Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-14653 | LibJS in Ladybird before f5a6704 mishandles the freeing of the vector that arguments_list references, leading to a use-after-free, and allowing remote attackers to execute arbitrary code via a crafted .js file. NOTE: the GitHub README says "Ladybird is in a pre-alpha state, and only suitable for use by developers." |
Thu, 01 May 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 01 May 2025 08:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | LibJS in Ladybird before f5a6704 mishandles the freeing of the vector that arguments_list references, leading to a use-after-free, and allowing remote attackers to execute arbitrary code via a crafted .js file. NOTE: the GitHub README says "Ladybird is in a pre-alpha state, and only suitable for use by developers." | |
| Weaknesses | CWE-820 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-05-01T15:33:42.106Z
Reserved: 2025-05-01T00:00:00.000Z
Link: CVE-2025-47154
Updated: 2025-05-01T14:38:14.176Z
Status : Deferred
Published: 2025-05-01T08:15:17.950
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-47154
No data.
OpenCVE Enrichment
No data.
EUVD