Записи Autodesk
381 опубликованных записей вендора autodesk.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 29
- С записью об исправлении
- 5,8 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-787 Out-of-bounds Write129
- CWE-125 Out-of-bounds Read58
- CWE-416 Use After Free29
- CWE-122 Heap-based Buffer Overflow28
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer21
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')19
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEОхват bug bounty
Вендор продукта присутствует в публичной программе. Сопоставление по имени; проверьте текст scope в программе.
Все записи
381 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
49В плане | CVE-2021-27030Эксплойта нет | A user may be tricked into opening a malicious FBX file which may exploit a Directory Traversal Remote Code Execution vulnerability in FBX’sautodesk · fbx review · CWE-22 | Высокая7,8 | — | 59,6 % | 19 апр. 2021 г. |
42В плане | CVE-2014-2967Эксплойта нет | Autodesk VRED Professional 2014 before SR1 SP8 allows remote attackers to execute arbitrary code via Python os library calls in Python API cautodesk · vred · CWE-78 | Критическая10,0 | — | 5,1 % | 7 июл. 2014 г. |
40В плане | CVE-2016-9303Эксплойта нет | Multiple buffer overflows in the Autodesk FBX-SDK before 2017.1 can allow attackers to execute arbitrary code or cause an infinite loop condautodesk · fbx software development kit · CWE-119 | Критическая9,8 | — | 4,1 % | 25 янв. 2017 г. |
40В плане | CVE-2016-9307Эксплойта нет | Multiple buffer overflows in the Autodesk FBX-SDK before 2017.1 can allow attackers to execute arbitrary code when reading or converting malautodesk · fbx software development kit · CWE-119 | Критическая9,8 | — | 2,2 % | 25 янв. 2017 г. |
40В плане | CVE-2016-9306Эксплойта нет | Multiple buffer overflows in the Autodesk FBX-SDK before 2017.1 can allow attackers to execute arbitrary code when reading or converting malautodesk · fbx software development kit · CWE-119 | Критическая9,8 | — | 2,2 % | 25 янв. 2017 г. |
39Наблюдать | CVE-2008-4472Proof of concept | The UpdateEngine class in the LiveUpdate ActiveX control (LiveUpdate16.DLL 17.2.56), as used in Revit Architecture 2009 SP2 and Autodesk Desautodesk · design review · CWE-264 | Критическая9,3 | — | 7,8 % | 7 окт. 2008 г. |
39Наблюдать | CVE-2008-4471Proof of concept | Directory traversal vulnerability in the CExpressViewerControl class in the DWF Viewer ActiveX control (AdView.dll 9.0.0.96), as used in Revautodesk · design review · CWE-22 | Критическая9,3 | — | 6,7 % | 7 окт. 2008 г. |
39Наблюдать | CVE-2014-3939Эксплойта нет | Heap-based buffer overflow in Autodesk SketchBook Pro before 6.2.6 allows remote attackers to execute arbitrary code via crafted layer bitmaautodesk · sketchbook pro · CWE-119 | Критическая9,3 | — | 6,0 % | 23 июл. 2014 г. |
39Наблюдать | CVE-2013-5365Эксплойта нет | Heap-based buffer overflow in Autodesk SketchBook for Enterprise 2014, Pro, and Express before 6.25, and Copic Edition before 2.0.2 allows rautodesk · sketchbook · CWE-119 | Критическая9,3 | — | 5,2 % | 2 апр. 2014 г. |
39Наблюдать | CVE-2009-3577Proof of concept | Autodesk 3D Studio Max (3DSMax) 6 through 9 and 2008 through 2010 allows remote attackers to execute arbitrary code via a .max file with a Mautodesk · 3ds max · CWE-94 | Критическая9,3 | — | 5,1 % | 24 нояб. 2009 г. |
39Наблюдать | CVE-2016-9305Эксплойта нет | Improper handling in the Autodesk FBX-SDK before 2017.1 of type mismatches and previously deleted objects related to reading and converting autodesk · fbx software development kit · CWE-19 | Критическая9,8 | — | 1,2 % | 25 янв. 2017 г. |
39Наблюдать | CVE-2023-29073Эксплойта нет | A maliciously crafted MODEL file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to cause a Heap-Based Buffer Overflow.autodesk · autocad · CWE-122 | Критическая9,8 | — | 1,1 % | 22 нояб. 2023 г. |
39Наблюдать | CVE-2023-29075Эксплойта нет | A maliciously crafted PRT file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to cause an Out-Of-Bounds Write.autodesk · autocad · CWE-787 | Критическая9,8 | — | 1,1 % | 23 нояб. 2023 г. |
39Наблюдать | CVE-2023-29074Эксплойта нет | A maliciously crafted CATPART file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to cause an Out-Of-Bounds Write.autodesk · autocad · CWE-787 | Критическая9,8 | — | 1,1 % | 23 нояб. 2023 г. |
39Наблюдать | CVE-2023-29076Эксплойта нет | A maliciously crafted MODEL, SLDASM, SAT or CATPART file when parsed through Autodesk AutoCAD 2024 and 2023 could cause memory corruption vuautodesk · autocad · CWE-119 | Критическая9,8 | — | 1,1 % | 23 нояб. 2023 г. |
39Наблюдать | CVE-2022-33882Эксплойта нет | Under certain conditions, an attacker could create an unintended sphere of control through a vulnerability present in file delete operation autodesk · autodesk desktop | Критическая9,8 | — | 0,9 % | 3 окт. 2022 г. |
38Наблюдать | CVE-2009-3578Proof of concept | Autodesk Maya 8.0, 8.5, 2008, 2009, and 2010 and Alias Wavefront Maya 6.5 and 7.0 allow remote attackers to execute arbitrary code via a (1)autodesk · alias wavefront maya · CWE-94 | Критическая9,3 | — | 4,4 % | 24 нояб. 2009 г. |
38Наблюдать | CVE-2014-3938Эксплойта нет | Integer overflow in Autodesk SketchBook Pro before 6.2.6 allows remote attackers to execute arbitrary code via crafted layer mask data in a autodesk · sketchbook pro · CWE-189 | Критическая9,3 | — | 4,3 % | 23 июл. 2014 г. |
38Наблюдать | CVE-2009-3576Proof of concept | Autodesk Softimage 7.x and Softimage XSI 6.x allow remote attackers to execute arbitrary JavaScript code via a scene package containing a Scautodesk · autodesk softimage · CWE-94 | Критическая9,3 | — | 3,2 % | 24 нояб. 2009 г. |
38Наблюдать | CVE-2026-10789Эксплойта нет | MCP Extension Code Injection Vulnerability in Autodesk Fusion Desktopautodesk · fusion · CWE-94 | Критическая9,6 | — | 0,7 % | 22 июн. 2026 г. |
36Наблюдать | CVE-2020-7082Эксплойта нет | A use-after-free vulnerability in the Autodesk FBX-SDK versions 2019.0 and earlier may lead to code execution on a system running it.autodesk · fbx software development kit · CWE-416 | Высокая8,8 | — | 2,1 % | 17 апр. 2020 г. |
36Наблюдать | CVE-2016-9304Эксплойта нет | Multiple buffer overflows in the Autodesk FBX-SDK before 2017.1 can allow attackers to execute arbitrary code when reading or converting malautodesk · fbx software development kit · CWE-119 | Высокая8,8 | — | 1,9 % | 25 янв. 2017 г. |
35Наблюдать | CVE-2020-7081Эксплойта нет | A type confusion vulnerability in the Autodesk FBX-SDK versions 2019.0 and earlier may lead to arbitary code read/write on the system runninautodesk · fbx software development kit · CWE-843 | Высокая8,8 | — | 1,5 % | 17 апр. 2020 г. |
35Наблюдать | CVE-2022-27864Эксплойта нет | A Double Free vulnerability allows remote attackers to execute arbitrary code through DesignReview.exe application on PDF files within affecautodesk · design review · CWE-415 | Высокая8,8 | — | 1,1 % | 29 июл. 2022 г. |
34Наблюдать | CVE-2025-10244Эксплойта нет | HTML Payload Stored Cross-Site Scripting (XSS) Vulnerabilityautodesk · fusion · CWE-79 | Высокая8,7 | — | 0,4 % | 23 сент. 2025 г. |
- CVE-2021-2703049В плане
A user may be tricked into opening a malicious FBX file which may exploit a Directory Traversal Remote Code Execution vulnerability in FBX’s
ВысокаяCVSS 7,8Эксплойта нетEPSS 60 %autodesk · fbx review19 апр. 2021 г.
- CVE-2014-296742В плане
Autodesk VRED Professional 2014 before SR1 SP8 allows remote attackers to execute arbitrary code via Python os library calls in Python API c
КритическаяCVSS 10,0Эксплойта нетEPSS 5 %autodesk · vred7 июл. 2014 г.
- CVE-2016-930340В плане
Multiple buffer overflows in the Autodesk FBX-SDK before 2017.1 can allow attackers to execute arbitrary code or cause an infinite loop cond
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %autodesk · fbx software development kit25 янв. 2017 г.
- CVE-2016-930740В плане
Multiple buffer overflows in the Autodesk FBX-SDK before 2017.1 can allow attackers to execute arbitrary code when reading or converting mal
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %autodesk · fbx software development kit25 янв. 2017 г.
- CVE-2016-930640В плане
Multiple buffer overflows in the Autodesk FBX-SDK before 2017.1 can allow attackers to execute arbitrary code when reading or converting mal
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %autodesk · fbx software development kit25 янв. 2017 г.
- CVE-2008-447239Наблюдать
The UpdateEngine class in the LiveUpdate ActiveX control (LiveUpdate16.DLL 17.2.56), as used in Revit Architecture 2009 SP2 and Autodesk Des
КритическаяCVSS 9,3Proof of conceptEPSS 8 %autodesk · design review7 окт. 2008 г.
- CVE-2008-447139Наблюдать
Directory traversal vulnerability in the CExpressViewerControl class in the DWF Viewer ActiveX control (AdView.dll 9.0.0.96), as used in Rev
КритическаяCVSS 9,3Proof of conceptEPSS 7 %autodesk · design review7 окт. 2008 г.
- CVE-2014-393939Наблюдать
Heap-based buffer overflow in Autodesk SketchBook Pro before 6.2.6 allows remote attackers to execute arbitrary code via crafted layer bitma
КритическаяCVSS 9,3Эксплойта нетEPSS 6 %autodesk · sketchbook pro23 июл. 2014 г.
- CVE-2013-536539Наблюдать
Heap-based buffer overflow in Autodesk SketchBook for Enterprise 2014, Pro, and Express before 6.25, and Copic Edition before 2.0.2 allows r
КритическаяCVSS 9,3Эксплойта нетEPSS 5 %autodesk · sketchbook2 апр. 2014 г.
- CVE-2009-357739Наблюдать
Autodesk 3D Studio Max (3DSMax) 6 through 9 and 2008 through 2010 allows remote attackers to execute arbitrary code via a .max file with a M
КритическаяCVSS 9,3Proof of conceptEPSS 5 %autodesk · 3ds max24 нояб. 2009 г.
- CVE-2016-930539Наблюдать
Improper handling in the Autodesk FBX-SDK before 2017.1 of type mismatches and previously deleted objects related to reading and converting
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %autodesk · fbx software development kit25 янв. 2017 г.
- CVE-2023-2907339Наблюдать
A maliciously crafted MODEL file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to cause a Heap-Based Buffer Overflow.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %autodesk · autocad22 нояб. 2023 г.
- CVE-2023-2907539Наблюдать
A maliciously crafted PRT file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to cause an Out-Of-Bounds Write.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %autodesk · autocad23 нояб. 2023 г.
- CVE-2023-2907439Наблюдать
A maliciously crafted CATPART file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to cause an Out-Of-Bounds Write.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %autodesk · autocad23 нояб. 2023 г.
- CVE-2023-2907639Наблюдать
A maliciously crafted MODEL, SLDASM, SAT or CATPART file when parsed through Autodesk AutoCAD 2024 and 2023 could cause memory corruption vu
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %autodesk · autocad23 нояб. 2023 г.
- CVE-2022-3388239Наблюдать
Under certain conditions, an attacker could create an unintended sphere of control through a vulnerability present in file delete operation
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %autodesk · autodesk desktop3 окт. 2022 г.
- CVE-2009-357838Наблюдать
Autodesk Maya 8.0, 8.5, 2008, 2009, and 2010 and Alias Wavefront Maya 6.5 and 7.0 allow remote attackers to execute arbitrary code via a (1)
КритическаяCVSS 9,3Proof of conceptEPSS 4 %autodesk · alias wavefront maya24 нояб. 2009 г.
- CVE-2014-393838Наблюдать
Integer overflow in Autodesk SketchBook Pro before 6.2.6 allows remote attackers to execute arbitrary code via crafted layer mask data in a
КритическаяCVSS 9,3Эксплойта нетEPSS 4 %autodesk · sketchbook pro23 июл. 2014 г.
- CVE-2009-357638Наблюдать
Autodesk Softimage 7.x and Softimage XSI 6.x allow remote attackers to execute arbitrary JavaScript code via a scene package containing a Sc
КритическаяCVSS 9,3Proof of conceptEPSS 3 %autodesk · autodesk softimage24 нояб. 2009 г.
- CVE-2026-1078938Наблюдать
MCP Extension Code Injection Vulnerability in Autodesk Fusion Desktop
КритическаяCVSS 9,6Эксплойта нетEPSS 1 %autodesk · fusion22 июн. 2026 г.
- CVE-2020-708236Наблюдать
A use-after-free vulnerability in the Autodesk FBX-SDK versions 2019.0 and earlier may lead to code execution on a system running it.
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %autodesk · fbx software development kit17 апр. 2020 г.
- CVE-2016-930436Наблюдать
Multiple buffer overflows in the Autodesk FBX-SDK before 2017.1 can allow attackers to execute arbitrary code when reading or converting mal
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %autodesk · fbx software development kit25 янв. 2017 г.
- CVE-2020-708135Наблюдать
A type confusion vulnerability in the Autodesk FBX-SDK versions 2019.0 and earlier may lead to arbitary code read/write on the system runnin
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %autodesk · fbx software development kit17 апр. 2020 г.
- CVE-2022-2786435Наблюдать
A Double Free vulnerability allows remote attackers to execute arbitrary code through DesignReview.exe application on PDF files within affec
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %autodesk · design review29 июл. 2022 г.
- CVE-2025-1024434Наблюдать
HTML Payload Stored Cross-Site Scripting (XSS) Vulnerability
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %autodesk · fusion23 сент. 2025 г.