An integer overflow vulnerability exists in the write method of the Buffer class in Robocode version 1.9.3.6. The method fails to properly validate the length of data being written, allowing attackers to cause an overflow, potentially leading to buffer overflows and arbitrary code execution. This vulnerability can be exploited by submitting specially crafted inputs that manipulate the data length, leading to potential unauthorized code execution.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://github.com/robo-code/robocode/pull/70 |
|
History
Wed, 10 Dec 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Robocode Project
Robocode Project robocode |
|
| Vendors & Products |
Robocode Project
Robocode Project robocode |
Tue, 09 Dec 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 09 Dec 2025 08:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An integer overflow vulnerability exists in the write method of the Buffer class in Robocode version 1.9.3.6. The method fails to properly validate the length of data being written, allowing attackers to cause an overflow, potentially leading to buffer overflows and arbitrary code execution. This vulnerability can be exploited by submitting specially crafted inputs that manipulate the data length, leading to potential unauthorized code execution. | |
| Title | Integer Overflow in Robocode's Buffer Write Method | |
| Weaknesses | CWE-190 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GovTech CSG
Published: 2025-12-09T07:44:34.003Z
Updated: 2025-12-09T14:39:50.288Z
Reserved: 2025-12-09T07:38:25.483Z
Link: CVE-2025-14308
Updated: 2025-12-09T14:39:45.509Z
Status : Awaiting Analysis
Published: 2025-12-09T16:17:38.797
Modified: 2025-12-09T18:37:13.640
Link: CVE-2025-14308
No data.