CVE-2025-14575

EUVD-2025-209891
An Uncontrolled Search Path Element vulnerability in the OpenSSL TLS backend of Qt Network (qtbase) in Qt Qt Framework (Unix) allows a local attacker to load a rogue CA certificate as a trusted system authority via a crafted certificate file placed in the application's working directory.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
TQtCCNA
1.8 LOW
LOCAL
HIGH
HIGH
CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 0.6%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
qtqt
5.0.0 ≤
𝑥
≤ 5.15.19
CNA
qtqt
6.0.0 ≤
𝑥
≤ 6.5.9
CNA
qtqt
6.6.0 ≤
𝑥
≤ 6.8.3
CNA
qtqt
6.9.0 ≤
𝑥
≤ 6.9.1
CNA
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
qt6-base
jammy
needs-triage
noble
needs-triage
questing
ignored
resolute
needs-triage
qtbase-opensource-src
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
questing
ignored
resolute
needs-triage
xenial
needs-triage
qtbase-opensource-src-gles
focal
needs-triage
jammy
needs-triage
noble
needs-triage
questing
ignored
resolute
needs-triage
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
libqt4
suse enterprise server 12 SP3
4.8.7-8.25.1
fixed
libqt4-32bit
suse enterprise server 12 SP3
4.8.7-8.25.1
fixed
libqt4-qt3support
suse enterprise server 12 SP3
4.8.7-8.25.1
fixed
libqt4-qt3support-32bit
suse enterprise server 12 SP3
4.8.7-8.25.1
fixed
libqt4-sql
suse enterprise server 12 SP3
4.8.7-8.25.1
fixed
libqt4-sql-32bit
suse enterprise server 12 SP3
4.8.7-8.25.1
fixed
libqt4-sql-mysql
suse enterprise server 12 SP3
4.8.7-8.25.1
fixed
libqt4-sql-sqlite
suse enterprise server 12 SP3
4.8.7-8.25.1
fixed
libqt4-x11
suse enterprise server 12 SP3
4.8.7-8.25.1
fixed
libqt4-x11-32bit
suse enterprise server 12 SP3
4.8.7-8.25.1
fixed
qt4-x11-tools
suse enterprise server 12 SP3
4.8.7-8.25.1
fixed