# CVE-2025-14308

## Summary

- **CVE ID:** CVE-2025-14308
- **Severity:** CRITICAL
- **CVSS Score:** 10 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/AU:Y/R:U/V:D/RE:M/U:Red)
- **CWE:** CWE-190
- **Published:** Dec 9, 2025
- **Last Modified:** Mar 12, 2026

## Description

An integer overflow vulnerability exists in the write method of the Buffer class in Robocode version 1.9.3.6. The method fails to properly validate the length of data being written, allowing attackers to cause an overflow, potentially leading to buffer overflows and arbitrary code execution. This vulnerability can be exploited by submitting specially crafted inputs that manipulate the data length, leading to potential unauthorized code execution.

## Affected Products

- Robocode Project — Robocode (1.9.3.6)

## References

- [CNA](https://github.com/robo-code/robocode/pull/70)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.58%
- **EPSS Percentile:** 45.4

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._