Buffer Overflow Remote Code Execution Vulnerability in NSF Unidata NetCDF-C
CVE-2025-14932

7.8HIGH

Key Information:

Status
Vendor
CVE Published:
23 December 2025

What is CVE-2025-14932?

A vulnerability exists in NSF Unidata NetCDF-C that allows attackers to execute arbitrary code remotely by exploiting a stack-based buffer overflow due to improper validation of user-supplied data during the parsing of time units. This flaw requires user interaction, as the target must access a malicious webpage or file for the attack to succeed. Successful exploitation can enable attackers to execute code in the context of the current user, potentially leading to further system compromise.

Affected Version(s)

NetCDF-C dbe0cbb9ff3f706009cf4ee011adf3e58d8a81c1

References

CVSS V3.0

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.