CNNVD-202509-2635 Information
Sep 17, 2025
cve
CNNVD ID
CNNVD-202509-2635
Related CVE
- CNNVD Published: 2025-09-17
Description (Chinese)
Ashlar-Vellum Cobalt是Ashlar-Vellum公司的一种基于参数的计算机辅助设计和 3D 建模程序。 Ashlar-Vellum Cobalt存在缓冲区错误漏洞,该漏洞源于CO文件解析过程中缺乏对用户提供数据的适当验证,可能导致内存损坏,从而在当前进程环境中执行任意代码。
Description (English)
Ashlar-Vellam Cobalt is an argument-based computer-aided design and 3D modelling program for Ashlar-Vellum. Ashlar-Vellam Cobalt had a buffer zone error loophole, which stemmed from the lack of proper validation of data provided by users during the CO document analysis process, which could lead to memory damage and the implementation of any code in the current process environment.
Hazard Level
Medium
Vulnerability Type
缓冲区错误
Affected Vendor
Ashlar-Vellum
Published
2025-09-17
Last Modified
2026-02-24
References
https://www.zerodayinitiative.com/advisories/ZDI-25-721/
Share on: