← Back

Autodesk

autodesk

364 CVEs • 74 products

Products (74)

Click to collapse
Toggle
Autocad
autocad
Autocad Mep
autocad_mep
Advance Steel
advance_steel
Civil 3d
civil_3d
Autocad Lt
autocad_lt
Navisworks
navisworks
Design Review
design_review
Revit
revit
3ds Max
3ds_max
Dwg Trueview
dwg_trueview
Inventor
inventor
Fusion
fusion
Fbx Review
fbx_review
Infraworks
infraworks
Autocad P&id
autocad_p&id
Vred
vred
Maya Usd
maya_usd
3ds Max Usd
3ds_max_usd
Installer
installer
Maya
maya
Alias
alias
Dwf Viewer
dwf_viewer
Vault
vault
Civil Design
civil_design
Land Desktop
land_desktop
Map 3d
map_3d
Raster Design
raster_design
Survey
survey
Utility Design
utility_design
Viz
viz
Backburner
backburner
Autodesk Maya
autodesk_maya
Autocad Ecscad
autocad_ecscad
Sketchbook
sketchbook
Dynamo Bim
dynamo_bim
Fusion 360
fusion_360
Revit Lt
revit_lt

CVEs (364)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Autodesk
1Fbx Software Development Kit
May 13, 2026
Jan 25, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Multiple buffer overflows in the Autodesk FBX-SDK before 2017.1 can allow attackers to execute arbitrary code when reading or converting malformed DAE format files.
1Autodesk
1Fbx Software Development Kit
May 13, 2026
Jan 25, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Improper handling in the Autodesk FBX-SDK before 2017.1 of type mismatches and previously deleted objects related to reading and converting malformed FBX format files can allow attackers to gain access to uninitialized p...Show more
Improper handling in the Autodesk FBX-SDK before 2017.1 of type mismatches and previously deleted objects related to reading and converting malformed FBX format files can allow attackers to gain access to uninitialized pointers.Show less
1Autodesk
1Fbx Software Development Kit
May 13, 2026
Jan 25, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Multiple buffer overflows in the Autodesk FBX-SDK before 2017.1 can allow attackers to execute arbitrary code when reading or converting malformed DFX format files.
1Autodesk
1Fbx Software Development Kit
May 13, 2026
Jan 25, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Multiple buffer overflows in the Autodesk FBX-SDK before 2017.1 can allow attackers to execute arbitrary code or cause an infinite loop condition when reading or converting malformed FBX format files.
1Autodesk
1Autodesk Backburner
May 6, 2026
Mar 28, 2016
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Stack-based buffer overflow in manager.exe in Backburner Manager in Autodesk Backburner 2016 2016.0.0.2150 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a c...Show more
Stack-based buffer overflow in manager.exe in Backburner Manager in Autodesk Backburner 2016 2016.0.0.2150 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a crafted command. NOTE: this is only a vulnerability in environments in which the administrator has not followed documentation that outlines the security risks of operating Backburner on untrusted networks.Show less
1Autodesk
1Design Review
May 6, 2026
Dec 15, 2015
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple buffer overflows in Autodesk Design Review (ADR) before 2013 Hotfix 2 allow remote attackers to execute arbitrary code via crafted RLE data in a (1) BMP or (2) FLI file, (3) encoded scan lines in a PCX file, or...Show more
Multiple buffer overflows in Autodesk Design Review (ADR) before 2013 Hotfix 2 allow remote attackers to execute arbitrary code via crafted RLE data in a (1) BMP or (2) FLI file, (3) encoded scan lines in a PCX file, or (4) DataSubBlock or (5) GlobalColorTable in a GIF file.Show less
1Autodesk
1Design Review
May 6, 2026
Dec 15, 2015
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Integer overflow in Autodesk Design Review (ADR) before 2013 Hotfix 2 allows remote attackers to execute arbitrary code via a crafted biClrUsed value in a BMP file, which triggers a buffer overflow.
1Autodesk
1Design Review
May 6, 2026
Dec 8, 2014
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The AdView.AdViewer.1 ActiveX control in Autodesk Design Review (ADR) before 2013 Hotfix 1 allows remote attackers to execute arbitrary code via a crafted DWF file.
1Autodesk
1Sketchbook Pro
May 6, 2026
Jul 23, 2014
N/A· v4
N/A· v3
9.3 HIGH· v2
Heap-based buffer overflow in Autodesk SketchBook Pro before 6.2.6 allows remote attackers to execute arbitrary code via crafted layer bitmap data in a PXD file.
1Autodesk
1Sketchbook Pro
May 6, 2026
Jul 23, 2014
N/A· v4
N/A· v3
9.3 HIGH· v2
Integer overflow in Autodesk SketchBook Pro before 6.2.6 allows remote attackers to execute arbitrary code via crafted layer mask data in a PSD file, which triggers a heap-based buffer overflow.
1Autodesk
1Vred
May 6, 2026
Jul 7, 2014
N/A· v4
N/A· v3
10.0 HIGH· v2
Autodesk VRED Professional 2014 before SR1 SP8 allows remote attackers to execute arbitrary code via Python os library calls in Python API commands to the integrated web server.
1Autodesk
4Sketchbook
Sketchbook ExpressSketchbook For Enterprise 2014+1 more
May 6, 2026
Apr 2, 2014
N/A· v4
N/A· v3
9.3 HIGH· v2
Heap-based buffer overflow in Autodesk SketchBook for Enterprise 2014, Pro, and Express before 6.25, and Copic Edition before 2.0.2 allows remote attackers to execute arbitrary code via RLE-compressed channel data in a P...Show more
Heap-based buffer overflow in Autodesk SketchBook for Enterprise 2014, Pro, and Express before 6.25, and Copic Edition before 2.0.2 allows remote attackers to execute arbitrary code via RLE-compressed channel data in a PSD file.Show less
1Autodesk
1Autocad
Apr 29, 2026
Feb 22, 2014
N/A· v4
N/A· v3
4.4 MEDIUM· v2
Untrusted search path vulnerability in Autodesk AutoCAD before 2014 allows local users to gain privileges via a Trojan horse DLL in the current working directory.
1Autodesk
1Autocad
Apr 29, 2026
Feb 22, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
Untrusted search path vulnerability in Autodesk AutoCAD before 2014 allows local users to gain privileges and execute arbitrary VBScript code via a Trojan horse FAS file in the FAS file search path.
1Autodesk
14Autocad
Autocad ArchitectureAutocad Civil 3d+11 more
Apr 29, 2026
Jul 18, 2013
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Unspecified vulnerability in Autodesk AutoCAD through 2014, AutoCAD LT through 2014, and DWG TrueView through 2014 allows remote attackers to execute arbitrary code via a crafted DWG file.
1Autodesk
1Autocad
Apr 29, 2026
Sep 7, 2012
N/A· v4
N/A· v3
6.9 MEDIUM· v2
Multiple untrusted search path vulnerabilities in Autodesk AutoCAD 2010 allow local users to gain privileges via a Trojan horse (1) dwmapi.dll or (2) IBFS32.DLL file in the current working directory, as demonstrated by a...Show more
Multiple untrusted search path vulnerabilities in Autodesk AutoCAD 2010 allow local users to gain privileges via a Trojan horse (1) dwmapi.dll or (2) IBFS32.DLL file in the current working directory, as demonstrated by a directory that contains a .dwg file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.Show less
1Autodesk
1Design Review 2011
Apr 29, 2026
Sep 7, 2012
N/A· v4
N/A· v3
6.9 MEDIUM· v2
Multiple untrusted search path vulnerabilities in Autodesk Design Review 2011 11.0.0.86 allow local users to gain privileges via a Trojan horse (1) dwmapi.dll, (2) whiptk_wt.7.12.601.dll, or (3) xaml_wt.7.6.0.dll file in...Show more
Multiple untrusted search path vulnerabilities in Autodesk Design Review 2011 11.0.0.86 allow local users to gain privileges via a Trojan horse (1) dwmapi.dll, (2) whiptk_wt.7.12.601.dll, or (3) xaml_wt.7.6.0.dll file in the current working directory, as demonstrated by a directory that contains a .dwf file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.Show less
1Autodesk
2Alias Wavefront Maya
Autodesk Maya
Apr 23, 2026
Nov 24, 2009
N/A· v4
N/A· v3
9.3 HIGH· v2
Autodesk Maya 8.0, 8.5, 2008, 2009, and 2010 and Alias Wavefront Maya 6.5 and 7.0 allow remote attackers to execute arbitrary code via a (1) .ma or (2) .mb file that uses the Maya Embedded Language (MEL) python command o...Show more
Autodesk Maya 8.0, 8.5, 2008, 2009, and 2010 and Alias Wavefront Maya 6.5 and 7.0 allow remote attackers to execute arbitrary code via a (1) .ma or (2) .mb file that uses the Maya Embedded Language (MEL) python command or unspecified other MEL commands, related to "Script Nodes."Show less
1Autodesk
13ds Max
Apr 23, 2026
Nov 24, 2009
N/A· v4
N/A· v3
9.3 HIGH· v2
Autodesk 3D Studio Max (3DSMax) 6 through 9 and 2008 through 2010 allows remote attackers to execute arbitrary code via a .max file with a MAXScript statement that calls the DOSCommand method, related to "application cal...Show more
Autodesk 3D Studio Max (3DSMax) 6 through 9 and 2008 through 2010 allows remote attackers to execute arbitrary code via a .max file with a MAXScript statement that calls the DOSCommand method, related to "application callbacks."Show less
1Autodesk
2Autodesk Softimage
Autodesk Softimage Xsi
Apr 23, 2026
Nov 24, 2009
N/A· v4
N/A· v3
9.3 HIGH· v2
Autodesk Softimage 7.x and Softimage XSI 6.x allow remote attackers to execute arbitrary JavaScript code via a scene package containing a Scene Table of Contents (aka .scntoc) file with a Script_Content element, as demon...Show more
Autodesk Softimage 7.x and Softimage XSI 6.x allow remote attackers to execute arbitrary JavaScript code via a scene package containing a Scene Table of Contents (aka .scntoc) file with a Script_Content element, as demonstrated by code that loads the WScript.Shell ActiveX control.Show less