Back to overview

CVE-2025-14308

CRITICAL
10.0
CVSS 4.0
Description
An integer overflow vulnerability exists in the write method of the Buffer class in Robocode version 1.9.3.6. The method fails to properly validate the length of data being written, allowing attackers to cause an overflow, potentially leading to buffer overflows and arbitrary code execution. This vulnerability can be exploited by submitting specially crafted inputs that manipulate the data length, leading to potential unauthorized code execution.

Metadata

CVE ID
CVE-2025-14308
State
PUBLISHED
Assigner
GovTech CSG
Reserved
2025-12-09 07:38 UTC
Published
2025-12-09 07:44 UTC
Last updated
2025-12-09 14:39 UTC
Primary CWE
CWE-190
CWE-190 Integer Overflow or Wraparound
Vendor / Product
Robocode Project / Robocode
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/AU:Y/R:U/V:D/RE:M/U:Red
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
Robocode Project Robocode Windows,MacOS,Linux 1.9.3.6
Weakness (CWE)
CWESourceDescription
CWE-190 cna CWE-190 Integer Overflow or Wraparound
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/AU:Y/R:U/V:D/RE:M/U:Red
Back to overview