CVE-2025-55014CWE-402

The YouDao plugin for StarDict, as used in stardict 3.0.7+git20220909+dfsg-6 in Debian trixie and elsewhere, sends an X11 selection to the dict.youdao.com and…

Medium · published August 4, 2025

CVSS v3.1
4.7
EPSS
0%
Percentile
30.9
In the wild
Unconfirmed
What it is

The YouDao plugin for StarDict, as used in stardict 3.0.7+git20220909+dfsg-6 in Debian trixie and elsewhere, sends an X11 selection to the dict.youdao.com and dict.cn servers via cleartext HTTP.

The record
Technical detail
CVSS v3.1
4.7 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N
CVSS v4.0
Not supplied
EPSS
0.00377 · 30.9th percentile
Weakness
CWE-402 · Transmission of Private Resources into a New Sphere ('Resource Leak')
Published
2025-08-04T00:00Z
EPSS history
Timeline
  • 04 AUG 00:00Z
    The YouDao plugin for StarDict, as used in stardict 3.0.7+git20220909+dfsg-6 in Debian trixie and elsewhere, sends an X11 selection to the dict.youdao.com and…
    cvelistv5