← Back

Autodesk

autodesk

364 CVEs • 74 products

Products (74)

Click to collapse
Toggle
Autocad
autocad
Autocad Mep
autocad_mep
Advance Steel
advance_steel
Civil 3d
civil_3d
Autocad Lt
autocad_lt
Navisworks
navisworks
Design Review
design_review
Revit
revit
3ds Max
3ds_max
Dwg Trueview
dwg_trueview
Inventor
inventor
Fusion
fusion
Fbx Review
fbx_review
Infraworks
infraworks
Autocad P&id
autocad_p&id
Vred
vred
Maya Usd
maya_usd
3ds Max Usd
3ds_max_usd
Installer
installer
Maya
maya
Alias
alias
Dwf Viewer
dwf_viewer
Vault
vault
Civil Design
civil_design
Land Desktop
land_desktop
Map 3d
map_3d
Raster Design
raster_design
Survey
survey
Utility Design
utility_design
Viz
viz
Backburner
backburner
Autodesk Maya
autodesk_maya
Autocad Ecscad
autocad_ecscad
Sketchbook
sketchbook
Dynamo Bim
dynamo_bim
Fusion 360
fusion_360
Revit Lt
revit_lt

CVEs (364)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Autodesk
10Autocad
Autocad Advance SteelAutocad Architecture+7 more
Jun 17, 2026
Oct 3, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
A maliciously crafted MODEL and SLDPRT file can be used to write beyond the allocated buffer while parsing through Autodesk AutoCAD 2023, 2022, 2021, 2020, and Maya 2023 and 2022. The vulnerability exists because the app...Show more
A maliciously crafted MODEL and SLDPRT file can be used to write beyond the allocated buffer while parsing through Autodesk AutoCAD 2023, 2022, 2021, 2020, and Maya 2023 and 2022. The vulnerability exists because the application fails to handle crafted MODEL and SLDPRT files, which causes an unhandled exception. A malicious actor could leverage this vulnerability to execute arbitrary code.Show less
1Autodesk
10Autocad
Autocad Advance SteelAutocad Architecture+7 more
Jun 17, 2026
Oct 3, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
A maliciously crafted X_B, CATIA, and PDF file when parsed through Autodesk AutoCAD 2023 and 2022 can be used to write beyond the allocated buffer. This vulnerability can lead to arbitrary code execution.
1Autodesk
10Autocad
Autocad Advance SteelAutocad Architecture+7 more
Jun 17, 2026
Oct 3, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Parsing a maliciously crafted X_B file can force Autodesk AutoCAD 2023 and 2022 to read beyond allocated boundaries. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the contex...Show more
Parsing a maliciously crafted X_B file can force Autodesk AutoCAD 2023 and 2022 to read beyond allocated boundaries. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.Show less
1Autodesk
4Advanced Material Exchange
Moldflow AdviserMoldflow Communicator+1 more
Jun 17, 2026
Oct 3, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
A malicious crafted file consumed through Moldflow Synergy, Moldflow Adviser, Moldflow Communicator, and Advanced Material Exchange applications could lead to memory corruption vulnerability. This vulnerability in conjun...Show more
A malicious crafted file consumed through Moldflow Synergy, Moldflow Adviser, Moldflow Communicator, and Advanced Material Exchange applications could lead to memory corruption vulnerability. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.Show less
1Autodesk
13ds Max
Jun 17, 2026
Aug 10, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
A Stack-based Buffer Overflow Vulnerability in Autodesk 3ds Max 2022, 2021, and 2020 may lead to code execution through the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-len...Show more
A Stack-based Buffer Overflow Vulnerability in Autodesk 3ds Max 2022, 2021, and 2020 may lead to code execution through the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer when parsing ActionScript Byte Code files. This vulnerability may allow arbitrary code execution on affected installations of Autodesk 3ds Max.Show less
1Autodesk
1Design Review
Jun 17, 2026
Jul 29, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
A maliciously crafted TIFF file when consumed through DesignReview.exe application can be forced to read beyond allocated boundaries when parsing the TIFF file. This vulnerability in conjunction with other vulnerabilitie...Show more
A maliciously crafted TIFF file when consumed through DesignReview.exe application can be forced to read beyond allocated boundaries when parsing the TIFF file. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.Show less
1Autodesk
1Design Review
Jun 17, 2026
Jul 29, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
A maliciously crafted TGA or PCX file may be used to write beyond the allocated buffer through DesignReview.exe application while parsing TGA and PCX files. This vulnerability may be exploited to execute arbitrary code.
1Autodesk
1Design Review
Jun 17, 2026
Jul 29, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
A Double Free vulnerability allows remote attackers to execute arbitrary code through DesignReview.exe application on PDF files within affected installations. User interaction is required to exploit this vulnerability in...Show more
A Double Free vulnerability allows remote attackers to execute arbitrary code through DesignReview.exe application on PDF files within affected installations. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.Show less
1Autodesk
10Autocad
Autocad Advance SteelAutocad Architecture+7 more
Jun 17, 2026
Jul 29, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
Parsing a maliciously crafted PRT file can force Autodesk AutoCAD 2023 to read beyond allocated boundaries. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the...Show more
Parsing a maliciously crafted PRT file can force Autodesk AutoCAD 2023 to read beyond allocated boundaries. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.Show less
1Autodesk
1Fusion 360
Jun 17, 2026
Jul 29, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
An attacker can force the victim’s device to perform arbitrary HTTP requests in WAN through a malicious SVG file being parsed by Autodesk Fusion 360’s document parser. The vulnerability exists in the application’s ‘Inser...Show more
An attacker can force the victim’s device to perform arbitrary HTTP requests in WAN through a malicious SVG file being parsed by Autodesk Fusion 360’s document parser. The vulnerability exists in the application’s ‘Insert SVG’ procedure. An attacker can also leverage this vulnerability to obtain victim’s public IP and possibly other sensitive information.Show less
1Autodesk
1Navisworks
Jun 17, 2026
Jun 21, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A maliciously crafted PDF file may be used to dereference a pointer for read or write operation while parsing PDF files in Autodesk Navisworks 2022. The vulnerability exists because the application fails to handle a craf...Show more
A maliciously crafted PDF file may be used to dereference a pointer for read or write operation while parsing PDF files in Autodesk Navisworks 2022. The vulnerability exists because the application fails to handle a crafted PDF file, which causes an unhandled exception. An attacker can leverage this vulnerability to cause a crash or read sensitive data or execute arbitrary code.Show less
1Autodesk
143ds Max
Advance SteelAutocad+11 more
Jun 17, 2026
Jun 21, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Autodesk AutoCAD product suite, Revit, Design Review and Navisworks releases using PDFTron prior to 9.1.17 version may be used to write beyond the allocated buffer while parsing PDF files. This vulnerability may be explo...Show more
Autodesk AutoCAD product suite, Revit, Design Review and Navisworks releases using PDFTron prior to 9.1.17 version may be used to write beyond the allocated buffer while parsing PDF files. This vulnerability may be exploited to execute arbitrary code.Show less
1Autodesk
1Autocad
Jun 17, 2026
Jun 21, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A maliciously crafted TGA file in Autodesk AutoCAD 2023 may be used to write beyond the allocated buffer while parsing TGA file. This vulnerability may be exploited to execute arbitrary code.
1Autodesk
1Autocad
Jun 17, 2026
Jun 21, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A maliciously crafted TIFF file in Autodesk AutoCAD 2023 can be forced to read and write beyond allocated boundaries when parsing the TIFF file. This vulnerability can be exploited to execute arbitrary code.
1Autodesk
1Autocad
Jun 17, 2026
Jun 21, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A maliciously crafted CAT file in Autodesk AutoCAD 2023 can be used to trigger use-after-free vulnerability. Exploitation of this vulnerability may lead to code execution.
1Autodesk
1Autocad
Jun 17, 2026
Jun 21, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A maliciously crafted JT file in Autodesk AutoCAD 2022, 2021, 2020, 2019 can be used to trigger use-after-free vulnerability. Exploitation of this vulnerability may lead to code execution.
1Autodesk
13ds Max
Jun 17, 2026
Jun 16, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A maliciously crafted TIF file in Autodesk 3ds Max 2022 and 2021 can be used to write beyond the allocated buffer while parsing TIF files. This vulnerability in conjunction with other vulnerabilities could lead to arbitr...Show more
A maliciously crafted TIF file in Autodesk 3ds Max 2022 and 2021 can be used to write beyond the allocated buffer while parsing TIF files. This vulnerability in conjunction with other vulnerabilities could lead to arbitrary code execution.Show less
1Autodesk
13ds Max
Jun 17, 2026
Jun 16, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A maliciously crafted TIF file can be forced to read beyond allocated boundaries in Autodesk 3ds Max 2022, and 2021 when parsing the TIF files. This vulnerability in conjunction with other vulnerabilities could lead to c...Show more
A maliciously crafted TIF file can be forced to read beyond allocated boundaries in Autodesk 3ds Max 2022, and 2021 when parsing the TIF files. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.Show less
1Autodesk
1Navisworks
Jun 17, 2026
Apr 19, 2022
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
A Memory Corruption vulnerability may lead to code execution through maliciously crafted DLL files. It was fixed in PDFTron earlier than 9.0.7 version in Autodesk Navisworks 2022, and 2020.
1Autodesk
11Advance Steel
AutocadAutocad Architecture+8 more
Jun 17, 2026
Apr 19, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A maliciously crafted JT file in Autodesk AutoCAD 2022 may be used to write beyond the allocated buffer while parsing JT files. This vulnerability can be exploited to execute arbitrary code.