An Out-of-Bounds Write vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions 12.6.1204.207 and prior that could allow an attacker to disclose information or execute arbitrary code.
Advisories

No advisories yet.

Fixes

Solution

Ashlar-Vellum recommends users update to the following versions: * Cobalt: Versions 12.6.1204.208 or higher * Xenon: Versions 12.6.1204.208 or higher * Argon: Versions 12.6.1204.208 or higher * Lithium: Versions 12.6.1204.208 or higher * Cobalt Share: Versions 12.6.1204.208 or higher


Workaround

No workaround given by the vendor.

History

Thu, 27 Nov 2025 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Ashlar
Ashlar argon
Ashlar cobalt
Ashlar lithium
Ashlar xenon
Vendors & Products Ashlar
Ashlar argon
Ashlar cobalt
Ashlar lithium
Ashlar xenon

Tue, 25 Nov 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 25 Nov 2025 18:00:00 +0000

Type Values Removed Values Added
Description An Out-of-Bounds Write vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions 12.6.1204.207 and prior that could allow an attacker to disclose information or execute arbitrary code.
Title Out-of-bounds Write in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, Cobalt Share
Weaknesses CWE-787
References
Metrics cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-11-25T20:21:46.962Z

Reserved: 2025-11-17T16:43:44.053Z

Link: CVE-2025-65084

cve-icon Vulnrichment

Updated: 2025-11-25T20:21:39.115Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-11-25T18:15:54.133

Modified: 2025-11-25T22:16:16.690

Link: CVE-2025-65084

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-11-27T09:45:23Z