← Back

Autodesk

autodesk

381 CVEs • 74 products

Products (74)

Click to collapse
Toggle
Autocad
autocad
Autocad Mep
autocad_mep
Advance Steel
advance_steel
Civil 3d
civil_3d
Autocad Lt
autocad_lt
Navisworks
navisworks
Design Review
design_review
Revit
revit
3ds Max
3ds_max
Dwg Trueview
dwg_trueview
Inventor
inventor
Fusion
fusion
Fbx Review
fbx_review
Infraworks
infraworks
Autocad P&id
autocad_p&id
Vred
vred
Maya Usd
maya_usd
Installer
installer
3ds Max Usd
3ds_max_usd
Maya
maya
Alias
alias
Dwf Viewer
dwf_viewer
Vault
vault
Civil Design
civil_design
Land Desktop
land_desktop
Map 3d
map_3d
Raster Design
raster_design
Survey
survey
Utility Design
utility_design
Viz
viz
Backburner
backburner
Autodesk Maya
autodesk_maya
Autocad Ecscad
autocad_ecscad
Sketchbook
sketchbook
Dynamo Bim
dynamo_bim
Fusion 360
fusion_360
Revit Lt
revit_lt

CVEs (381)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Autodesk
13ds Max
Aug 28, 2026
Aug 24, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
A maliciously crafted FLT file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute...Show more
A maliciously crafted FLT file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.Show less
1Autodesk
13ds Max
Aug 28, 2026
Aug 24, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current...Show more
A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.Show less
1Autodesk
13ds Max
Aug 28, 2026
Aug 24, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
A maliciously crafted ABC file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute...Show more
A maliciously crafted ABC file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.Show less
1Autodesk
13ds Max
Aug 28, 2026
Aug 24, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arb...Show more
A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.Show less
1Autodesk
13ds Max
Aug 28, 2026
Aug 24, 2026
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can trigger an Uncontrolled Recursion vulnerability. A malicious actor may leverage this vulnerability to cause the application to terminate unexpecte...Show more
A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can trigger an Uncontrolled Recursion vulnerability. A malicious actor may leverage this vulnerability to cause the application to terminate unexpectedly, resulting in a denial-of-service.Show less
1Autodesk
1Installer
Sep 4, 2026
Aug 12, 2026
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A maliciously crafted input, when processed by the Autodesk Installer IPC frame parser, may trigger improper validation of an input-specified position or offset, resulting in an out-of-range substring operation. A malici...Show more
A maliciously crafted input, when processed by the Autodesk Installer IPC frame parser, may trigger improper validation of an input-specified position or offset, resulting in an out-of-range substring operation. A malicious actor may leverage this vulnerability to cause the NT AUTHORITY\SYSTEM service to terminate unexpectedly, resulting in a denial-of-service condition.Show less
1Autodesk
1Installer
Sep 4, 2026
Aug 12, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
A maliciously created executable, when executed on the victim's machine, may allow a local low-privileged attacker to inject unauthenticated IPC messages into named pipes, modify pipe permissions or ownership, and potent...Show more
A maliciously created executable, when executed on the victim's machine, may allow a local low-privileged attacker to inject unauthenticated IPC messages into named pipes, modify pipe permissions or ownership, and potentially impact confidentiality, integrity, and availability.Show less
1Autodesk
1Revit
Sep 4, 2026
Aug 6, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute ar...Show more
A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.Show less
1Autodesk
12Advance Steel
AutocadAutocad Architecture+9 more
Sep 4, 2026
Aug 6, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
A maliciously crafted BMP file, when parsed through certain Autodesk products, can force a Untrusted Pointer Dereference vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the c...Show more
A maliciously crafted BMP file, when parsed through certain Autodesk products, can force a Untrusted Pointer Dereference vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.Show less
1Autodesk
12Advance Steel
AutocadAutocad Architecture+9 more
Sep 4, 2026
Aug 6, 2026
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A maliciously crafted TIF file, when parsed through certain Autodesk products during image import, can cause an Out-of-Bounds Read in the image handling library. A malicious actor can leverage this vulnerability to cause...Show more
A maliciously crafted TIF file, when parsed through certain Autodesk products during image import, can cause an Out-of-Bounds Read in the image handling library. A malicious actor can leverage this vulnerability to cause a denial of serviceShow less
1Autodesk
1Revit
Sep 4, 2026
Aug 6, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
A maliciously crafted PDF file, when parsed through Autodesk Revit, can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to cause a crash, disclose sensitive data, or execute arbitr...Show more
A maliciously crafted PDF file, when parsed through Autodesk Revit, can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to cause a crash, disclose sensitive data, or execute arbitrary code in the context of the current process.Show less
1Autodesk
1Revit
Sep 4, 2026
Aug 6, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbit...Show more
A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.Show less
1Autodesk
1Fbx Software Development Kit
Sep 4, 2026
Aug 4, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buffer overflow vulnerability in fbxsdk::ExtractDrive. A malicious actor can leverage this vulnerability to execute arbitrar...Show more
A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buffer overflow vulnerability in fbxsdk::ExtractDrive. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.Show less
1Autodesk
1Fbx Software Development Kit
Sep 4, 2026
Aug 4, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buffer overflow vulnerability in fbxsdk::FbxIO::BinaryReadSectionHeader. A malicious actor can leverage this vulnerability t...Show more
A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buffer overflow vulnerability in fbxsdk::FbxIO::BinaryReadSectionHeader. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.Show less
1Autodesk
11Advance Steel
AutocadAutocad Architecture+8 more
Sep 2, 2026
Jul 29, 2026
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A maliciously crafted DWG or DXF file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash or disclose sensitive informa...Show more
A maliciously crafted DWG or DXF file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash or disclose sensitive information.Show less
1Autodesk
11Advance Steel
AutocadAutocad Architecture+8 more
Sep 2, 2026
Jul 29, 2026
N/A· v4
7.1 HIGH· v3
N/A· v2
A maliciously crafted DWG or DXF file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash or disclose sensitive informa...Show more
A maliciously crafted DWG or DXF file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash or disclose sensitive information.Show less
1Autodesk
11Advance Steel
AutocadAutocad Architecture+8 more
Sep 2, 2026
Jul 29, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
A maliciously crafted DXF file, when parsed through Autodesk AutoCAD, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arb...Show more
A maliciously crafted DXF file, when parsed through Autodesk AutoCAD, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.Show less
1Autodesk
1Fusion
Jun 24, 2026
Jun 22, 2026
N/A· v4
9.6 CRITICAL· v3
N/A· v2
A maliciously crafted webpage, when visited by a user with Autodesk Fusion Desktop running and the MCP extension enabled, can trigger a vulnerability in the MCP extension that could allow arbitrary code execution. A succ...Show more
A maliciously crafted webpage, when visited by a user with Autodesk Fusion Desktop running and the MCP extension enabled, can trigger a vulnerability in the MCP extension that could allow arbitrary code execution. A successful exploit may allow code to execute with the privileges of the current user.Show less
1Autodesk
1Revit
Jun 29, 2026
Jun 17, 2026
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A maliciously crafted RFA file, when converted to FormIt via “Convert RFA to FormIt” in Autodesk Revit, can force a NULL Pointer Dereference vulnerability. Successful exploitation may cause the application to crash, lead...Show more
A maliciously crafted RFA file, when converted to FormIt via “Convert RFA to FormIt” in Autodesk Revit, can force a NULL Pointer Dereference vulnerability. Successful exploitation may cause the application to crash, leading to a denial-of-service condition.Show less
1Autodesk
13ds Max
Jul 24, 2026
May 26, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current...Show more
A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.Show less