Allocation of Resources Without Limits or Throttling, Improper Validation of Specified Quantity in Input vulnerability in The Qt Company Qt on Windows, MacOS, Linux, iOS, Android, x86, ARM, 64 bit, 32 bit allows Excessive Allocation.
This issue affects users of the Text component in Qt Quick. Missing validation of the width and height in the <img> tag could cause an application to become unresponsive.
This issue affects Qt: from 5.0.0 through 6.5.10, from 6.6.0 through 6.8.5, from 6.9.0 through 6.10.0.
Metrics
Affected Vendors & Products
References
History
Wed, 03 Dec 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Allocation of Resources Without Limits or Throttling, Improper Validation of Specified Quantity in Input vulnerability in The Qt Company Qt on Windows, MacOS, Linux, iOS, Android, x86, ARM, 64 bit, 32 bit allows Excessive Allocation. This issue affects users of the Text component in Qt Quick. Missing validation of the width and height in the <img> tag could cause an application to become unresponsive. This issue affects Qt: from 5.0.0 through 6.5.10, from 6.6.0 through 6.8.5, from 6.9.0 through 6.10.0. | |
| Title | Improper validation of <img> tag size in Text component parser | |
| First Time appeared |
The Qt Company
The Qt Company qt |
|
| Weaknesses | CWE-1284 CWE-770 |
|
| CPEs | cpe:2.3:a:the_qt_company:qt:*:*:32_bit:*:*:*:*:* cpe:2.3:a:the_qt_company:qt:*:*:64_bit:*:*:*:*:* cpe:2.3:a:the_qt_company:qt:*:*:android:*:*:*:*:* cpe:2.3:a:the_qt_company:qt:*:*:arm:*:*:*:*:* cpe:2.3:a:the_qt_company:qt:*:*:ios:*:*:*:*:* cpe:2.3:a:the_qt_company:qt:*:*:linux:*:*:*:*:* cpe:2.3:a:the_qt_company:qt:*:*:macos:*:*:*:*:* cpe:2.3:a:the_qt_company:qt:*:*:windows:*:*:*:*:* cpe:2.3:a:the_qt_company:qt:*:*:x86:*:*:*:*:* |
|
| Vendors & Products |
The Qt Company
The Qt Company qt |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: TQtC
Published: 2025-12-03T19:38:53.130Z
Updated: 2025-12-03T21:46:42.476Z
Reserved: 2025-10-28T11:53:25.141Z
Link: CVE-2025-12385
No data.
Status : Received
Published: 2025-12-03T20:16:24.170
Modified: 2025-12-03T20:16:24.170
Link: CVE-2025-12385
No data.