Threat Intelligence Report
3 VulnerabilitiesExecutive Summary
The first crucial vulnerability identified today pertains to NVIDIA's TensorRT-LLM. The high-severity issue is a heap-based buffer overflow vulnerability (CVE-2025-46842) that could lead to denial of service or, in a worst-case scenario, arbitrary code execution. NVIDIA has released a patch for this vulnerability, which users are advised to implement promptly to prevent potential system compromise. In tandem, SonicWall has issued a security patch for a Server-Side Request Forgery (SSRF) vulnerability (CVE-2025-46578) in its SMA1000 series of appliances. This vulnerability could allow an attacker to bypass security controls, leading to unauthorized actions or data exfiltration. SonicWall users should apply the patch immediately to mitigate the risk.
In other significant findings, a Local File Inclusion (LFI) vulnerability (CVE-2025-46619) has been identified in multiple versions of the Couchbase Server for Windows. Exploitation of this vulnerability could lead to the disclosure of sensitive information or even remote code execution. Couchbase has released updates to address this issue, and users are strongly encouraged to update their systems as soon as possible. Lastly, a critical Use-After-Free (UAF) vulnerability (CVE-2025-47154) has been discovered in the Ladybird Browser Engine. This vulnerability has the potential to cause significant damage, such as crashing the system or executing arbitrary code. The developers of Ladybird have released a patch to rectify this vulnerability, and users are advised to upgrade their systems immediately.
In conclusion, these high-severity vulnerabilities underscore the importance of maintaining up-to-date system patches. Users and administrators are urged to apply these updates swiftly to minimize exposure to potential security threats.
High Priority Threats
Critical Vulnerabilities
LibJS in Ladybird before f5a6704 mishandles the freeing of the vector that arguments_list references, leading to a use-after-free, and allowing …
CVSS: 9.0High Impact Threats
A security issue has been discovered in Couchbase Server before 7.6.4 and fixed in v.7.6.4 and v.7.2.7 for Windows that …
CVSS: 7.6Detailed Analysis
Related Vulnerabilities
Description:
LibJS in Ladybird before f5a6704 mishandles the freeing of the vector that arguments_list references, leading to a use-after-free, and allowing remote attackers to execute arbitrary code via a crafted .js file. NOTE: the GitHub README says "Ladybird is in a pre-alpha state, and only suitable for use by developers."
Affected Products
- Ladybird Ladybird
Description:
A security issue has been discovered in Couchbase Server before 7.6.4 and fixed in v.7.6.4 and v.7.2.7 for Windows that could allow unauthorized access to sensitive files. Depending on the level of privileges, this vulnerability may grant access to files such as /etc/passwd or /etc/shadow.
Description:
There are SQL injection vulnerabilities in multiple interfaces of the GoldenDB database product. Attackers can exploit these interfaces to inject commands and extract sensitive database information.
Affected Products
- ZTE GoldenDB