VDB
CVE-2025-10997
CVE-2025-10997
PUBLISHED
CVSS 5.300000190734863 MEDIUM
A flaw has been found in Open Babel up to 3.1.1. Impacted is the function ChemKinFormat::CheckSpecies of the file /src/formats/chemkinformat.cpp. Executing manipulation can lead to heap-based buffer overflow. The attack can only be executed locally. The exploit has been published and may be used.
EPSS 0.28% · 20.1th percentile
Risk Scores
CVSS 3.1
5.300000190734863
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
EPSS Score
0.28%
20.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | Open Babel | 3.1.0, 3.1.1 |
| openbabel | open_babel | 0 |
Timeline
- Sep 26, 2025 EPSS Score
- Sep 26, 2025 CVE Published
- Oct 3, 2025 EPSS Score
- Oct 3, 2025 Coalition ESS Score
- Oct 6, 2025 Coalition ESS Score
- Oct 10, 2025 EPSS Score
- Oct 17, 2025 EPSS Score
- Oct 24, 2025 EPSS Score
- Oct 30, 2025 EPSS Score
- Nov 1, 2025 Coalition ESS Score
- Nov 6, 2025 EPSS Score
- Nov 13, 2025 EPSS Score
References
- VDB-325925 | Open Babel chemkinformat.cpp CheckSpecies heap-based overflow vdb
- VDB-325925 | CTI Indicators (IOB, IOC, IOA) url
- Submit #654062 | Open Babel 3.1.1 / master commit 889c350 Heap-based Buffer Overflow third-party-advisory
- https://github.com/openbabel/openbabel/issues/2830 issue
- https://github.com/user-attachments/files/22318543/poc.zip exploit
- https://nvd.nist.gov/vuln/detail/CVE-2025-10997 advisory