CNNVD-202510-3947 Information

CNNVD ID

CNNVD-202510-3947

CVE-2025-11463

  • CNNVD Published: 2025-10-29

Description (Chinese)

Ashlar-Vellum Cobalt是Ashlar-Vellum公司的一种基于参数的计算机辅助设计和 3D 建模程序。 Ashlar-Vellum Cobalt存在输入验证错误漏洞,该漏洞源于XE文件解析时缺少对用户提供数据的验证,可能导致整数溢出和远程代码执行。

Description (English)

Ashlar-Vellam Cobalt is an argument-based computer-aided design and 3D modelling program for Ashlar-Vellum. Ashlar-Vellam Cobalt has an input validation bug, which arises from the lack of validation of data provided by users when XE files are analysed, which may result in integer spills and remote code execution.

Hazard Level

Medium

Vulnerability Type

输入验证错误

Affected Vendor

Ashlar-Vellum

Published

2025-10-29

Last Modified

2026-02-24

References

https://www.zerodayinitiative.com/advisories/ZDI-25-954/

Share on: