CVE-2025-65087

EUVD-2025-209807
An Out-of-Bounds Read vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions 12.6.1204.216 and prior that could allow an attacker to disclose information or execute arbitrary code when a specially crafted VC6 file is being parsed.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 HIGH
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 6%
Affected Products (NVD)
VendorProductVersion
ashlarargon
𝑥
≤ 12.6.1204.216
ashlarcobalt
𝑥
≤ 12.6.1204.216
ashlarcobalt_share
𝑥
≤ 12.6.1204.216
ashlarlithium
𝑥
≤ 12.6.1204.216
ashlarxenon
𝑥
≤ 12.6.1204.216
𝑥
= Vulnerable software versions