Out-Of-Bounds Read Vulnerability in Ashlar-Vellum Cobalt
CVE-2025-7977
7.8HIGH
What is CVE-2025-7977?
A critical flaw has been identified in the Ashlar-Vellum Cobalt software, specifically concerning the parsing of LI files. Due to inadequate validation of user-supplied data, this flaw may lead to an out-of-bounds read, allowing remote attackers to execute arbitrary code. Exploiting this vulnerability necessitates that users interact with malicious content, such as visiting a harmful page or opening a specially crafted file. If successful, an attacker can run code within the context of the current user process, potentially leading to serious security breaches.
Affected Version(s)
Cobalt 1204.91