VDB
CVE-2025-10996
CVE-2025-10996
PUBLISHED
CVSS 5.300000190734863 MEDIUM
A vulnerability was detected in Open Babel up to 3.1.1. This issue affects the function OBSmilesParser::ParseSmiles of the file /src/formats/smilesformat.cpp. Performing manipulation results in heap-based buffer overflow. The attack needs to be approached locally. The exploit is now public and may be used.
EPSS 0.28% · 20.1th percentile
Risk Scores
CVSS 3.1
5.300000190734863
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
EPSS Score
0.28%
20.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| openbabel | open_babel | 0 |
| n/a | Open Babel | 3.1.0, 3.1.1 |
Timeline
- Sep 26, 2025 EPSS Score
- Sep 26, 2025 CVE Published
- Oct 3, 2025 EPSS Score
- Oct 3, 2025 Coalition ESS Score
- Oct 6, 2025 Coalition ESS Score
- Oct 10, 2025 EPSS Score
- Oct 17, 2025 EPSS Score
- Oct 24, 2025 EPSS Score
- Oct 30, 2025 EPSS Score
- Nov 1, 2025 Coalition ESS Score
- Nov 6, 2025 EPSS Score
- Nov 13, 2025 EPSS Score
References
- VDB-325924 | Open Babel smilesformat.cpp ParseSmiles heap-based overflow vdb
- VDB-325924 | CTI Indicators (IOB, IOC, IOA) url
- Submit #654060 | Open Babel 3.1.1 / master commit 889c350 Heap-based Buffer Overflow third-party-advisory
- https://github.com/openbabel/openbabel/issues/2831 issue
- https://github.com/user-attachments/files/22318556/poc.zip exploit
- https://nvd.nist.gov/vuln/detail/CVE-2025-10996 advisory