Vulnerability index

Browse CVEs

362 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Autocad HIGH 7.8
CVE-2024-23137

A maliciously crafted STP or SLDPRT file, when parsed in ODXSW_DLL.dll through Autodesk applications, can be used to uninitialized variables. This vu…

Fix: 2021.1.4 / 2022.1.4+
Fix from $1,950 2024-02-22
Autocad HIGH 7.8
CVE-2024-23128

A maliciously crafted MODEL file, when parsed in libodxdll.dll and ASMDATAX229A.dll through Autodesk applications, can lead to a memory corruption vu…

Fix: 2021.1.4 / 2022.1.4+
Fix from $1,950 2024-02-22
Autocad HIGH 7.8
CVE-2024-23129

A maliciously crafted MODEL 3DM, STP, or SLDASM file, when in opennurbs.dll parsed through Autodesk applications, can lead to a memory corruption vul…

Fix: 2021.1.4 / 2022.1.4+
Fix from $1,950 2024-02-22
Autocad HIGH 7.8
CVE-2024-23130

A maliciously crafted SLDASM or SLDPRT file, when parsed in ODXSW_DLL.dll through Autodesk applications, can lead to a memory corruption vulnerabilit…

Fix: 2021.1.4 / 2022.1.4+
Fix from $1,950 2024-02-22
Autocad Electrical HIGH 7.8
CVE-2024-23131

A maliciously crafted STP file, when parsed in ASMIMPORT229A.dll, ASMKERN228A.dll, ASMkern229A.dll or ASMDATAX228A.dll through Autodesk applications,…

Fix: 2021.1.4 / 2022.1.4+
Fix from $1,950 2024-02-22
Autocad HIGH 7.8
CVE-2024-23132

A maliciously crafted STP file in atf_dwg_consumer.dll when parsed through Autodesk applications can lead to a memory corruption vulnerability by wri…

Fix: 2021.1.4 / 2022.1.4+
Fix from $1,950 2024-02-22
Autocad HIGH 7.8
CVE-2024-23133

A maliciously crafted STP file in ASMDATAX228A.dll when parsed through Autodesk applications can lead to a memory corruption vulnerability by write a…

Fix: 2021.1.4 / 2022.1.4+
Fix from $1,950 2024-02-22
Autocad HIGH 7.8
CVE-2024-23124

A maliciously crafted STP file, when parsed in ASMIMPORT228A.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A maliciou…

Fix: 2021.1.4 / 2022.1.4+
Fix from $1,950 2024-02-22
Autocad Electrical HIGH 7.8
CVE-2024-23125

A maliciously crafted SLDPRT file when parsed ODXSW_DLL.dll through Autodesk applications can be used to cause a Stack-based Overflow. A malicious ac…

Fix: 2021.1.4 / 2022.1.4+
Fix from $1,950 2024-02-22
Autocad HIGH 7.8
CVE-2024-23126

A maliciously crafted CATPART file when parsed CC5Dll.dll through Autodesk applications can be used to cause a Stack-based Overflow. A malicious acto…

Fix: 2021.1.4 / 2022.1.4+
Fix from $1,950 2024-02-22
Autocad HIGH 7.8
CVE-2024-23127

A maliciously crafted MODEL, SLDPRT, or SLDASM file, when parsed in ODXSW_DLL.dll and libodxdll.dll through Autodesk applications, can be used to cau…

Fix: 2021.1.4 / 2022.1.4+
Fix from $1,950 2024-02-22
Autocad Electrical HIGH 7.8
CVE-2024-23121

A maliciously crafted MODEL file, when parsed in libodxdll.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious …

Fix: 2021.1.4 / 2022.1.4+
Fix from $1,950 2024-02-22
Autocad Electrical HIGH 7.8
CVE-2024-23122

A maliciously crafted 3DM file, when parsed in opennurbs.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious ac…

Fix: 2021.1.4 / 2022.1.4+
Fix from $1,950 2024-02-22
Autocad HIGH 7.8
CVE-2024-23123

A maliciously crafted CATPART file, when parsed in CC5Dll.dll and ASMBASE228A.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerab…

Fix: 2021.1.4 / 2022.1.4+
Fix from $1,950 2024-02-22
Autocad HIGH 7.8
CVE-2024-23120

A maliciously crafted STP and STEP file, when parsed in ASMIMPORT228A.dll and ASMIMPORT229A.dll through Autodesk AutoCAD, may force an Out-of-Bounds …

Fix: 2021.1.4 / 2022.1.4+
Fix from $1,950 2024-02-22
Autocad HIGH 7.8
CVE-2024-0446

A maliciously crafted STP, CATPART or MODEL file, when parsed in ASMKERN228A.dll and ASMdatax229A.dll through Autodesk AutoCAD, may force an Out-of-B…

Fix: 2021.1.4 / 2022.1.4+
Fix from $1,950 2024-02-22
Autocad CRITICAL 9.8
CVE-2023-29074

A maliciously crafted CATPART file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to cause an Out-Of-Bounds Write. A malicious actor …

Fix: 2023.1.4 / 2024.1+
Fix from $2,300 2023-11-23
Autocad CRITICAL 9.8
CVE-2023-29075

A maliciously crafted PRT file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to cause an Out-Of-Bounds Write. A malicious actor can …

Fix: 2023.1.4 / 2024.1+
Fix from $2,300 2023-11-23
Autocad CRITICAL 9.8
CVE-2023-29076

A maliciously crafted MODEL, SLDASM, SAT or CATPART file when parsed through Autodesk AutoCAD 2024 and 2023 could cause memory corruption vulnerabili…

Fix: 2023.1.4 / 2024.1+
Fix from $2,300 2023-11-23
Autocad HIGH 7.8
CVE-2023-41139

A maliciously crafted STP file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to dereference an untrusted pointer. This vulnerability…

Fix: 2023.1.4 / 2024.1+
Fix from $1,950 2023-11-23
Autocad HIGH 7.8
CVE-2023-41140

A maliciously crafted PRT file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to cause a Heap-Based Buffer Overflow. A malicious acto…

Fix: 2023.1.4 / 2024.1+
Fix from $1,950 2023-11-23
Autocad CRITICAL 9.8
CVE-2023-29073

A maliciously crafted MODEL file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to cause a Heap-Based Buffer Overflow. A malicious ac…

Fix: 2023.1.4 / 2024.1+
Fix from $2,300 2023-11-23
Desktop Connector HIGH 7.8
CVE-2023-29069

A maliciously crafted DLL file can be forced to install onto a non-default location, and attacker can overwrite parts of the product with malicious D…

Fix: after 16.2.1.2016
Fix from $1,950 2023-11-22
Customer Portal MEDIUM 5.3
CVE-2023-41145

Autodesk users who no longer have an active license for an account can still access cases for that account.

Mitigation only
Fix from $1,600 2023-11-22
Navisworks HIGH 7.8
CVE-2023-25001

A maliciously crafted SKP file in Autodesk Navisworks 2023 and 2022 be used to trigger use-after-free vulnerability. Exploitation of this vulnerabili…

Mitigation only
Fix from $1,950 2023-06-27
3ds Max HIGH 7.8
CVE-2023-25002

A maliciously crafted SKP file in Autodesk products is used to trigger use-after-free vulnerability. Exploitation of this vulnerability may lead to c…

Mitigation only
Fix from $1,950 2023-06-27
Alias HIGH 7.8
CVE-2023-25004

A maliciously crafted pskernel.dll file in Autodesk products is used to trigger integer overflow vulnerabilities. Exploitation of these vulnerabiliti…

Fix: 2020.1.6 / 2021.1.3+
Fix from $1,950 2023-06-27
Alias HIGH 7.8
CVE-2023-29068

A maliciously crafted file consumed through pskernel.dll file could lead to memory corruption vulnerabilities. These vulnerabilities in conjunction w…

Fix: 2020.1.6 / 2021.1.3+
Fix from $1,950 2023-06-27
Installer HIGH 7.8
CVE-2023-27908

A maliciously crafted DLL file can be forced to write beyond allocated boundaries in the Autodesk installer when parsing the DLL files and could lead…

Fix: 1.39.0.216+
Fix from $1,950 2023-06-23
Alias HIGH 7.8
CVE-2023-25003

A maliciously crafted pskernel.dll file in Autodesk AutoCAD 2023 and Maya 2022 may be used to trigger out-of-bound read write / read vulnerabilities.…

Fix: 2020.1.6 / 2021.1.3+
Fix from $1,950 2023-06-23