Unidata develops the NetCDF scientific data format and access libraries, widely used in atmospheric science, climate modeling, and geophysical research; its vulnerability footprint reflects the memory-management demands of a C/Fortran codebase handling untrusted binary file formats. The recurring weakness classes—out-of-bounds writes, stack- and heap-based buffer overflows, and integer overflow—are characteristic of parsing and array-indexing logic in scientific data processing software. Current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Unidata over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-14934HIGH NSF Unidata NetCDF-C Variable Name Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected | Dec 23, 2025 | 7.8 | 25 | NO | NO |
CVE-2025-14933HIGH NSF Unidata NetCDF-C NC Variable Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installation | Dec 23, 2025 | 7.8 | 25 | NO | NO |
CVE-2025-14932HIGH NSF Unidata NetCDF-C Time Unit Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected ins | Dec 23, 2025 | 7.8 | 25 | NO | NO |
CVE-2025-14936HIGH NSF Unidata NetCDF-C Attribute Name Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affecte | Dec 23, 2025 | 7.8 | 24 | NO | NO |
CVE-2025-14935HIGH NSF Unidata NetCDF-C Dimension Name Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected | Dec 23, 2025 | 7.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Unidata.
Media articles that mention a CVE ID that affects a product developed by Unidata — matched by CVE ID, not by vendor name.