CVE-2025-65087
Out-of-bounds read in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, Cobalt Share
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
An Out-of-Bounds Read vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions 12.6.1204.216 and prior that could allow an attacker to disclose information or execute arbitrary code when a specially crafted VC6 file is being parsed.
| CWE | CWE-125 |
| Vendor | ashlar-vellum |
| Product | cobalt |
| Published | May 12, 2026 |
| Last Updated | May 12, 2026 |
Stay Ahead of the Next One
Get instant alerts for ashlar-vellum cobalt
Be the first to know when new unknown vulnerabilities affecting ashlar-vellum cobalt are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Ashlar-Vellum / Cobalt
0 โค 12.6.1204.216
Ashlar-Vellum / Xenon
0 โค 12.6.1204.216
Ashlar-Vellum / Argon
0 โค 12.6.1204.216
Ashlar-Vellum / Lithium
0 โค 12.6.1204.216
Ashlar-Vellum / Cobalt Share
0 โค 12.6.1204.216
References
Credits
Michael Heinzl reported these vulnerabilities to CISA.