📦 Cobalt

by Ashlar

🔍 What is Cobalt?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-65084

CRITICAL CVSS 9.8 Nov 25, 2025

An Out-of-Bounds Write vulnerability in Ashlar-Vellum CAD software allows attackers to execute arbitrary code or disclose sensitive information by sending specially crafted files. This affects users o...

CVE-2025-65085

CRITICAL CVSS 9.8 Nov 25, 2025

A heap-based buffer overflow vulnerability in Ashlar-Vellum CAD software allows attackers to read sensitive memory or execute arbitrary code by sending specially crafted data. This affects users of Co...

CVE-2025-11463

HIGH CVSS 7.8 Oct 29, 2025

This vulnerability allows remote attackers to execute arbitrary code on Ashlar-Vellum Cobalt installations by tricking users into opening malicious XE files or visiting malicious web pages. The intege...

CVE-2025-11465

HIGH CVSS 7.8 Oct 29, 2025

This vulnerability allows remote attackers to execute arbitrary code on Ashlar-Vellum Cobalt installations by tricking users into opening malicious CO files or visiting malicious web pages. The use-af...

CVE-2025-7977

HIGH CVSS 7.8 Sep 17, 2025

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious LI files or visiting malicious web pages. It affects Ashlar-Vellum Cobalt installations an...

CVE-2025-46269

HIGH CVSS 7.8 Aug 18, 2025

A heap-based buffer overflow vulnerability in Ashlar-Vellum CAD software allows attackers to execute arbitrary code by crafting malicious VC6 files. This affects users of Cobalt, Xenon, Argon, Lithium...

CVE-2025-41392

HIGH CVSS 7.8 Aug 18, 2025

This vulnerability allows attackers to execute arbitrary code by exploiting an out-of-bounds read when parsing AR files in Ashlar-Vellum CAD software. Users of Cobalt, Xenon, Argon, Lithium, and Cobal...

CVE-2025-2017

HIGH CVSS 7.8 Mar 11, 2025

A buffer overflow vulnerability in Ashlar-Vellum Cobalt's CO file parser allows remote attackers to execute arbitrary code when users open malicious files or visit malicious pages. This affects all in...

CVE-2025-2018

HIGH CVSS 7.8 Mar 11, 2025

This vulnerability allows remote attackers to execute arbitrary code on Ashlar-Vellum Cobalt installations by tricking users into opening malicious VS files. Attackers can gain control of the affected...

CVE-2025-2019

HIGH CVSS 7.8 Mar 11, 2025

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious VC6 files in Ashlar-Vellum Cobalt software. The heap-based buffer overflow occurs during f...

CVE-2025-2020

HIGH CVSS 7.8 Mar 11, 2025

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious VC6 files in Ashlar-Vellum Cobalt software. The flaw exists in file parsing where improper...

CVE-2025-2021

HIGH CVSS 7.8 Mar 11, 2025

This vulnerability allows remote attackers to execute arbitrary code on Ashlar-Vellum Cobalt installations by exploiting an integer overflow in XE file parsing. Attackers can achieve remote code execu...

CVE-2025-2022

HIGH CVSS 7.8 Mar 11, 2025

This vulnerability allows remote attackers to execute arbitrary code on Ashlar-Vellum Cobalt installations by tricking users into opening malicious VS files. Attackers can achieve remote code executio...

CVE-2025-2023

HIGH CVSS 7.8 Mar 11, 2025

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious LI files in Ashlar-Vellum Cobalt software. The integer overflow during file parsing enable...

CVE-2025-2012

HIGH CVSS 7.8 Mar 11, 2025

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious VS files in Ashlar-Vellum Cobalt software. The flaw exists in how the software parses VS f...

CVE-2025-2013

HIGH CVSS 7.8 Mar 11, 2025

This is a use-after-free vulnerability in Ashlar-Vellum Cobalt's CO file parser that allows remote attackers to execute arbitrary code. Attackers can exploit it by tricking users into opening maliciou...

CVE-2025-2014

HIGH CVSS 7.8 Mar 11, 2025

This vulnerability allows remote attackers to execute arbitrary code on Ashlar-Vellum Cobalt installations by tricking users into opening malicious VS files. It affects users of Ashlar-Vellum Cobalt s...

CVE-2025-2015

HIGH CVSS 7.8 Mar 11, 2025

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious VS files in Ashlar-Vellum Cobalt software. The type confusion flaw during file parsing ena...

CVE-2025-2016

HIGH CVSS 7.8 Mar 11, 2025

This vulnerability allows remote attackers to execute arbitrary code on Ashlar-Vellum Cobalt installations by tricking users into opening malicious VC6 files. Attackers can gain control of the affecte...

CVE-2023-39943

HIGH CVSS 7.8 Feb 4, 2025

This vulnerability in Ashlar-Vellum Cobalt allows attackers to execute arbitrary code by exploiting improper validation when parsing XE files. It affects users of Cobalt versions before v12 SP2 Build ...

CVE-2024-13047

HIGH CVSS 7.8 Dec 30, 2024

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious CO files or visiting malicious web pages. It affects Ashlar-Vellum Cobalt installations du...

CVE-2024-13049

HIGH CVSS 7.8 Dec 30, 2024

This vulnerability allows remote attackers to execute arbitrary code on Ashlar-Vellum Cobalt installations by tricking users into opening malicious XE files or visiting malicious web pages. The flaw e...

CVE-2024-13045

HIGH CVSS 7.8 Dec 30, 2024

A stack-based buffer overflow vulnerability in Ashlar-Vellum Cobalt's AR file parser allows remote attackers to execute arbitrary code when a user opens a malicious AR file or visits a malicious webpa...

CVE-2023-44437

HIGH CVSS 7.8 May 3, 2024

This vulnerability allows remote attackers to execute arbitrary code on Ashlar-Vellum Cobalt installations by tricking users into opening malicious files or visiting malicious pages. The flaw exists i...

CVE-2023-42105

HIGH CVSS 7.8 May 3, 2024

This vulnerability allows remote attackers to execute arbitrary code on Ashlar-Vellum Cobalt installations by tricking users into opening malicious AR files or visiting malicious web pages. The flaw e...

CVE-2023-42101

HIGH CVSS 7.8 May 3, 2024

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious AR files in Ashlar-Vellum Cobalt. The flaw exists in AR file parsing where improper valida...

CVE-2023-42103

HIGH CVSS 7.8 May 3, 2024

This is a use-after-free vulnerability in Ashlar-Vellum Cobalt's AR file parser that allows remote code execution. Attackers can exploit it by tricking users into opening malicious AR files or visitin...

CVE-2023-35716

HIGH CVSS 7.8 May 3, 2024

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious AR files in Ashlar-Vellum Cobalt. Attackers can exploit improper buffer validation during ...

CVE-2023-35710

HIGH CVSS 7.8 May 3, 2024

A stack-based buffer overflow vulnerability in Ashlar-Vellum Cobalt allows remote attackers to execute arbitrary code when users open malicious CO files or visit malicious web pages. This affects all ...

CVE-2023-35712

HIGH CVSS 7.8 May 3, 2024

This vulnerability allows remote attackers to execute arbitrary code on Ashlar-Vellum Cobalt installations by tricking users into opening malicious XE files or visiting malicious web pages. The flaw e...

CVE-2023-35714

HIGH CVSS 7.8 May 3, 2024

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious IGS files in Ashlar-Vellum Cobalt software. The flaw exists in improper data validation du...

CVE-2023-34309

HIGH CVSS 7.8 May 3, 2024

This vulnerability allows remote attackers to execute arbitrary code on Ashlar-Vellum Cobalt installations by tricking users into opening malicious CO files. Attackers can gain control of the affected...

CVE-2023-34311

HIGH CVSS 7.8 May 3, 2024

This vulnerability allows remote attackers to execute arbitrary code on Ashlar-Vellum Cobalt installations by tricking users into opening malicious CO files. Attackers can gain control of the affected...

CVE-2023-34301

HIGH CVSS 7.8 May 3, 2024

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious CO files or visiting malicious web pages. It affects Ashlar-Vellum Cobalt installations wh...

CVE-2023-34303

HIGH CVSS 7.8 May 3, 2024

This vulnerability allows remote attackers to execute arbitrary code on Ashlar-Vellum Cobalt installations by tricking users into opening malicious VC6 files. The flaw exists in improper validation of...

CVE-2023-34305

HIGH CVSS 7.0 May 3, 2024

This vulnerability allows remote attackers to execute arbitrary code on Ashlar-Vellum Cobalt installations by tricking users into opening malicious X_B or X_T files. The flaw is an out-of-bounds write...

CVE-2023-34299

HIGH CVSS 7.8 May 3, 2024

This vulnerability allows remote attackers to execute arbitrary code by tricking users into opening malicious CO files in Ashlar-Vellum Cobalt. Attackers can exploit a heap buffer overflow during CO f...

CVE-2023-34291

HIGH CVSS 7.8 May 3, 2024

This vulnerability allows remote attackers to execute arbitrary code on Ashlar-Vellum Cobalt installations by tricking users into opening malicious X_B or X_T files. The flaw is an out-of-bounds write...

CVE-2023-34293

HIGH CVSS 8.8 May 3, 2024

This vulnerability allows remote attackers to execute arbitrary code on Ashlar-Vellum Cobalt installations by tricking users into opening malicious X_B or X_T files. The flaw exists in improper data v...

CVE-2023-34287

HIGH CVSS 7.8 May 3, 2024

This vulnerability allows remote attackers to execute arbitrary code on Ashlar-Vellum Cobalt installations by tricking users into opening malicious CO files. Attackers can exploit a stack-based buffer...

CVE-2023-34289

HIGH CVSS 7.8 May 3, 2024

This is a heap-based buffer overflow vulnerability in Ashlar-Vellum Cobalt's AR file parser that allows remote code execution. Attackers can exploit it by tricking users into opening malicious AR file...