9.6

CVE-2025-53964

Exploit
GoldenDict 1.5.0 and 1.5.1 has an exposed dangerous method that allows reading and modifying files when a user adds a crafted dictionary and then searches for any term included in that dictionary.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Goldendict ≫ Goldendict Version 1.5.0
Goldendict ≫ Goldendict Version 1.5.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.43% 0.34
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
CISA-ADP 9.6 2.8 6
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L
CWE-749 Exposed Dangerous Method or Function

The product provides an Applications Programming Interface (API) or similar interface for interaction with external actors, but the interface includes a dangerous method or function that is not properly restricted.

https://github.com/goldendict/goldendict/releases
Release Notes
https://github.com/tigr78/CVE-2025-53964
Third Party Advisory
Exploit