CVE-2025-66216

Received
Published: 29 Nov 2025, 03:15
Last modified:29 Nov 2025, 03:15

Vulnerability Summary

Overall Risk
Medium Risk
37/100
CVSS Score
9.3 CRITICAL
CVSS v4.0 (SECURITY-ADVISORIES)
EPSS Score
0.04% INFO
0% probability 0.00%
CISA KEV
Not listed
Ransomware
No reports
Exploits
None found
Dark Web
Not detected
AIS-catcher is a multi-platform AIS receiver. Prior to version 0.64, a heap buffer overflow vulnerability has been identified in the AIS::Message class of AIS-catcher. This vulnerability allows an attacker to write approximately 1KB of arbitrary data into a 128-byte buffer. This issue has been patched in version 0.64.
Source Identifier: security-advisories@github.com
CVSSSourceSeverityExploit.ImpactVector
v4.0security-advisories@github.com9.3 CRITICALNANA
CVSS:4.0/AV:N/AC:L/AT:N/P...
v3.1n/a
v3.0n/a
v2.0n/a
0.04%
Current Score
0.00%
12%ile
Percentile Rank
0.00%
Loading chart...
Loading chart...
Incorrect Calculation of Buffer Size CWE-131
Description:The product does not correctly calculate the size to be used when allocating a buffer, which could lead to a buffer overflow.

Not listed in CISA Known Exploited Vulnerabilities catalog.

No dark web activity detected for this vulnerability.

No known public exploit code indexed (as of 29 Nov 2025, 03:15).

Exploitation status can change quickly once PoC code appears.

No affected systems information available.

© 2025 CveMate. All rights reserved.v0.1.4