VDB
CVE-2025-14308
CVE-2025-14308
PUBLISHED
CVSS 10 CRITICAL
An integer overflow vulnerability exists in the write method of the Buffer class in Robocode version 1.9.3.6. The method fails to properly validate the length of data being written, allowing attackers to cause an overflow, potentially leading to buffer overflows and arbitrary code execution. This vulnerability can be exploited by submitting specially crafted inputs that manipulate the data length, leading to potential unauthorized code execution.
EPSS 0.58% · 46.2th percentile
Risk Scores
CVSS 4.0
10
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:D/RE:M/U:Red
EPSS Score
0.58%
46.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| robocode | robocode | 1.9.3.6 |
| Robocode Project | Robocode | 1.9.3.6 |
Timeline
- Dec 9, 2025 EPSS Score
- Dec 9, 2025 CVE ID Reserved
- Dec 9, 2025 CVE Published
- Dec 9, 2025 PoC Published
- Dec 9, 2025 PoC Published
- Dec 9, 2025 CVE Updated
- Dec 9, 2025 PoC Published
- Dec 14, 2025 EPSS Score
- Dec 18, 2025 EPSS Score
- Dec 23, 2025 EPSS Score
- Dec 28, 2025 EPSS Score
- Jan 1, 2026 EPSS Score