CVE-2025-14307
HIGHDescription
An insecure temporary file creation vulnerability exists in the AutoExtract component of Robocode version 1.9.3.6. The createTempFile method fails to securely create temporary files, allowing attackers to exploit race conditions and potentially execute arbitrary code or overwrite critical files. This vulnerability can be exploited by manipulating the temporary file creation process, leading to potential unauthorized actions.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| robocode | robocode |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2025-14307? +
How severe is CVE-2025-14307? +
What products are affected by CVE-2025-14307? +
How do I check if I'm vulnerable to CVE-2025-14307? +
Related Vulnerabilities
Insecure creation of temporary files allows local users on systems with non-default configurations to cause denial of service or set …
Products for macOS enables a user logged on to the system to perform a denial-of-service attack, which could be misused …
Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 25.1.102 and Application versions prior to 25.1.1413 (Windows client deployments) …
The llama_index library version 0.12.33 sets the NLTK data directory to a subdirectory of the codebase by default, which is …
Dell Alienware Command Center 6.x (AWCC), versions prior to 6.10.15.0, contains an Insecure Temporary File vulnerability. A low privileged attacker …
The Aranda File Server (AFS) component in Aranda Software Aranda Service Desk before 8.3.12 stores daily activity logs with predictable …