Ashlar-Vellum Products Out-of-Bounds Read Vulnerability Allowing Information Disclosure or Arbitrary Code Execution

Vulnerability

An out-of-bounds read vulnerability has been identified in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share, all versions through 12.6.1204.216. This vulnerability could enable an attacker to disclose information or execute arbitrary code by exploiting the way a specially crafted VC6 file is parsed.

Impact

Exploitation of this vulnerability could lead to unauthorized information disclosure or arbitrary code execution on the affected system.

Added: May 12, 2026, 9:23 PM
Updated: May 12, 2026, 9:23 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
3.6
remediation
0.0
relevance
8.1
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.