Autodesk kayıtları
autodesk üreticisine ait 381 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 29
- Düzeltme kaydı olan
- %5,8
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-787 Out-of-bounds Write129
- CWE-125 Out-of-bounds Read58
- CWE-416 Use After Free29
- CWE-122 Heap-based Buffer Overflow28
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer21
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')19
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWEBug bounty kapsamı
Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.
Tüm kayıtlar
381 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
49Planlayın | CVE-2021-27030İstismar yok | A user may be tricked into opening a malicious FBX file which may exploit a Directory Traversal Remote Code Execution vulnerability in FBX’sautodesk · fbx review · CWE-22 | Yüksek7,8 | — | %59,6 | 19 Nis 2021 |
42Planlayın | CVE-2014-2967İstismar yok | Autodesk VRED Professional 2014 before SR1 SP8 allows remote attackers to execute arbitrary code via Python os library calls in Python API cautodesk · vred · CWE-78 | Kritik10,0 | — | %5,1 | 7 Tem 2014 |
40Planlayın | CVE-2016-9303İstismar yok | Multiple buffer overflows in the Autodesk FBX-SDK before 2017.1 can allow attackers to execute arbitrary code or cause an infinite loop condautodesk · fbx software development kit · CWE-119 | Kritik9,8 | — | %4,1 | 25 Oca 2017 |
40Planlayın | CVE-2016-9307İstismar yok | Multiple buffer overflows in the Autodesk FBX-SDK before 2017.1 can allow attackers to execute arbitrary code when reading or converting malautodesk · fbx software development kit · CWE-119 | Kritik9,8 | — | %2,2 | 25 Oca 2017 |
40Planlayın | CVE-2016-9306İstismar yok | Multiple buffer overflows in the Autodesk FBX-SDK before 2017.1 can allow attackers to execute arbitrary code when reading or converting malautodesk · fbx software development kit · CWE-119 | Kritik9,8 | — | %2,2 | 25 Oca 2017 |
39İzleyin | CVE-2008-4472Kavram kanıtı | The UpdateEngine class in the LiveUpdate ActiveX control (LiveUpdate16.DLL 17.2.56), as used in Revit Architecture 2009 SP2 and Autodesk Desautodesk · design review · CWE-264 | Kritik9,3 | — | %7,8 | 7 Eki 2008 |
39İzleyin | CVE-2008-4471Kavram kanıtı | Directory traversal vulnerability in the CExpressViewerControl class in the DWF Viewer ActiveX control (AdView.dll 9.0.0.96), as used in Revautodesk · design review · CWE-22 | Kritik9,3 | — | %6,7 | 7 Eki 2008 |
39İzleyin | CVE-2014-3939İstismar yok | Heap-based buffer overflow in Autodesk SketchBook Pro before 6.2.6 allows remote attackers to execute arbitrary code via crafted layer bitmaautodesk · sketchbook pro · CWE-119 | Kritik9,3 | — | %6,0 | 23 Tem 2014 |
39İzleyin | CVE-2013-5365İstismar yok | Heap-based buffer overflow in Autodesk SketchBook for Enterprise 2014, Pro, and Express before 6.25, and Copic Edition before 2.0.2 allows rautodesk · sketchbook · CWE-119 | Kritik9,3 | — | %5,2 | 2 Nis 2014 |
39İzleyin | CVE-2009-3577Kavram kanıtı | Autodesk 3D Studio Max (3DSMax) 6 through 9 and 2008 through 2010 allows remote attackers to execute arbitrary code via a .max file with a Mautodesk · 3ds max · CWE-94 | Kritik9,3 | — | %5,1 | 24 Kas 2009 |
39İzleyin | CVE-2016-9305İstismar yok | Improper handling in the Autodesk FBX-SDK before 2017.1 of type mismatches and previously deleted objects related to reading and converting autodesk · fbx software development kit · CWE-19 | Kritik9,8 | — | %1,2 | 25 Oca 2017 |
39İzleyin | CVE-2023-29073İstismar yok | A maliciously crafted MODEL file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to cause a Heap-Based Buffer Overflow.autodesk · autocad · CWE-122 | Kritik9,8 | — | %1,1 | 22 Kas 2023 |
39İzleyin | CVE-2023-29075İstismar yok | A maliciously crafted PRT file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to cause an Out-Of-Bounds Write.autodesk · autocad · CWE-787 | Kritik9,8 | — | %1,1 | 23 Kas 2023 |
39İzleyin | CVE-2023-29074İstismar yok | A maliciously crafted CATPART file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to cause an Out-Of-Bounds Write.autodesk · autocad · CWE-787 | Kritik9,8 | — | %1,1 | 23 Kas 2023 |
39İzleyin | CVE-2023-29076İstismar yok | A maliciously crafted MODEL, SLDASM, SAT or CATPART file when parsed through Autodesk AutoCAD 2024 and 2023 could cause memory corruption vuautodesk · autocad · CWE-119 | Kritik9,8 | — | %1,1 | 23 Kas 2023 |
39İzleyin | CVE-2022-33882İstismar yok | Under certain conditions, an attacker could create an unintended sphere of control through a vulnerability present in file delete operation autodesk · autodesk desktop | Kritik9,8 | — | %0,9 | 3 Eki 2022 |
38İzleyin | CVE-2009-3578Kavram kanıtı | Autodesk Maya 8.0, 8.5, 2008, 2009, and 2010 and Alias Wavefront Maya 6.5 and 7.0 allow remote attackers to execute arbitrary code via a (1)autodesk · alias wavefront maya · CWE-94 | Kritik9,3 | — | %4,4 | 24 Kas 2009 |
38İzleyin | CVE-2014-3938İstismar yok | Integer overflow in Autodesk SketchBook Pro before 6.2.6 allows remote attackers to execute arbitrary code via crafted layer mask data in a autodesk · sketchbook pro · CWE-189 | Kritik9,3 | — | %4,3 | 23 Tem 2014 |
38İzleyin | CVE-2009-3576Kavram kanıtı | Autodesk Softimage 7.x and Softimage XSI 6.x allow remote attackers to execute arbitrary JavaScript code via a scene package containing a Scautodesk · autodesk softimage · CWE-94 | Kritik9,3 | — | %3,2 | 24 Kas 2009 |
38İzleyin | CVE-2026-10789İstismar yok | MCP Extension Code Injection Vulnerability in Autodesk Fusion Desktopautodesk · fusion · CWE-94 | Kritik9,6 | — | %0,7 | 22 Haz 2026 |
36İzleyin | CVE-2020-7082İstismar yok | A use-after-free vulnerability in the Autodesk FBX-SDK versions 2019.0 and earlier may lead to code execution on a system running it.autodesk · fbx software development kit · CWE-416 | Yüksek8,8 | — | %2,1 | 17 Nis 2020 |
36İzleyin | CVE-2016-9304İstismar yok | Multiple buffer overflows in the Autodesk FBX-SDK before 2017.1 can allow attackers to execute arbitrary code when reading or converting malautodesk · fbx software development kit · CWE-119 | Yüksek8,8 | — | %1,9 | 25 Oca 2017 |
35İzleyin | CVE-2020-7081İstismar yok | A type confusion vulnerability in the Autodesk FBX-SDK versions 2019.0 and earlier may lead to arbitary code read/write on the system runninautodesk · fbx software development kit · CWE-843 | Yüksek8,8 | — | %1,5 | 17 Nis 2020 |
35İzleyin | CVE-2022-27864İstismar yok | A Double Free vulnerability allows remote attackers to execute arbitrary code through DesignReview.exe application on PDF files within affecautodesk · design review · CWE-415 | Yüksek8,8 | — | %1,1 | 29 Tem 2022 |
34İzleyin | CVE-2025-10244İstismar yok | HTML Payload Stored Cross-Site Scripting (XSS) Vulnerabilityautodesk · fusion · CWE-79 | Yüksek8,7 | — | %0,4 | 23 Eyl 2025 |
- CVE-2021-2703049Planlayın
A user may be tricked into opening a malicious FBX file which may exploit a Directory Traversal Remote Code Execution vulnerability in FBX’s
YüksekCVSS 7,8İstismar yokEPSS %60autodesk · fbx review19 Nis 2021
- CVE-2014-296742Planlayın
Autodesk VRED Professional 2014 before SR1 SP8 allows remote attackers to execute arbitrary code via Python os library calls in Python API c
KritikCVSS 10,0İstismar yokEPSS %5autodesk · vred7 Tem 2014
- CVE-2016-930340Planlayın
Multiple buffer overflows in the Autodesk FBX-SDK before 2017.1 can allow attackers to execute arbitrary code or cause an infinite loop cond
KritikCVSS 9,8İstismar yokEPSS %4autodesk · fbx software development kit25 Oca 2017
- CVE-2016-930740Planlayın
Multiple buffer overflows in the Autodesk FBX-SDK before 2017.1 can allow attackers to execute arbitrary code when reading or converting mal
KritikCVSS 9,8İstismar yokEPSS %2autodesk · fbx software development kit25 Oca 2017
- CVE-2016-930640Planlayın
Multiple buffer overflows in the Autodesk FBX-SDK before 2017.1 can allow attackers to execute arbitrary code when reading or converting mal
KritikCVSS 9,8İstismar yokEPSS %2autodesk · fbx software development kit25 Oca 2017
- CVE-2008-447239İzleyin
The UpdateEngine class in the LiveUpdate ActiveX control (LiveUpdate16.DLL 17.2.56), as used in Revit Architecture 2009 SP2 and Autodesk Des
KritikCVSS 9,3Kavram kanıtıEPSS %8autodesk · design review7 Eki 2008
- CVE-2008-447139İzleyin
Directory traversal vulnerability in the CExpressViewerControl class in the DWF Viewer ActiveX control (AdView.dll 9.0.0.96), as used in Rev
KritikCVSS 9,3Kavram kanıtıEPSS %7autodesk · design review7 Eki 2008
- CVE-2014-393939İzleyin
Heap-based buffer overflow in Autodesk SketchBook Pro before 6.2.6 allows remote attackers to execute arbitrary code via crafted layer bitma
KritikCVSS 9,3İstismar yokEPSS %6autodesk · sketchbook pro23 Tem 2014
- CVE-2013-536539İzleyin
Heap-based buffer overflow in Autodesk SketchBook for Enterprise 2014, Pro, and Express before 6.25, and Copic Edition before 2.0.2 allows r
KritikCVSS 9,3İstismar yokEPSS %5autodesk · sketchbook2 Nis 2014
- CVE-2009-357739İzleyin
Autodesk 3D Studio Max (3DSMax) 6 through 9 and 2008 through 2010 allows remote attackers to execute arbitrary code via a .max file with a M
KritikCVSS 9,3Kavram kanıtıEPSS %5autodesk · 3ds max24 Kas 2009
- CVE-2016-930539İzleyin
Improper handling in the Autodesk FBX-SDK before 2017.1 of type mismatches and previously deleted objects related to reading and converting
KritikCVSS 9,8İstismar yokEPSS %1autodesk · fbx software development kit25 Oca 2017
- CVE-2023-2907339İzleyin
A maliciously crafted MODEL file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to cause a Heap-Based Buffer Overflow.
KritikCVSS 9,8İstismar yokEPSS %1autodesk · autocad22 Kas 2023
- CVE-2023-2907539İzleyin
A maliciously crafted PRT file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to cause an Out-Of-Bounds Write.
KritikCVSS 9,8İstismar yokEPSS %1autodesk · autocad23 Kas 2023
- CVE-2023-2907439İzleyin
A maliciously crafted CATPART file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to cause an Out-Of-Bounds Write.
KritikCVSS 9,8İstismar yokEPSS %1autodesk · autocad23 Kas 2023
- CVE-2023-2907639İzleyin
A maliciously crafted MODEL, SLDASM, SAT or CATPART file when parsed through Autodesk AutoCAD 2024 and 2023 could cause memory corruption vu
KritikCVSS 9,8İstismar yokEPSS %1autodesk · autocad23 Kas 2023
- CVE-2022-3388239İzleyin
Under certain conditions, an attacker could create an unintended sphere of control through a vulnerability present in file delete operation
KritikCVSS 9,8İstismar yokEPSS %1autodesk · autodesk desktop3 Eki 2022
- CVE-2009-357838İzleyin
Autodesk Maya 8.0, 8.5, 2008, 2009, and 2010 and Alias Wavefront Maya 6.5 and 7.0 allow remote attackers to execute arbitrary code via a (1)
KritikCVSS 9,3Kavram kanıtıEPSS %4autodesk · alias wavefront maya24 Kas 2009
- CVE-2014-393838İzleyin
Integer overflow in Autodesk SketchBook Pro before 6.2.6 allows remote attackers to execute arbitrary code via crafted layer mask data in a
KritikCVSS 9,3İstismar yokEPSS %4autodesk · sketchbook pro23 Tem 2014
- CVE-2009-357638İzleyin
Autodesk Softimage 7.x and Softimage XSI 6.x allow remote attackers to execute arbitrary JavaScript code via a scene package containing a Sc
KritikCVSS 9,3Kavram kanıtıEPSS %3autodesk · autodesk softimage24 Kas 2009
- CVE-2026-1078938İzleyin
MCP Extension Code Injection Vulnerability in Autodesk Fusion Desktop
KritikCVSS 9,6İstismar yokEPSS %1autodesk · fusion22 Haz 2026
- CVE-2020-708236İzleyin
A use-after-free vulnerability in the Autodesk FBX-SDK versions 2019.0 and earlier may lead to code execution on a system running it.
YüksekCVSS 8,8İstismar yokEPSS %2autodesk · fbx software development kit17 Nis 2020
- CVE-2016-930436İzleyin
Multiple buffer overflows in the Autodesk FBX-SDK before 2017.1 can allow attackers to execute arbitrary code when reading or converting mal
YüksekCVSS 8,8İstismar yokEPSS %2autodesk · fbx software development kit25 Oca 2017
- CVE-2020-708135İzleyin
A type confusion vulnerability in the Autodesk FBX-SDK versions 2019.0 and earlier may lead to arbitary code read/write on the system runnin
YüksekCVSS 8,8İstismar yokEPSS %1autodesk · fbx software development kit17 Nis 2020
- CVE-2022-2786435İzleyin
A Double Free vulnerability allows remote attackers to execute arbitrary code through DesignReview.exe application on PDF files within affec
YüksekCVSS 8,8İstismar yokEPSS %1autodesk · design review29 Tem 2022
- CVE-2025-1024434İzleyin
HTML Payload Stored Cross-Site Scripting (XSS) Vulnerability
YüksekCVSS 8,7İstismar yokEPSS %0autodesk · fusion23 Eyl 2025