In Eclipse OpenJ9 versions up to 0.51, when used with OpenJDK version 8 a stack based buffer overflow can be caused by modifying a file on disk that is read when the JVM starts.
CVE ID: CVE-2025-4447
CVSS Base Severity: HIGH
CVSS Base Score: 7.0
CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:H/SC:H/SI:N/SA:N
Vendor: Eclipse Foundation
Product: OpenJ9
EPSS Score: 0.02% (probability of being exploited)
EPSS Percentile: 2.22% (scored less or equal to compared to others)
EPSS Date: 2025-06-07 (when was this score calculated)