280+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>qt6-qtbase: qt5-qtbase: QtCore Assertion Failure Denial of Service</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:9462"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:02968-1</id>
    <title>SUSE-SU-2025:02968-1 — Security update for libqt4</title>
    <updated>2026-10-02T22:36:40.950295+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for libqt4</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:02968-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-5455</id>
    <title>UBUNTU-CVE-2025-5455</title>
    <updated>2026-10-02T22:36:40.950311+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: qtbase-opensource-src, Ubuntu:16.04:LTS: qtbase-opensource-src-gles, Ubuntu:Pro:18.04:LTS: qtbase-opensource-src, Ubuntu:Pro:20.04:LTS: qtbase-opensource-src, Ubuntu:20.04:LTS: qtbase-opensource-src-gles, Ubuntu:22.04:LTS: qt6-base, Ubuntu:22.04:LTS: qtbase-opensource-src, Ubuntu:22.04:LTS: qtbase-opensource-src-gles, Ubuntu:24.04:LTS: qt6-base, Ubuntu:24.04:LTS: qtbase-opensource-src and 5 more</p>
<p>An issue was found in the private API function qDecodeDataUrl() in QtCore, which is used in QTextDocument and QNetworkReply, and, potentially, in user code. If the function was called with malformed data, for example, an URL that contained a "charset" parameter that lacked a value (such as "data:charset,"), and Qt was built with assertions enabled, then it would hit an assertion, resulting in a denial of service (abort). This impacts Qt up to 5.15.18, 6.0.0-&gt;6.5.8, 6.6.0-&gt;6.8.3 and 6.9.0. This has been fixed in 5.15.19, 6.5.9, 6.8.4 and 6.9.1.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-5455"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1220</id>
    <title>WID-SEC-W-2025-1220 — QT: Schwachstelle ermöglicht Denial of Service</title>
    <updated>2026-10-02T22:36:40.950352+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in QT ausnutzen, um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1220"/>
  </entry>
</feed>
