VYPR

Vendor CVEs

Autodesk

All CVEs

377 total · sorted by risk
  • CVE-2021-40161HigDec 23, 2021
    risk 0.51cvss 7.8epss 0.01

    A Memory Corruption vulnerability may lead to code execution through maliciously crafted DLL files through PDFTron earlier than 9.0.7 version.

  • CVE-2021-40160HigDec 23, 2021
    risk 0.51cvss 7.8epss 0.02

    PDFTron prior to 9.0.7 version may be forced to read beyond allocated boundaries when parsing a maliciously crafted PDF file. This vulnerability can be exploited to execute arbitrary code.

  • CVE-2021-40156HigSep 15, 2021
    risk 0.51cvss 7.8epss 0.01

    A maliciously crafted DWG file in Autodesk Navisworks 2019, 2020, 2021, 2022 can be forced to write beyond allocated boundaries when parsing the DWG files. This vulnerability can be exploited to execute arbitrary code.

  • CVE-2021-40155HigSep 15, 2021
    risk 0.51cvss 7.8epss 0.01

    A maliciously crafted DWG file in Autodesk Navisworks 2019, 2020, 2021, 2022 can be forced to read beyond allocated boundaries when parsing the DWG files. This vulnerability can be exploited to execute arbitrary code.

  • CVE-2021-27046HigSep 15, 2021
    risk 0.51cvss 7.8epss 0.00

    A Memory Corruption vulnerability for PDF files in Autodesk Navisworks 2019, 2020, 2021, 2022 may lead to code execution through maliciously crafted DLL files.

  • CVE-2021-27045HigSep 15, 2021
    risk 0.51cvss 7.8epss 0.01

    A maliciously crafted PDF file in Autodesk Navisworks 2019, 2020, 2021, 2022 can be forced to read beyond allocated boundaries when parsing the PDF file. This vulnerability can be exploited to execute arbitrary code.

  • CVE-2021-40157HigSep 15, 2021
    risk 0.51cvss 7.8epss 0.01

    A user may be tricked into opening a malicious FBX file which may exploit an Untrusted Pointer Dereference vulnerability in FBX’s Review version 1.5.0 and prior causing it to run arbitrary code on the system.

  • CVE-2021-27044HigSep 15, 2021
    risk 0.51cvss 7.8epss 0.01

    A Out-Of-Bounds Read/Write Vulnerability in Autodesk FBX Review version 1.4.0 may lead to remote code execution through maliciously crafted DLL files or information disclosure.

  • CVE-2021-27039HigJul 9, 2021
    risk 0.51cvss 7.8epss 0.02

    A maliciously crafted TIFF and PCX file can be forced to read and write beyond allocated boundaries when parsing the TIFF and PCX file for based overflow. This vulnerability can be exploited to execute arbitrary code.

  • CVE-2021-27038HigJul 9, 2021
    risk 0.51cvss 7.8epss 0.02

    A Type Confusion vulnerability in Autodesk Design Review 2018, 2017, 2013, 2012, 2011 can occur when processing a maliciously crafted PDF file. A malicious actor can leverage this to execute arbitrary code.

  • CVE-2021-27037HigJul 9, 2021
    risk 0.51cvss 7.8epss 0.02

    A maliciously crafted PNG, PDF or DWF file in Autodesk Design Review 2018, 2017, 2013, 2012, 2011 can be used to attempt to free an object that has already been freed while parsing them. This vulnerability may be exploited by remote malicious actors to execute arbitrary code.

  • CVE-2021-27036HigJul 9, 2021
    risk 0.51cvss 7.8epss 0.02

    A maliciously crafted PCX, PICT, RCL, TIF, BMP, PSD or TIFF file can be used to write beyond the allocated buffer while parsing PCX, PDF, PICT, RCL, BMP, PSD or TIFF files. This vulnerability can be exploited to execute arbitrary code

  • CVE-2021-27035HigJul 9, 2021
    risk 0.51cvss 7.8epss 0.02

    A maliciously crafted TIFF, TIF, PICT, TGA, or DWF files in Autodesk Design Review 2018, 2017, 2013, 2012, 2011 can be forced to read beyond allocated boundaries when parsing the TIFF, PICT, TGA or DWF files. This vulnerability in conjunction with other vulnerabilities could…

  • CVE-2021-27034HigJul 9, 2021
    risk 0.51cvss 7.8epss 0.02

    A heap-based buffer overflow could occur while parsing PICT, PCX, RCL or TIFF files in Autodesk Design Review 2018, 2017, 2013, 2012, 2011. This vulnerability can be exploited to execute arbitrary code.

  • CVE-2021-27043HigJun 25, 2021
    risk 0.51cvss 7.8epss 0.01

    An Arbitrary Address Write issue in the Autodesk DWG application can allow a malicious user to leverage the application to write in unexpected paths. In order to exploit this the attacker would need the victim to enable full page heap in the application.

  • CVE-2021-27042HigJun 25, 2021
    risk 0.51cvss 7.8epss 0.02

    A maliciously crafted DWG file can be used to write beyond the allocated buffer while parsing DWG files. The vulnerability exists because the application fails to handle a crafted DWG file, which causes an unhandled exception. An attacker can leverage this vulnerability to…

  • CVE-2021-27041HigJun 25, 2021
    risk 0.51cvss 7.8epss 0.02

    A maliciously crafted DWG file can be used to write beyond the allocated buffer while parsing DWG files. This vulnerability can be exploited to execute arbitrary code

  • CVE-2021-27032HigMay 28, 2021
    risk 0.51cvss 7.8epss 0.00

    Autodesk Licensing Installer was found to be vulnerable to privilege escalation issues. A malicious user with limited privileges could run any number of tools on a system to identify services that are configured with weak permissions and are running under elevated privileges.…

  • CVE-2021-27031HigApr 19, 2021
    risk 0.51cvss 7.8epss 0.01

    A user may be tricked into opening a malicious FBX file which may exploit a use-after-free vulnerability in FBX's Review causing the application to reference a memory location controlled by an unauthorized third party, thereby running arbitrary code on the system.

  • CVE-2021-27028HigApr 19, 2021
    risk 0.51cvss 7.8epss 0.02

    A Memory Corruption Vulnerability in Autodesk FBX Review version 1.5.0 and prior may lead to remote code execution through maliciously crafted DLL files.

  • CVE-2021-27027HigApr 19, 2021
    risk 0.51cvss 7.8epss 0.02

    An Out-Of-Bounds Read Vulnerability in Autodesk FBX Review version 1.5.0 and prior may lead to code execution through maliciously crafted DLL files or information disclosure.

  • CVE-2020-7085HigApr 17, 2020
    risk 0.51cvss 7.8epss 0.01

    A heap overflow vulnerability in the Autodesk FBX-SDK versions 2019.2 and earlier may lead to arbitrary code execution on a system running it.

  • CVE-2020-7080HigApr 17, 2020
    risk 0.51cvss 7.8epss 0.01

    A buffer overflow vulnerability in the Autodesk FBX-SDK versions 2019.0 and earlier may lead to arbitrary code execution on a system running it.

  • CVE-2020-7079HigApr 17, 2020
    risk 0.51cvss 7.8epss 0.00

    An improper signature validation vulnerability in Autodesk Dynamo BIM versions 2.5.1 and 2.5.0 may lead to code execution through maliciously crafted DLL files.

  • CVE-2019-7366HigDec 3, 2019
    risk 0.51cvss 7.8epss 0.01

    Buffer overflow vulnerability in Autodesk FBX Software Development Kit version 2019.5. A user may be tricked into opening a malicious FBX file which may exploit a buffer overflow vulnerability causing it to run arbitrary code on the system.

  • CVE-2019-7365HigDec 3, 2019
    risk 0.51cvss 7.8epss 0.00

    DLL preloading vulnerability in Autodesk Desktop Application versions 7.0.16.29 and earlier. An attacker may trick a user into downloading a malicious DLL file into the working directory, which may then leverage a DLL preloading vulnerability and execute code on the system.

  • CVE-2019-7364HigAug 23, 2019
    risk 0.51cvss 7.8epss 0.02

    DLL preloading vulnerability in versions 2017, 2018, 2019, and 2020 of Autodesk Advanced Steel, Civil 3D, AutoCAD, AutoCAD LT, AutoCAD Architecture, AutoCAD Electrical, AutoCAD Map 3D, AutoCAD Mechanical, AutoCAD MEP, AutoCAD Plant 3D and version 2017 of AutoCAD P&ID. An…

  • CVE-2019-7363HigAug 23, 2019
    risk 0.51cvss 7.8epss 0.01

    Use-after-free vulnerability in Autodesk Design Review versions 2011, 2012, 2013, and 2018. An attacker may trick a user into opening a malicious DWF file that may leverage a use-after-free vulnerability, which may result in code execution.

  • CVE-2019-7362HigAug 23, 2019
    risk 0.51cvss 7.8epss 0.01

    DLL preloading vulnerability in Autodesk Design Review versions 2011, 2012, 2013, and 2018. An attacker may trick a user into opening a malicious DWF file that may leverage a DLL preloading vulnerability, which may result in code execution.

  • CVE-2019-7361HigApr 9, 2019
    risk 0.51cvss 7.8epss 0.01

    An attacker may convince a victim to open a malicious action micro (.actm) file that has serialized data, which may trigger a code execution in Autodesk Advance Steel 2018, Autodesk AutoCAD 2018, Autodesk AutoCAD Architecture 2018, Autodesk AutoCAD Electrical 2018, Autodesk…

  • CVE-2019-7360HigApr 9, 2019
    risk 0.51cvss 7.8epss 0.02

    An exploitable use-after-free vulnerability in the DXF-parsing functionality in Autodesk Advance Steel 2018, Autodesk AutoCAD 2018, Autodesk AutoCAD Architecture 2018, Autodesk AutoCAD Electrical 2018, Autodesk AutoCAD Map 3D 2018, Autodesk AutoCAD Mechanical 2018, Autodesk…

  • CVE-2019-7359HigApr 9, 2019
    risk 0.51cvss 7.8epss 0.02

    An exploitable heap overflow vulnerability in the AcCellMargin handling code in Autodesk Advance Steel 2018, Autodesk AutoCAD 2018, Autodesk AutoCAD Architecture 2018, Autodesk AutoCAD Electrical 2018, Autodesk AutoCAD Map 3D 2018, Autodesk AutoCAD Mechanical 2018, Autodesk…

  • CVE-2019-7358HigApr 9, 2019
    risk 0.51cvss 7.8epss 0.02

    An exploitable heap overflow vulnerability in the DXF-parsing functionality in Autodesk Advance Steel 2018, Autodesk AutoCAD 2018, Autodesk AutoCAD Architecture 2018, Autodesk AutoCAD Electrical 2018, Autodesk AutoCAD Map 3D 2018, Autodesk AutoCAD Mechanical 2018, Autodesk…

  • CVE-2022-33884HigOct 3, 2022
    risk 0.49cvss 7.5epss 0.03

    Parsing a maliciously crafted X_B file can force Autodesk AutoCAD 2023 and 2022 to read beyond allocated boundaries. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.

  • CVE-2016-2344HigMar 28, 2016
    risk 0.49cvss 7.5epss 0.04

    Stack-based buffer overflow in manager.exe in Backburner Manager in Autodesk Backburner 2016 2016.0.0.2150 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a crafted command. NOTE: this is only a vulnerability in…

  • CVE-2026-4369HigApr 14, 2026
    risk 0.46cvss 7.1epss 0.00

    A maliciously crafted HTML payload in an assembly variant name, when displayed during the delete confirmation dialog and clicked by a user, can trigger a Stored Cross-site Scripting (XSS) vulnerability in the Autodesk Fusion desktop application. A malicious actor may leverage…

  • CVE-2026-4345HigApr 14, 2026
    risk 0.46cvss 7.1epss 0.00

    A maliciously crafted HTML payload, stored in a design name and exported to CSV, can trigger a Stored Cross-site Scripting (XSS) vulnerability in the Autodesk Fusion desktop application. A malicious actor may leverage this vulnerability to read local files or execute arbitrary…

  • CVE-2026-4344HigApr 14, 2026
    risk 0.46cvss 7.1epss 0.00

    A maliciously crafted HTML payload in a component name, when displayed during the delete confirmation dialog and clicked by a user, can trigger a Stored Cross-site Scripting (XSS) vulnerability in the Autodesk Fusion desktop application. A malicious actor may leverage this…

  • CVE-2022-42946HigDec 19, 2022
    risk 0.46cvss 7.1epss 0.00

    Parsing a maliciously crafted X_B and PRT file can force Autodesk Maya 2023 and 2022 to read beyond allocated buffer. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.

  • CVE-2022-27524HigApr 13, 2022
    risk 0.46cvss 7.1epss 0.01

    An out-of-bounds read can be exploited in Autodesk TrueView 2022 may lead to an exposure of sensitive information or a crash through using a maliciously crafted DWG file as an Input. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the…

  • CVE-2022-27523HigApr 13, 2022
    risk 0.46cvss 7.1epss 0.01

    A buffer over-read can be exploited in Autodesk TrueView 2022 may lead to an exposure of sensitive information or a crash through using a maliciously crafted DWG file as an Input. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the…

  • CVE-2025-4605MedJun 11, 2025
    risk 0.43cvss 6.6epss 0.00

    A maliciously crafted .usdc file, when loaded through Autodesk Maya, can force an uncontrolled memory allocation vulnerability. A malicious actor may leverage this vulnerability to cause a denial-of-service (DoS), or cause data corruption.

  • CVE-2020-7083MedApr 17, 2020
    risk 0.42cvss 6.5epss 0.01

    An intager overflow vulnerability in the Autodesk FBX-SDK versions 2019.0 and earlier may lead to denial of service of the application.

  • CVE-2026-16465MedJul 29, 2026
    risk 0.40cvss 6.1epss 0.00

    A maliciously crafted DWG or DXF file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash or disclose sensitive information.

  • CVE-2026-14479MedAug 12, 2026
    risk 0.36cvss 5.5epss 0.00

    A maliciously crafted input, when processed by the Autodesk Installer IPC frame parser, may trigger improper validation of an input-specified position or offset, resulting in an out-of-range substring operation. A malicious actor may leverage this vulnerability to cause the NT…

  • CVE-2026-7405MedAug 6, 2026
    risk 0.36cvss 5.5epss 0.00

    A maliciously crafted TIF file, when parsed through certain Autodesk products during image import, can cause an Out-of-Bounds Read in the image handling library. A malicious actor can leverage this vulnerability to cause a denial of service

  • CVE-2026-17550MedJul 29, 2026
    risk 0.36cvss 5.5epss 0.00

    A maliciously crafted DWG or DXF file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash or disclose sensitive information.

  • CVE-2026-1288MedJun 17, 2026
    risk 0.36cvss 5.5epss 0.00

    A maliciously crafted RFA file, when converted to FormIt via “Convert RFA to FormIt” in Autodesk Revit, can force a NULL Pointer Dereference vulnerability. Successful exploitation may cause the application to crash, leading to a denial-of-service condition.

  • CVE-2026-7453MedMay 26, 2026
    risk 0.36cvss 5.5epss 0.00

    A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can cause a Stack Exhaustion vulnerability, leading to a denial-of-service condition.

  • CVE-2026-7450MedMay 26, 2026
    risk 0.36cvss 5.5epss 0.00

    A maliciously crafted PAR file, when parsed through Autodesk 3ds Max, can force a NULL Pointer Dereference vulnerability. Successful exploitation may cause the application to crash, leading to a denial-of-service condition.

Page 7 of 8