Get real-time updates on Telegram
CVE-2025-14576: qtdeclarative from 6.8.0 (inclusive), before 6.8.6 (exclusive), from 6.10.0 (inclusive), before 6.10.1 (exclusive)…
CVE-2025-14576. CVSS 3.1 base score 7.8 (HIGH, NVD). EPSS 0.00224 (percentile 0.11816), scored 2026-10-05.
Affected technology
qtdeclarative · from 6.8.0 (inclusive), before 6.8.6 (exclusive)
qt
qtdeclarative · from 6.10.0 (inclusive), before 6.10.1 (exclusive)
qt
Qt · 6.8.0 through 6.8.6, 6.10.0 through 6.10.1
Qt
Red Hat Enterprise Linux 10 · Exact affected versions not specified by the source
Red Hat
Red Hat Enterprise Linux 10.0 Extended Update Support · Exact affected versions not specified by the source
Red Hat
Red Hat Hardened Images · Exact affected versions not specified by the source
Red Hat
Multicluster Global Hub · Exact affected versions not specified by the source
Red Hat
Red Hat Advanced Cluster Management for Kubernetes 2 · Exact affected versions not specified by the source
Red Hat
Red Hat Enterprise Linux 6 · Exact affected versions not specified by the source
Red Hat
Red Hat Enterprise Linux 7 · Exact affected versions not specified by the source
Red Hat
Red Hat Enterprise Linux 8 · Exact affected versions not specified by the source
Red Hat
Red Hat Enterprise Linux 9 · Exact affected versions not specified by the source
Red Hat
Red Hat OpenShift Container Platform 4 · Exact affected versions not specified by the source
Red Hat
Red Hat OpenShift GitOps · Exact affected versions not specified by the source
Red Hat
Component: Qt Declarative (Qt Quick), VectorImage Component
Attack conditions (Source advisory, CVSS 4.0): Local · No privileges required · Passive user interaction
What an attacker can do
The source reports that an attacker could disrupt service and access information they should not be able to access under the conditions described by the source. Source advisory’s CVSS 4.0 assessment (base score 7.4/10) rates confidentiality, integrity and availability impact as high.
- CWE
- CWE-20, CWE-94
- CCR priority
- 31.3 /100 (P4)
- CVSS 3.1
- 7.8 /10 · CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H · NVD
- EPSS
- 0.00224 · percentile 0.11883 · 2026-10-06
- KEV
- no
Provenance
- FIRST EPSS daily exploit-probability · Source record · observed 2026-10-07 11:53:15.413517+00:00 UTC
- NVD CVE API 2.0 · Source record · observed 2026-10-07 11:49:32.540646+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2025-14576.html