Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Ashlar-Vellum — Vulnerabilities & Security Advisories 101

Browse all 101 CVE security advisories affecting Ashlar-Vellum. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Ashlar-Vellum provides computer-aided design and drafting software primarily serving the masonry and stone industry. The platform’s extensive history has resulted in a significant vulnerability footprint, with 101 Common Vulnerabilities and Exposures currently recorded. These security flaws predominantly involve remote code execution, cross-site scripting, and privilege escalation, often stemming from inadequate input validation and improper access controls within the application’s architecture. While specific major incidents involving widespread exploitation remain largely undocumented in public threat intelligence feeds, the high volume of CVEs indicates systemic weaknesses in the software’s security lifecycle. Users are advised to maintain strict patch management protocols, as the legacy nature of the codebase presents persistent risks for unauthorized access and data compromise. Continuous monitoring and immediate application of vendor-provided security updates are essential to mitigate these known technical deficiencies and protect organizational infrastructure from potential exploitation.

CVE IDTitleCVSSSeverityPublished
CVE-2024-13044 Ashlar-Vellum Cobalt AR File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability — CobaltCWE-787 7.8 -2024-12-30
CVE-2023-44439 Ashlar-Vellum Xenon Uncontrolled Search Path Element Remote Code Execution Vulnerability — XenonCWE-427 7.8 -2024-05-03
CVE-2023-44440 Ashlar-Vellum Lithium Uncontrolled Search Path Element Remote Code Execution Vulnerability — LithiumCWE-427 7.8 -2024-05-03
CVE-2023-44438 Ashlar-Vellum Argon Uncontrolled Search Path Element Remote Code Execution Vulnerability — ArgonCWE-427 7.8 -2024-05-03
CVE-2023-44437 Ashlar-Vellum Cobalt Uncontrolled Search Path Element Remote Code Execution Vulnerability — CobaltCWE-427 7.8 -2024-05-03
CVE-2023-42105 Ashlar-Vellum Cobalt AR File Parsing Type Confusion Remote Code Execution Vulnerability — CobaltCWE-843 7.8 -2024-05-03
CVE-2023-42104 Ashlar-Vellum Cobalt AR File Parsing Use-After-Free Remote Code Execution Vulnerability — CobaltCWE-416 7.8 -2024-05-03
CVE-2023-42103 Ashlar-Vellum Cobalt AR File Parsing Use-After-Free Remote Code Execution Vulnerability — CobaltCWE-416 7.8 -2024-05-03
CVE-2023-42101 Ashlar-Vellum Cobalt AR File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability — CobaltCWE-125 7.8 -2024-05-03
CVE-2023-42102 Ashlar-Vellum Cobalt AR File Parsing Type Confusion Remote Code Execution Vulnerability — CobaltCWE-843 7.8 -2024-05-03
CVE-2023-35716 Ashlar-Vellum Cobalt AR File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability — CobaltCWE-125 7.8 -2024-05-03
CVE-2023-35715 Ashlar-Vellum Cobalt AR File Parsing Uninitialized Memory Remote Code Execution Vulnerability — CobaltCWE-824 7.8 -2024-05-03
CVE-2023-35714 Ashlar-Vellum Cobalt IGS File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability — CobaltCWE-125 7.8 -2024-05-03
CVE-2023-35713 Ashlar-Vellum Cobalt XE File Parsing Uninitialized Memory Remote Code Execution Vulnerability — CobaltCWE-824 7.8 -2024-05-03
CVE-2023-35712 Ashlar-Vellum Cobalt XE File Parsing Uninitialized Memory Remote Code Execution Vulnerability — CobaltCWE-824 7.8 -2024-05-03
CVE-2023-35711 Ashlar-Vellum Cobalt XE File Parsing Untrusted Pointer Dereference Remote Code Execution Vulnerability — CobaltCWE-822 7.8 -2024-05-03
CVE-2023-35709 Ashlar-Vellum Cobalt Heap-based Buffer Overflow Remote Code Execution Vulnerability — CobaltCWE-122 7.8 -2024-05-03
CVE-2023-35710 Ashlar-Vellum Cobalt Stack-based Buffer Overflow Remote Code Execution Vulnerability — CobaltCWE-121 7.8 -2024-05-03
CVE-2023-34311 Ashlar-Vellum Cobalt Untrusted Pointer Dereference Remote Code Execution Vulnerability — CobaltCWE-822 7.8 -2024-05-03
CVE-2023-34310 Ashlar-Vellum Cobalt Uninitialized Memory Remote Code Execution Vulnerability — CobaltCWE-457 7.8 -2024-05-03
CVE-2023-34308 Ashlar-Vellum Graphite VC6 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability — GraphiteCWE-787 7.8 -2024-05-03
CVE-2023-34309 Ashlar-Vellum Cobalt Untrusted Pointer Dereference Remote Code Execution Vulnerability — CobaltCWE-822 7.8 -2024-05-03
CVE-2023-34307 Ashlar-Vellum Graphite VC6 File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability — GraphiteCWE-787 7.8 -2024-05-03
CVE-2023-34306 Ashlar-Vellum Graphite VC6 File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability — GraphiteCWE-121 7.8 -2024-05-03
CVE-2023-34305 Ashlar-Vellum Cobalt Out-Of-Bounds Write Remote Code Execution Vulnerability — CobaltCWE-787 7.8 -2024-05-03
CVE-2023-34304 Ashlar-Vellum Cobalt Out-Of-Bounds Access Remote Code Execution Vulnerability — CobaltCWE-787 7.8 -2024-05-03
CVE-2023-34303 Ashlar-Vellum Cobalt Out-Of-Bounds Read Remote Code Execution Vulnerability — CobaltCWE-125 7.8 -2024-05-03
CVE-2023-34302 Ashlar-Vellum Cobalt CO File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability — CobaltCWE-121 7.8 -2024-05-03
CVE-2023-34301 Ashlar-Vellum Cobalt CO File Parsing Untrusted Pointer Dereference Remote Code Execution Vulnerability — CobaltCWE-822 7.8 -2024-05-03
CVE-2023-34300 Ashlar-Vellum Cobalt XE File Parsing Untrusted Pointer Dereference Remote Code Execution Vulnerability — CobaltCWE-822 7.8 -2024-05-03

This page lists every published CVE security advisory associated with Ashlar-Vellum. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.