Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-14308

Опубликовано: 09 дек. 2025
Источник: debian
EPSS Низкий

Описание

An integer overflow vulnerability exists in the write method of the Buffer class in Robocode version 1.9.3.6. The method fails to properly validate the length of data being written, allowing attackers to cause an overflow, potentially leading to buffer overflows and arbitrary code execution. This vulnerability can be exploited by submitting specially crafted inputs that manipulate the data length, leading to potential unauthorized code execution.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
robocodeunfixedpackage
robocodeno-dsatrixiepackage
robocodeno-dsabookwormpackage
robocodeignoredbullseyepackage

Примечания

  • https://github.com/robo-code/robocode/pull/70

  • Fixed by: https://github.com/robo-code/robocode/commit/5ca52e3af7e35cd0a7309d573595dcb78cce7fa7 (VER_1_9_5_6)

  • Fixed by: https://github.com/robo-code/robocode/commit/9f616173e5ed3b7b6c02c2b230b1014822bee363 (VER_1_9_5_6)

  • Fixed by: https://github.com/robo-code/robocode/commit/9787e2cc90942d94ae341cf5562e42495443084b (VER_1_9_5_6)

EPSS

Процентиль: 46%
0.00576
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
9 месяцев назад

An integer overflow vulnerability exists in the write method of the Buffer class in Robocode version 1.9.3.6. The method fails to properly validate the length of data being written, allowing attackers to cause an overflow, potentially leading to buffer overflows and arbitrary code execution. This vulnerability can be exploited by submitting specially crafted inputs that manipulate the data length, leading to potential unauthorized code execution.

CVSS3: 9.8
nvd
9 месяцев назад

An integer overflow vulnerability exists in the write method of the Buffer class in Robocode version 1.9.3.6. The method fails to properly validate the length of data being written, allowing attackers to cause an overflow, potentially leading to buffer overflows and arbitrary code execution. This vulnerability can be exploited by submitting specially crafted inputs that manipulate the data length, leading to potential unauthorized code execution.

CVSS3: 9.8
github
9 месяцев назад

An integer overflow vulnerability exists in the write method of the Buffer class in Robocode version 1.9.3.6. The method fails to properly validate the length of data being written, allowing attackers to cause an overflow, potentially leading to buffer overflows and arbitrary code execution. This vulnerability can be exploited by submitting specially crafted inputs that manipulate the data length, leading to potential unauthorized code execution.

EPSS

Процентиль: 46%
0.00576
Низкий