← Back

Autodesk

autodesk

361 CVEs • 74 products

Products (74)

Click to collapse
Toggle
Autocad
autocad
Autocad Mep
autocad_mep
Advance Steel
advance_steel
Civil 3d
civil_3d
Autocad Lt
autocad_lt
Navisworks
navisworks
Design Review
design_review
Revit
revit
3ds Max
3ds_max
Dwg Trueview
dwg_trueview
Inventor
inventor
Fusion
fusion
Fbx Review
fbx_review
Infraworks
infraworks
Autocad P&id
autocad_p&id
Vred
vred
Maya Usd
maya_usd
3ds Max Usd
3ds_max_usd
Installer
installer
Maya
maya
Alias
alias
Dwf Viewer
dwf_viewer
Vault
vault
Civil Design
civil_design
Land Desktop
land_desktop
Map 3d
map_3d
Raster Design
raster_design
Survey
survey
Utility Design
utility_design
Viz
viz
Backburner
backburner
Autodesk Maya
autodesk_maya
Autocad Ecscad
autocad_ecscad
Sketchbook
sketchbook
Dynamo Bim
dynamo_bim
Fusion 360
fusion_360
Revit Lt
revit_lt

CVEs (361)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Autodesk
1Navisworks
Nov 21, 2024
Sep 15, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A maliciously crafted PDF file in Autodesk Navisworks 2019, 2020, 2021, 2022 can be forced to read beyond allocated boundaries when parsing the PDF file. This vulnerability can be exploited to execute arbitrary code.
1Autodesk
1Fbx Review
Nov 21, 2024
Sep 15, 2021
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
A user may be tricked into opening a malicious FBX file which may exploit an Untrusted Pointer Dereference vulnerability in FBX’s Review version 1.5.0 and prior causing it to run arbitrary code on the system.
1Autodesk
1Fbx Review
Nov 21, 2024
Sep 15, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A Out-Of-Bounds Read/Write Vulnerability in Autodesk FBX Review version 1.4.0 may lead to remote code execution through maliciously crafted DLL files or information disclosure.
1Autodesk
2Autocad
Design Review
Nov 21, 2024
Jul 9, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A maliciously crafted TIFF and PCX file can be forced to read and write beyond allocated boundaries when parsing the TIFF and PCX file for based overflow. This vulnerability can be exploited to execute arbitrary code.
1Autodesk
1Design Review
Nov 21, 2024
Jul 9, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A Type Confusion vulnerability in Autodesk Design Review 2018, 2017, 2013, 2012, 2011 can occur when processing a maliciously crafted PDF file. A malicious actor can leverage this to execute arbitrary code.
1Autodesk
1Design Review
Nov 21, 2024
Jul 9, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A maliciously crafted PNG, PDF or DWF file in Autodesk Design Review 2018, 2017, 2013, 2012, 2011 can be used to attempt to free an object that has already been freed while parsing them. This vulnerability may be exploit...Show more
A maliciously crafted PNG, PDF or DWF file in Autodesk Design Review 2018, 2017, 2013, 2012, 2011 can be used to attempt to free an object that has already been freed while parsing them. This vulnerability may be exploited by remote malicious actors to execute arbitrary code.Show less
1Autodesk
1Design Review
Nov 21, 2024
Jul 9, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A maliciously crafted PCX, PICT, RCL, TIF, BMP, PSD or TIFF file can be used to write beyond the allocated buffer while parsing PCX, PDF, PICT, RCL, BMP, PSD or TIFF files. This vulnerability can be exploited to execute...Show more
A maliciously crafted PCX, PICT, RCL, TIF, BMP, PSD or TIFF file can be used to write beyond the allocated buffer while parsing PCX, PDF, PICT, RCL, BMP, PSD or TIFF files. This vulnerability can be exploited to execute arbitrary codeShow less
1Autodesk
1Design Review
Nov 21, 2024
Jul 9, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A maliciously crafted TIFF, TIF, PICT, TGA, or DWF files in Autodesk Design Review 2018, 2017, 2013, 2012, 2011 can be forced to read beyond allocated boundaries when parsing the TIFF, PICT, TGA or DWF files. This vulner...Show more
A maliciously crafted TIFF, TIF, PICT, TGA, or DWF files in Autodesk Design Review 2018, 2017, 2013, 2012, 2011 can be forced to read beyond allocated boundaries when parsing the TIFF, PICT, TGA or DWF files. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.Show less
1Autodesk
1Design Review
Nov 21, 2024
Jul 9, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A heap-based buffer overflow could occur while parsing PICT, PCX, RCL or TIFF files in Autodesk Design Review 2018, 2017, 2013, 2012, 2011. This vulnerability can be exploited to execute arbitrary code.
1Autodesk
1Design Review
Nov 21, 2024
Jul 9, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A Double Free vulnerability allows remote attackers to execute arbitrary code on PDF files within affected installations of Autodesk Design Review 2018, 2017, 2013, 2012, 2011. User interaction is required to exploit thi...Show more
A Double Free vulnerability allows remote attackers to execute arbitrary code on PDF files within affected installations of Autodesk Design Review 2018, 2017, 2013, 2012, 2011. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.Show less
1Autodesk
11Advance Steel
AutocadAutocad Architecture+8 more
Nov 21, 2024
Jun 25, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
An Arbitrary Address Write issue in the Autodesk DWG application can allow a malicious user to leverage the application to write in unexpected paths. In order to exploit this the attacker would need the victim to enable...Show more
An Arbitrary Address Write issue in the Autodesk DWG application can allow a malicious user to leverage the application to write in unexpected paths. In order to exploit this the attacker would need the victim to enable full page heap in the application.Show less
1Autodesk
10Advance Steel
AutocadAutocad Architecture+7 more
Nov 21, 2024
Jun 25, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A maliciously crafted DWG file can be used to write beyond the allocated buffer while parsing DWG files. The vulnerability exists because the application fails to handle a crafted DWG file, which causes an unhandled exce...Show more
A maliciously crafted DWG file can be used to write beyond the allocated buffer while parsing DWG files. The vulnerability exists because the application fails to handle a crafted DWG file, which causes an unhandled exception. An attacker can leverage this vulnerability to execute arbitrary code.Show less
3Autodesk
IconicsMitsubishielectric
13Advance Steel
AutocadAutocad Architecture+10 more
Nov 21, 2024
Jun 25, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A maliciously crafted DWG file can be used to write beyond the allocated buffer while parsing DWG files. This vulnerability can be exploited to execute arbitrary code
3Autodesk
IconicsMitsubishielectric
13Advance Steel
AutocadAutocad Architecture+10 more
Nov 21, 2024
Jun 25, 2021
N/A· v4
3.3 LOW· v3
4.3 MEDIUM· v2
A maliciously crafted DWG file can be forced to read beyond allocated boundaries when parsing the DWG file. This vulnerability can be exploited to execute arbitrary code.
1Autodesk
1Licensing Services
Nov 21, 2024
May 28, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Autodesk Licensing Installer was found to be vulnerable to privilege escalation issues. A malicious user with limited privileges could run any number of tools on a system to identify services that are configured with wea...Show more
Autodesk Licensing Installer was found to be vulnerable to privilege escalation issues. A malicious user with limited privileges could run any number of tools on a system to identify services that are configured with weak permissions and are running under elevated privileges. These weak permissions could allow all users on the operating system to modify the service configuration and take ownership of the service.Show less
1Autodesk
1Fbx Review
Nov 21, 2024
Apr 19, 2021
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
A user may be tricked into opening a malicious FBX file which may exploit a use-after-free vulnerability in FBX's Review causing the application to reference a memory location controlled by an unauthorized third party, t...Show more
A user may be tricked into opening a malicious FBX file which may exploit a use-after-free vulnerability in FBX's Review causing the application to reference a memory location controlled by an unauthorized third party, thereby running arbitrary code on the system.Show less
1Autodesk
1Fbx Review
Nov 21, 2024
Apr 19, 2021
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
A user may be tricked into opening a malicious FBX file which may exploit a Directory Traversal Remote Code Execution vulnerability in FBX’s Review causing it to run arbitrary code on the system.
1Autodesk
1Fbx Review
Nov 21, 2024
Apr 19, 2021
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The user may be tricked into opening a malicious FBX file which may exploit a Null Pointer Dereference vulnerability in FBX's Review version 1.5.0 and prior causing the application to crash leading to a denial of service...Show more
The user may be tricked into opening a malicious FBX file which may exploit a Null Pointer Dereference vulnerability in FBX's Review version 1.5.0 and prior causing the application to crash leading to a denial of service.Show less
1Autodesk
1Fbx Review
Nov 21, 2024
Apr 19, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A Memory Corruption Vulnerability in Autodesk FBX Review version 1.5.0 and prior may lead to remote code execution through maliciously crafted DLL files.
1Autodesk
1Fbx Review
Nov 21, 2024
Apr 19, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
An Out-Of-Bounds Read Vulnerability in Autodesk FBX Review version 1.5.0 and prior may lead to code execution through maliciously crafted DLL files or information disclosure.