Vendor CVEs
Autodesk
All CVEs
377 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-11268 | Med | 0.36 | 5.5 | 0.00 | Dec 9, 2024 | A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Read. A malicious actor can leverage this vulnerability to cause a crash or could lead to an arbitrary memory leak. | ||
| CVE-2021-27029 | Med | 0.36 | 5.5 | 0.01 | Apr 19, 2021 | The user may be tricked into opening a malicious FBX file which may exploit a Null Pointer Dereference vulnerability in FBX's Review version 1.5.0 and prior causing the application to crash leading to a denial of service. | ||
| CVE-2020-7084 | Med | 0.36 | 5.5 | 0.01 | Apr 17, 2020 | A NULL pointer dereference vulnerability in the Autodesk FBX-SDK versions 2019.0 and earlier may lead to denial of service of the application. | ||
| CVE-2025-6632 | Med | 0.34 | 5.3 | 0.00 | Aug 6, 2025 | A maliciously crafted PSD file, when linked or imported into Autodesk 3ds Max, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process. | ||
| CVE-2023-41145 | Med | 0.34 | 5.3 | 0.01 | Nov 22, 2023 | Autodesk users who no longer have an active license for an account can still access cases for that account. | ||
| CVE-2023-7298 | Med | 0.29 | 4.4 | 0.00 | Dec 9, 2024 | A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process. | ||
| CVE-2023-41146 | Med | 0.28 | 4.3 | 0.00 | Nov 22, 2023 | Autodesk Customer Support Portal allows cases created by users under an account to see cases created by other users on the same account. | ||
| CVE-2021-27040 | Low | 0.22 | 3.3 | 0.03 | Jun 25, 2021 | A maliciously crafted DWG file can be forced to read beyond allocated boundaries when parsing the DWG file. This vulnerability can be exploited to execute arbitrary code. | ||
| CVE-2008-4472 | 0.04 | — | 0.08 | Oct 7, 2008 | The UpdateEngine class in the LiveUpdate ActiveX control (LiveUpdate16.DLL 17.2.56), as used in Revit Architecture 2009 SP2 and Autodesk Design Review 2009, allows remote attackers to execute arbitrary programs via the second argument to the ApplyPatch method. | |||
| CVE-2008-4471 | 0.04 | — | 0.07 | Oct 7, 2008 | Directory traversal vulnerability in the CExpressViewerControl class in the DWF Viewer ActiveX control (AdView.dll 9.0.0.96), as used in Revit Architecture 2009 SP2 and Autodesk Design Review 2009, allows remote attackers to overwrite arbitrary files via "..\" sequences in the… | |||
| CVE-2010-5241 | 0.03 | — | 0.01 | Sep 7, 2012 | Multiple untrusted search path vulnerabilities in Autodesk AutoCAD 2010 allow local users to gain privileges via a Trojan horse (1) dwmapi.dll or (2) IBFS32.DLL file in the current working directory, as demonstrated by a directory that contains a .dwg file. NOTE: the provenance… | |||
| CVE-2009-3578 | 0.03 | — | 0.04 | Nov 24, 2009 | Autodesk Maya 8.0, 8.5, 2008, 2009, and 2010 and Alias Wavefront Maya 6.5 and 7.0 allow remote attackers to execute arbitrary code via a (1) .ma or (2) .mb file that uses the Maya Embedded Language (MEL) python command or unspecified other MEL commands, related to "Script Nodes." | |||
| CVE-2009-3577 | 0.03 | — | 0.05 | Nov 24, 2009 | Autodesk 3D Studio Max (3DSMax) 6 through 9 and 2008 through 2010 allows remote attackers to execute arbitrary code via a .max file with a MAXScript statement that calls the DOSCommand method, related to "application callbacks." | |||
| CVE-2009-3576 | 0.03 | — | 0.03 | Nov 24, 2009 | Autodesk Softimage 7.x and Softimage XSI 6.x allow remote attackers to execute arbitrary JavaScript code via a scene package containing a Scene Table of Contents (aka .scntoc) file with a Script_Content element, as demonstrated by code that loads the WScript.Shell ActiveX… | |||
| CVE-2015-8572 | 0.00 | — | 0.04 | Dec 15, 2015 | Multiple buffer overflows in Autodesk Design Review (ADR) before 2013 Hotfix 2 allow remote attackers to execute arbitrary code via crafted RLE data in a (1) BMP or (2) FLI file, (3) encoded scan lines in a PCX file, or (4) DataSubBlock or (5) GlobalColorTable in a GIF file. | |||
| CVE-2015-8571 | 0.00 | — | 0.03 | Dec 15, 2015 | Integer overflow in Autodesk Design Review (ADR) before 2013 Hotfix 2 allows remote attackers to execute arbitrary code via a crafted biClrUsed value in a BMP file, which triggers a buffer overflow. | |||
| CVE-2014-9268 | 0.00 | — | 0.05 | Dec 8, 2014 | The AdView.AdViewer.1 ActiveX control in Autodesk Design Review (ADR) before 2013 Hotfix 1 allows remote attackers to execute arbitrary code via a crafted DWF file. | |||
| CVE-2014-3939 | 0.00 | — | 0.06 | Jul 23, 2014 | Heap-based buffer overflow in Autodesk SketchBook Pro before 6.2.6 allows remote attackers to execute arbitrary code via crafted layer bitmap data in a PXD file. | |||
| CVE-2014-3938 | 0.00 | — | 0.04 | Jul 23, 2014 | Integer overflow in Autodesk SketchBook Pro before 6.2.6 allows remote attackers to execute arbitrary code via crafted layer mask data in a PSD file, which triggers a heap-based buffer overflow. | |||
| CVE-2014-2967 | 0.00 | — | 0.05 | Jul 7, 2014 | Autodesk VRED Professional 2014 before SR1 SP8 allows remote attackers to execute arbitrary code via Python os library calls in Python API commands to the integrated web server. | |||
| CVE-2013-5365 | 0.00 | — | 0.05 | Apr 2, 2014 | Heap-based buffer overflow in Autodesk SketchBook for Enterprise 2014, Pro, and Express before 6.25, and Copic Edition before 2.0.2 allows remote attackers to execute arbitrary code via RLE-compressed channel data in a PSD file. | |||
| CVE-2014-0819 | 0.00 | — | 0.00 | Feb 22, 2014 | Untrusted search path vulnerability in Autodesk AutoCAD before 2014 allows local users to gain privileges via a Trojan horse DLL in the current working directory. | |||
| CVE-2014-0818 | 0.00 | — | 0.02 | Feb 22, 2014 | Untrusted search path vulnerability in Autodesk AutoCAD before 2014 allows local users to gain privileges and execute arbitrary VBScript code via a Trojan horse FAS file in the FAS file search path. | |||
| CVE-2013-3665 | 0.00 | — | 0.03 | Jul 18, 2013 | Unspecified vulnerability in Autodesk AutoCAD through 2014, AutoCAD LT through 2014, and DWG TrueView through 2014 allows remote attackers to execute arbitrary code via a crafted DWG file. | |||
| CVE-2010-5226 | 0.00 | — | 0.00 | Sep 7, 2012 | Multiple untrusted search path vulnerabilities in Autodesk Design Review 2011 11.0.0.86 allow local users to gain privileges via a Trojan horse (1) dwmapi.dll, (2) whiptk_wt.7.12.601.dll, or (3) xaml_wt.7.6.0.dll file in the current working directory, as demonstrated by a… | |||
| CVE-2007-4749 | 0.00 | — | 0.02 | Sep 14, 2007 | The cmdjob utility in Autodesk Backburner 3.0.2 allows remote attackers to execute arbitrary commands on render servers by queueing jobs that contain these commands. NOTE: this is only a vulnerability in environments in which the administrator has not followed documentation… | |||
| CVE-2005-4710 | 0.00 | — | 0.01 | Dec 31, 2005 | Unspecified vulnerability in multiple Autodesk and AutoCAD products and product families from 2006 and earlier allows remote attackers to "gain inappropriate access to another local user's computer," aka ID DL5549329. |
- risk 0.36cvss 5.5epss 0.00
A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Read. A malicious actor can leverage this vulnerability to cause a crash or could lead to an arbitrary memory leak.
- risk 0.36cvss 5.5epss 0.01
The user may be tricked into opening a malicious FBX file which may exploit a Null Pointer Dereference vulnerability in FBX's Review version 1.5.0 and prior causing the application to crash leading to a denial of service.
- risk 0.36cvss 5.5epss 0.01
A NULL pointer dereference vulnerability in the Autodesk FBX-SDK versions 2019.0 and earlier may lead to denial of service of the application.
- risk 0.34cvss 5.3epss 0.00
A maliciously crafted PSD file, when linked or imported into Autodesk 3ds Max, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
- risk 0.34cvss 5.3epss 0.01
Autodesk users who no longer have an active license for an account can still access cases for that account.
- risk 0.29cvss 4.4epss 0.00
A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
- risk 0.28cvss 4.3epss 0.00
Autodesk Customer Support Portal allows cases created by users under an account to see cases created by other users on the same account.
- risk 0.22cvss 3.3epss 0.03
A maliciously crafted DWG file can be forced to read beyond allocated boundaries when parsing the DWG file. This vulnerability can be exploited to execute arbitrary code.
- CVE-2008-4472Oct 7, 2008risk 0.04cvss —epss 0.08
The UpdateEngine class in the LiveUpdate ActiveX control (LiveUpdate16.DLL 17.2.56), as used in Revit Architecture 2009 SP2 and Autodesk Design Review 2009, allows remote attackers to execute arbitrary programs via the second argument to the ApplyPatch method.
- CVE-2008-4471Oct 7, 2008risk 0.04cvss —epss 0.07
Directory traversal vulnerability in the CExpressViewerControl class in the DWF Viewer ActiveX control (AdView.dll 9.0.0.96), as used in Revit Architecture 2009 SP2 and Autodesk Design Review 2009, allows remote attackers to overwrite arbitrary files via "..\" sequences in the…
- CVE-2010-5241Sep 7, 2012risk 0.03cvss —epss 0.01
Multiple untrusted search path vulnerabilities in Autodesk AutoCAD 2010 allow local users to gain privileges via a Trojan horse (1) dwmapi.dll or (2) IBFS32.DLL file in the current working directory, as demonstrated by a directory that contains a .dwg file. NOTE: the provenance…
- CVE-2009-3578Nov 24, 2009risk 0.03cvss —epss 0.04
Autodesk Maya 8.0, 8.5, 2008, 2009, and 2010 and Alias Wavefront Maya 6.5 and 7.0 allow remote attackers to execute arbitrary code via a (1) .ma or (2) .mb file that uses the Maya Embedded Language (MEL) python command or unspecified other MEL commands, related to "Script Nodes."
- CVE-2009-3577Nov 24, 2009risk 0.03cvss —epss 0.05
Autodesk 3D Studio Max (3DSMax) 6 through 9 and 2008 through 2010 allows remote attackers to execute arbitrary code via a .max file with a MAXScript statement that calls the DOSCommand method, related to "application callbacks."
- CVE-2009-3576Nov 24, 2009risk 0.03cvss —epss 0.03
Autodesk Softimage 7.x and Softimage XSI 6.x allow remote attackers to execute arbitrary JavaScript code via a scene package containing a Scene Table of Contents (aka .scntoc) file with a Script_Content element, as demonstrated by code that loads the WScript.Shell ActiveX…
- CVE-2015-8572Dec 15, 2015risk 0.00cvss —epss 0.04
Multiple buffer overflows in Autodesk Design Review (ADR) before 2013 Hotfix 2 allow remote attackers to execute arbitrary code via crafted RLE data in a (1) BMP or (2) FLI file, (3) encoded scan lines in a PCX file, or (4) DataSubBlock or (5) GlobalColorTable in a GIF file.
- CVE-2015-8571Dec 15, 2015risk 0.00cvss —epss 0.03
Integer overflow in Autodesk Design Review (ADR) before 2013 Hotfix 2 allows remote attackers to execute arbitrary code via a crafted biClrUsed value in a BMP file, which triggers a buffer overflow.
- CVE-2014-9268Dec 8, 2014risk 0.00cvss —epss 0.05
The AdView.AdViewer.1 ActiveX control in Autodesk Design Review (ADR) before 2013 Hotfix 1 allows remote attackers to execute arbitrary code via a crafted DWF file.
- CVE-2014-3939Jul 23, 2014risk 0.00cvss —epss 0.06
Heap-based buffer overflow in Autodesk SketchBook Pro before 6.2.6 allows remote attackers to execute arbitrary code via crafted layer bitmap data in a PXD file.
- CVE-2014-3938Jul 23, 2014risk 0.00cvss —epss 0.04
Integer overflow in Autodesk SketchBook Pro before 6.2.6 allows remote attackers to execute arbitrary code via crafted layer mask data in a PSD file, which triggers a heap-based buffer overflow.
- CVE-2014-2967Jul 7, 2014risk 0.00cvss —epss 0.05
Autodesk VRED Professional 2014 before SR1 SP8 allows remote attackers to execute arbitrary code via Python os library calls in Python API commands to the integrated web server.
- CVE-2013-5365Apr 2, 2014risk 0.00cvss —epss 0.05
Heap-based buffer overflow in Autodesk SketchBook for Enterprise 2014, Pro, and Express before 6.25, and Copic Edition before 2.0.2 allows remote attackers to execute arbitrary code via RLE-compressed channel data in a PSD file.
- CVE-2014-0819Feb 22, 2014risk 0.00cvss —epss 0.00
Untrusted search path vulnerability in Autodesk AutoCAD before 2014 allows local users to gain privileges via a Trojan horse DLL in the current working directory.
- CVE-2014-0818Feb 22, 2014risk 0.00cvss —epss 0.02
Untrusted search path vulnerability in Autodesk AutoCAD before 2014 allows local users to gain privileges and execute arbitrary VBScript code via a Trojan horse FAS file in the FAS file search path.
- CVE-2013-3665Jul 18, 2013risk 0.00cvss —epss 0.03
Unspecified vulnerability in Autodesk AutoCAD through 2014, AutoCAD LT through 2014, and DWG TrueView through 2014 allows remote attackers to execute arbitrary code via a crafted DWG file.
- CVE-2010-5226Sep 7, 2012risk 0.00cvss —epss 0.00
Multiple untrusted search path vulnerabilities in Autodesk Design Review 2011 11.0.0.86 allow local users to gain privileges via a Trojan horse (1) dwmapi.dll, (2) whiptk_wt.7.12.601.dll, or (3) xaml_wt.7.6.0.dll file in the current working directory, as demonstrated by a…
- CVE-2007-4749Sep 14, 2007risk 0.00cvss —epss 0.02
The cmdjob utility in Autodesk Backburner 3.0.2 allows remote attackers to execute arbitrary commands on render servers by queueing jobs that contain these commands. NOTE: this is only a vulnerability in environments in which the administrator has not followed documentation…
- CVE-2005-4710Dec 31, 2005risk 0.00cvss —epss 0.01
Unspecified vulnerability in multiple Autodesk and AutoCAD products and product families from 2006 and earlier allows remote attackers to "gain inappropriate access to another local user's computer," aka ID DL5549329.
Page 8 of 8