Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Ashlar-Vellum — Vulnerabilities & Security Advisories 101

Browse all 101 CVE security advisories affecting Ashlar-Vellum. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Ashlar-Vellum provides computer-aided design and drafting software primarily serving the masonry and stone industry. The platform’s extensive history has resulted in a significant vulnerability footprint, with 101 Common Vulnerabilities and Exposures currently recorded. These security flaws predominantly involve remote code execution, cross-site scripting, and privilege escalation, often stemming from inadequate input validation and improper access controls within the application’s architecture. While specific major incidents involving widespread exploitation remain largely undocumented in public threat intelligence feeds, the high volume of CVEs indicates systemic weaknesses in the software’s security lifecycle. Users are advised to maintain strict patch management protocols, as the legacy nature of the codebase presents persistent risks for unauthorized access and data compromise. Continuous monitoring and immediate application of vendor-provided security updates are essential to mitigate these known technical deficiencies and protect organizational infrastructure from potential exploitation.

CVE IDTitleCVSSSeverityPublished
CVE-2025-65085 Heap-based Buffer Overflow in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, Cobalt Share — CobaltCWE-122 9.8AICriticalAI2025-11-25
CVE-2025-65084 Out-of-bounds Write in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, Cobalt Share — CobaltCWE-787 9.8AICriticalAI2025-11-25
CVE-2025-11465 Ashlar-Vellum Cobalt CO File Parsing Use-After-Free Remote Code Execution Vulnerability — CobaltCWE-416 7.8AIHighAI2025-10-29
CVE-2025-11464 Ashlar-Vellum Cobalt CO File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability — CobaltCWE-122 7.8AIHighAI2025-10-29
CVE-2025-11463 Ashlar-Vellum Cobalt XE File Parsing Integer Overflow Remote Code Execution Vulnerability — CobaltCWE-190 7.8AIHighAI2025-10-29
CVE-2025-7993 Ashlar-Vellum Cobalt LI File Parsing Use-After-Free Remote Code Execution Vulnerability — CobaltCWE-416 7.8AIHighAI2025-09-17
CVE-2025-8006 Ashlar-Vellum Cobalt XE File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability — CobaltCWE-125 7.8AIHighAI2025-09-17
CVE-2025-8002 Ashlar-Vellum Cobalt CO File Parsing Type Confusion Remote Code Execution Vulnerability — CobaltCWE-843 7.8AIHighAI2025-09-17
CVE-2025-8004 Ashlar-Vellum Cobalt XE File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability — CobaltCWE-125 7.8AIHighAI2025-09-17
CVE-2025-8005 Ashlar-Vellum Cobalt XE File Parsing Type Confusion Remote Code Execution Vulnerability — CobaltCWE-843 7.8AIHighAI2025-09-17
CVE-2025-8001 Ashlar-Vellum Cobalt CO File Parsing Memory Corruption Remote Code Execution Vulnerability — CobaltCWE-119 7.8AIHighAI2025-09-17
CVE-2025-8003 Ashlar-Vellum Cobalt CO File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability — CobaltCWE-125 7.8AIHighAI2025-09-17
CVE-2025-7997 Ashlar-Vellum Cobalt XE File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability — CobaltCWE-125 7.8AIHighAI2025-09-17
CVE-2025-8000 Ashlar-Vellum Cobalt LI File Parsing Type Confusion Remote Code Execution Vulnerability — CobaltCWE-843 7.8AIHighAI2025-09-17
CVE-2025-7995 Ashlar-Vellum Cobalt CO File Parsing Type Confusion Remote Code Execution Vulnerability — CobaltCWE-843 7.8AIHighAI2025-09-17
CVE-2025-7996 Ashlar-Vellum Cobalt AR File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability — CobaltCWE-787 7.8AIHighAI2025-09-17
CVE-2025-7998 Ashlar-Vellum Cobalt CO File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability — CobaltCWE-787 7.8AIHighAI2025-09-17
CVE-2025-7994 Ashlar-Vellum Cobalt AR File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability — CobaltCWE-125 7.8AIHighAI2025-09-17
CVE-2025-7999 Ashlar-Vellum Cobalt AR File Parsing Type Confusion Remote Code Execution Vulnerability — CobaltCWE-843 7.8AIHighAI2025-09-17
CVE-2025-7988 Ashlar-Vellum Graphite VC6 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability — GraphiteCWE-787 7.8AIHighAI2025-09-17
CVE-2025-7991 Ashlar-Vellum Cobalt VC6 File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability — CobaltCWE-125 7.8AIHighAI2025-09-17
CVE-2025-7992 Ashlar-Vellum Cobalt AR File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability — CobaltCWE-125 7.8AIHighAI2025-09-17
CVE-2025-7987 Ashlar-Vellum Graphite VC6 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability — GraphiteCWE-787 7.8AIHighAI2025-09-17
CVE-2025-7989 Ashlar-Vellum Cobalt AR File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability — CobaltCWE-125 7.8AIHighAI2025-09-17
CVE-2025-7986 Ashlar-Vellum Graphite VC6 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability — GraphiteCWE-787 7.8AIHighAI2025-09-17
CVE-2025-7990 Ashlar-Vellum Cobalt VC6 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability — CobaltCWE-787 7.8AIHighAI2025-09-17
CVE-2025-7985 Ashlar-Vellum Cobalt VC6 File Parsing Integer Overflow Remote Code Execution Vulnerability — CobaltCWE-190 7.8AIHighAI2025-09-17
CVE-2025-7984 Ashlar-Vellum Cobalt AR File Parsing Uninitialized Variable Remote Code Execution Vulnerability — CobaltCWE-457 7.8AIHighAI2025-09-17
CVE-2025-7983 Ashlar-Vellum Graphite VC6 File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability — GraphiteCWE-122 7.8AIHighAI2025-09-17
CVE-2025-7981 Ashlar-Vellum Graphite VC6 File Parsing Uninitialized Variable Remote Code Execution Vulnerability — GraphiteCWE-457 7.8AIHighAI2025-09-17

This page lists every published CVE security advisory associated with Ashlar-Vellum. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.