CVE-2025-14308

EUVD-2025-201906
An integer overflow vulnerability exists in the write method of the Buffer class in Robocode version 1.9.3.6. The method fails to properly validate the length of data being written, allowing attackers to cause an overflow, potentially leading to buffer overflows and arbitrary code execution. This vulnerability can be exploited by submitting specially crafted inputs that manipulate the data length, leading to potential unauthorized code execution.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 44.42%
Affected Products (NVD)
VendorProductVersion
robocoderobocode
1.9.3.6
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
robocode
bookworm
no-dsa
bullseye
ignored
forky
vulnerable
sid
vulnerable
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
robocode
bionic
Fixed 1.9.3.1-1ubuntu0.1~esm1
released
focal
Fixed 1.9.3.7-1ubuntu0.1~esm1
released
jammy
Fixed 1.9.3.9-2ubuntu0.1~esm1
released
noble
Fixed 1.9.3.9-3ubuntu0.1~esm1
released
plucky
ignored
questing
ignored
resolute
Fixed 1.9.3.9-4ubuntu0.26.04.1~esm1
released
xenial
Fixed 1.9.2.5-2ubuntu0.1~esm1
released