The YouDao plugin for StarDict, as used in stardict 3.0.7+git20220909+dfsg-6 in Debian trixie and elsewhere, sends an X11 selection to the dict.youdao.com and dict.cn servers via cleartext HTTP.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-23543 The YouDao plugin for StarDict, as used in stardict 3.0.7+git20220909+dfsg-6 in Debian trixie and elsewhere, sends an X11 selection to the dict.youdao.com and dict.cn servers via cleartext HTTP.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 05 Nov 2025 07:30:00 +0900

Type Values Removed Values Added
References

Thu, 14 Aug 2025 02:30:00 +0900


Tue, 05 Aug 2025 16:45:00 +0900

Type Values Removed Values Added
First Time appeared Stardict
Stardict stardict
Vendors & Products Stardict
Stardict stardict

Tue, 05 Aug 2025 05:15:00 +0900

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 05 Aug 2025 05:00:00 +0900

Type Values Removed Values Added
Description The YouDao plugin for StarDict, as used in stardict 3.0.7+git20220909+dfsg-6 in Debian trixie and elsewhere, sends an X11 selection to the dict.youdao.com and dict.cn servers via cleartext HTTP.
Weaknesses CWE-402
References
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-11-04T21:12:59.566Z

Reserved: 2025-08-04T00:00:00.000Z

Link: CVE-2025-55014

cve-icon Vulnrichment

Updated: 2025-11-04T21:12:59.566Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-08-04T20:15:31.557

Modified: 2025-11-04T22:16:30.023

Link: CVE-2025-55014

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-08-05T16:35:03Z

Weaknesses