CVE-2025-46269
18.08.2025, 22:15
In Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions prior to 12.6.1204.204, the affected applications lack proper validation of user-supplied data when parsing VC6 files. This could lead to a heap-based buffer overflow. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process.Enginsight
| Vendor | Product | Version |
|---|---|---|
| ashlar | argon | 𝑥 < 12.2.1204.204 |
| ashlar | cobalt | 𝑥 < 12.2.1204.204 |
| ashlar | cobalt_share | 𝑥 < 12.2.1204.204 |
| ashlar | lithium | 𝑥 < 12.2.1204.204 |
| ashlar | xenon | 𝑥 < 12.2.1204.204 |
𝑥
= Vulnerable software versions