VDB

CVE-2025-14308

CVE-2025-14308 PUBLISHED CVSS 10 CRITICAL

An integer overflow vulnerability exists in the write method of the Buffer class in Robocode version 1.9.3.6. The method fails to properly validate the length of data being written, allowing attackers to cause an overflow, potentially leading to buffer overflows and arbitrary code execution. This vulnerability can be exploited by submitting specially crafted inputs that manipulate the data length, leading to potential unauthorized code execution.

EPSS 0.58% · 46.2th percentile

Risk Scores

CVSS 4.0
10
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:D/RE:M/U:Red
EPSS Score
0.58%
46.2th percentile

Affected Products

VendorProductVersions
robocoderobocode1.9.3.6
Robocode ProjectRobocode1.9.3.6

Timeline

  • Dec 9, 2025 EPSS Score
  • Dec 9, 2025 CVE ID Reserved
  • Dec 9, 2025 CVE Published
  • Dec 9, 2025 PoC Published
  • Dec 9, 2025 PoC Published
  • Dec 9, 2025 CVE Updated
  • Dec 9, 2025 PoC Published
  • Dec 14, 2025 EPSS Score
  • Dec 18, 2025 EPSS Score
  • Dec 23, 2025 EPSS Score
  • Dec 28, 2025 EPSS Score
  • Jan 1, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›