CVE-2025-66216CRITICAL 9.8EPSS p34.7%

CVE-2025-66216CVE-2025-66216

Description

AIS-catcher is a multi-platform AIS receiver. Prior to version 0.64, a heap buffer overflow vulnerability has been identified in the AIS::Message class of AIS-catcher. This vulnerability allows an attacker to write approximately 1KB of arbitrary data into a 128-byte buffer. This issue has been patched in version 0.64.

Scoring

CVSS 3.19.8 (CRITICAL)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS0.44% probability of exploitation · percentile 34.7% · 2026-06-18T12:00:27Z
Published2025-11-29
Last modified2025-12-23

Underlying weaknesses· 2

CWE-131CWE-787

References

  1. https://github.com/jvde-github/AIS-catcher/commit/3de0ef785fc3c96265a71b37df7b0a82cb279312
  2. https://github.com/jvde-github/AIS-catcher/security/advisories/GHSA-v53x-f5hh-g2g6
  3. https://github.com/jvde-github/AIS-catcher/security/advisories/GHSA-v53x-f5hh-g2g6

2

TypeTargetConfidenceTier
WeaknessIncorrect Calculation of Buffer Sizecwe-1310%live
WeaknessOut-of-bounds Writecwe-7870%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2025-1744
CVE
CVE-2025-1864
CVE
CVE-2026-5121
CVE
CVE-2026-5402
CVE
CVE-2025-14512
CVE
CVE-2025-67268
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.