8.4 HIGH
- CVSS version (CVSS): 4.0
- Attack Vector (AV): Local (L)
- Attack Complexity (AC): Low (L)
- Attack Requirement (AT): None (N)
- Privileges Required (PR): None (N)
- User Interaction (UI): Active (A)
- Vulnerable System Impact Confidentiality (VC): High (H)
- Vulnerable System Impact Integrity (VI): High (H)
- Vulnerable System Impact Availability (VA): High (H)
- Subsequent System Impact Confidentiality (SC): None (N)
- Subsequent System Impact Integrity (SI): None (N)
- Subsequent System Impact Availability (SA): None (N)
- Modified Attack Vector (MAV): Local (L)
- Modified Attack Complexity (MAC): Low (L)
- Modified Attack Requirement (MAT): None (N)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): Active (A)
- Modified Vulnerable System Impact Confidentiality (MVC): High (H)
- Modified Vulnerable System Impact Integrity (MVI): High (H)
- Modified Vulnerable System Impact Availability (MVA): High (H)
- Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
- Modified Subsequent System Impact Integrity (MSI): Negligible (N)
- Modified Subsequent System Impact Availability (MSA): Negligible (N)
- Safety (S): Not Defined (X)
- Automatable (AU): Not Defined (X)
- Recovery (R): Not Defined (X)
- Value Density (V): Not Defined (X)
- Vulnerability Response Effort (RE): Not Defined (X)
- Provider Urgency (U): Not Defined (X)
- Confidentiality Req. (CR): Not Defined (X)
- Integrity Req. (IR): Not Defined (X)
- Availability Req. (AR): Not Defined (X)
- Exploit Maturity (E): Not Defined (X)
by @LeSuisse Activity log
- Created suggestion
- @LeSuisse dismissed (not in Nixpkgs)
Out-of-bounds write in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, Cobalt Share
An Out-of-Bounds Write vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions 12.6.1204.216 and prior that could allow an attacker to execute arbitrary code when a specially crafted VC6 file is being parsed.
References
-
https://www.cisa.gov/news-events/ics-advisories/icsa-25-329-01 government-resource
Affected products
- =<12.6.1204.216
- =<12.6.1204.216
- =<12.6.1204.216
- =<12.6.1204.216
- =<12.6.1204.216
Matching in nixpkgs
pkgs.argon
Full featured tool for Roblox development
pkgs.xenon
Monitoring tool based on radon
pkgs.cobalt
Static site generator written in Rust
pkgs.argonaut
Keyboard-first terminal UI for Argo CD
pkgs.argononed
Replacement daemon for the Argon One Raspberry Pi case
-
nixos-unstable 0.4.1-unstable-2025-12-26
- nixpkgs-unstable 0.4.1-unstable-2025-12-26
- nixos-unstable-small 0.4.1-unstable-2025-12-26
-
nixos-25.11 2022-03-26
- nixos-25.11-small 2022-03-26
- nixpkgs-25.11-darwin 2022-03-26
pkgs.ocamlPackages.argon2
Ocaml bindings to Argon2
-
nixos-unstable argon2-1.0.2
- nixpkgs-unstable argon2-1.0.2
- nixos-unstable-small argon2-1.0.2
-
nixos-25.11 argon2-1.0.2
- nixos-25.11-small argon2-1.0.2
- nixpkgs-25.11-darwin argon2-1.0.2
pkgs.haskellPackages.argon2
Memory-hard password hash and proof-of-work function
pkgs.typstPackages.cobalt-cv
A clean two-column resume template with a shaded sidebar, Font Awesome icons, and a customizable accent color
pkgs.perlPackages.CryptArgon2
Perl interface to the Argon2 key derivation functions
-
nixos-unstable Argon2-0.019
- nixpkgs-unstable Argon2-0.019
- nixos-unstable-small Argon2-0.019
-
nixos-25.11 Argon2-0.019
- nixos-25.11-small Argon2-0.019
- nixpkgs-25.11-darwin Argon2-0.019
pkgs.perl5Packages.CryptArgon2
Perl interface to the Argon2 key derivation functions
-
nixos-unstable Argon2-0.019
- nixpkgs-unstable Argon2-0.019
- nixos-unstable-small Argon2-0.019
pkgs.ocamlPackages_latest.argon2
Ocaml bindings to Argon2
-
nixos-unstable argon2-1.0.2
- nixpkgs-unstable argon2-1.0.2
- nixos-unstable-small argon2-1.0.2
pkgs.perl538Packages.CryptArgon2
Perl interface to the Argon2 key derivation functions
-
nixos-25.11 Argon2-0.019
- nixos-25.11-small Argon2-0.019
- nixpkgs-25.11-darwin Argon2-0.019
pkgs.perl540Packages.CryptArgon2
Perl interface to the Argon2 key derivation functions
-
nixos-25.11 Argon2-0.019
- nixos-25.11-small Argon2-0.019
- nixpkgs-25.11-darwin Argon2-0.019
pkgs.python312Packages.argon2-cffi
Secure Password Hashes for Python
-
nixos-25.11 argon2-cffi-25.1.0
- nixos-25.11-small argon2-cffi-25.1.0
- nixpkgs-25.11-darwin argon2-cffi-25.1.0
pkgs.python313Packages.argon2-cffi
Secure Password Hashes for Python
-
nixos-unstable argon2-cffi-25.1.0
- nixpkgs-unstable argon2-cffi-25.1.0
- nixos-unstable-small argon2-cffi-25.1.0
-
nixos-25.11 argon2-cffi-25.1.0
- nixos-25.11-small argon2-cffi-25.1.0
- nixpkgs-25.11-darwin argon2-cffi-25.1.0
pkgs.python314Packages.argon2-cffi
Secure Password Hashes for Python
-
nixos-unstable argon2-cffi-25.1.0
- nixpkgs-unstable argon2-cffi-25.1.0
- nixos-unstable-small argon2-cffi-25.1.0
pkgs.typstPackages.cobalt-cv_0_1_0
A clean two-column resume template with a shaded sidebar, Font Awesome icons, and a customizable accent color
pkgs.perlPackages.CryptPassphraseArgon2
Argon2 encoder for Crypt::Passphrase
-
nixos-unstable Argon2-0.009
- nixpkgs-unstable Argon2-0.009
- nixos-unstable-small Argon2-0.009
-
nixos-25.11 Argon2-0.009
- nixos-25.11-small Argon2-0.009
- nixpkgs-25.11-darwin Argon2-0.009
pkgs.perl5Packages.CryptPassphraseArgon2
Argon2 encoder for Crypt::Passphrase
-
nixos-unstable Argon2-0.009
- nixpkgs-unstable Argon2-0.009
- nixos-unstable-small Argon2-0.009
pkgs.perl538Packages.CryptPassphraseArgon2
Argon2 encoder for Crypt::Passphrase
-
nixos-25.11 Argon2-0.009
- nixos-25.11-small Argon2-0.009
- nixpkgs-25.11-darwin Argon2-0.009
pkgs.perl540Packages.CryptPassphraseArgon2
Argon2 encoder for Crypt::Passphrase
-
nixos-25.11 Argon2-0.009
- nixos-25.11-small Argon2-0.009
- nixpkgs-25.11-darwin Argon2-0.009
pkgs.python312Packages.argon2-cffi-bindings
Low-level CFFI bindings for Argon2
-
nixos-25.11 argon2-cffi-bindings-25.1.0
- nixos-25.11-small argon2-cffi-bindings-25.1.0
- nixpkgs-25.11-darwin argon2-cffi-bindings-25.1.0
pkgs.python312Packages.dissect-cobaltstrike
Dissect module implementing a parser for Cobalt Strike related data
pkgs.python313Packages.argon2-cffi-bindings
Low-level CFFI bindings for Argon2
-
nixos-unstable argon2-cffi-bindings-25.1.0
- nixpkgs-unstable argon2-cffi-bindings-25.1.0
- nixos-unstable-small argon2-cffi-bindings-25.1.0
-
nixos-25.11 argon2-cffi-bindings-25.1.0
- nixos-25.11-small argon2-cffi-bindings-25.1.0
- nixpkgs-25.11-darwin argon2-cffi-bindings-25.1.0
pkgs.python313Packages.dissect-cobaltstrike
Dissect module implementing a parser for Cobalt Strike related data
pkgs.python314Packages.argon2-cffi-bindings
Low-level CFFI bindings for Argon2
-
nixos-unstable argon2-cffi-bindings-25.1.0
- nixpkgs-unstable argon2-cffi-bindings-25.1.0
- nixos-unstable-small argon2-cffi-bindings-25.1.0
Package maintainers
-
@StayBlue StayBlue <blue@spook.rip>
-
@ehrenschwan-gh Luca Schwan <luca@ehrenschwan.dev>
-
@Misterio77 Gabriel Fontes <eu@misterio.me>
-
@ethancedwards8 Ethan Carter Edwards <ethan@ethancedwards.com>
-
@olynch Owen Lynch <owen@olynch.me>
-
@Radvendii Taeer Bar-Yam <taeer@necsi.edu>
-
@Naora Joris Gundermann <jorisgundermann@gmail.com>
-
@fabaff Fabian Affolter <mail@fabian-affolter.ch>
-
@cherrypiejam Gongqi Huang
-
@RossSmyth Ross Smyth
-
@jfvillablanca Jann Marc Villablanca <jmfv.dev@gmail.com>