A Heap-based Buffer Overflow vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions 12.6.1204.216 and prior that could allow an attacker to disclose information or execute arbitrary code.

Project Subscriptions

Vendors Products
Advisories

No advisories yet.

Fixes

Solution

Ashlar-Vellum recommends users update to build 12.6.1204.217 and later.


Workaround

No workaround given by the vendor.

History

Tue, 12 May 2026 21:00:00 +0000

Type Values Removed Values Added
Description A Heap-based Buffer Overflow vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions 12.6.1204.207 and prior that could allow an attacker to disclose information or execute arbitrary code. A Heap-based Buffer Overflow vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions 12.6.1204.216 and prior that could allow an attacker to disclose information or execute arbitrary code.

Fri, 06 Mar 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 28 Nov 2025 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Ashlar cobalt Share
CPEs cpe:2.3:a:ashlar:argon:*:*:*:*:*:*:*:*
cpe:2.3:a:ashlar:cobalt:*:*:*:*:*:*:*:*
cpe:2.3:a:ashlar:cobalt_share:*:*:*:*:*:*:*:*
cpe:2.3:a:ashlar:lithium:*:*:*:*:*:*:*:*
cpe:2.3:a:ashlar:xenon:*:*:*:*:*:*:*:*
Vendors & Products Ashlar cobalt Share
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Thu, 27 Nov 2025 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Ashlar
Ashlar argon
Ashlar cobalt
Ashlar lithium
Ashlar xenon
Vendors & Products Ashlar
Ashlar argon
Ashlar cobalt
Ashlar lithium
Ashlar xenon

Tue, 25 Nov 2025 18:00:00 +0000

Type Values Removed Values Added
Description A Heap-based Buffer Overflow vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions 12.6.1204.207 and prior that could allow an attacker to disclose information or execute arbitrary code.
Title Heap-based Buffer Overflow in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, Cobalt Share
Weaknesses CWE-122
References
Metrics cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-05-12T20:19:10.639Z

Reserved: 2025-11-17T16:43:44.054Z

Link: CVE-2025-65085

cve-icon Vulnrichment

Updated: 2025-11-25T20:22:17.119Z

cve-icon NVD

Status : Modified

Published: 2025-11-25T18:15:54.283

Modified: 2026-05-12T21:16:13.290

Link: CVE-2025-65085

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-11-27T09:45:49Z

Weaknesses