Show filters
21 Total Results
Displaying 1-10 of 21
Sort by:
Attacker Value
Unknown

CVE-2024-37006

Disclosure Date: June 25, 2024 (last updated June 25, 2024)
A maliciously crafted CATPRODUCT file, when parsed in CC5Dll.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, in conjunction with other vulnerabilities, can lead to code execution in the context of the current process.
0
Attacker Value
Unknown

CVE-2024-37004

Disclosure Date: June 25, 2024 (last updated June 25, 2024)
A maliciously crafted SLDPRT file, when parsed in ASMKERN229A.dll through Autodesk applications, can cause a use-after-free vulnerability. This vulnerability, along with other vulnerabilities, could lead to code execution in the current process.
0
Attacker Value
Unknown

CVE-2024-37003

Disclosure Date: June 25, 2024 (last updated June 25, 2024)
A maliciously crafted DWG and SLDPRT file, when parsed in opennurbs.dll and ODXSW_DLL.dll through Autodesk applications, can be used to cause a Stack-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
0
Attacker Value
Unknown

CVE-2024-23159

Disclosure Date: June 25, 2024 (last updated June 25, 2024)
A maliciously crafted STP file, when parsed in stp_aim_x64_vc15d.dll through Autodesk applications, can be used to uninitialized variables. This vulnerability, along with other vulnerabilities, can lead to code execution in the current process.
0
Attacker Value
Unknown

CVE-2024-23158

Disclosure Date: June 25, 2024 (last updated June 25, 2024)
A maliciously crafted IGES file, when parsed in ASMImport229A.dll through Autodesk applications, can be used to cause a use-after-free vulnerability. A malicious actor can leverage this vulnerability to cause a crash or execute arbitrary code in the context of the current process.
0
Attacker Value
Unknown

CVE-2024-23157

Disclosure Date: June 25, 2024 (last updated June 25, 2024)
A maliciously crafted SLDASM or SLDPRT file, when parsed in ODXSW_DLL.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, along with other vulnerabilities, can lead to code execution in the current process.
0
Attacker Value
Unknown

CVE-2024-23156

Disclosure Date: June 25, 2024 (last updated June 25, 2024)
A maliciously crafted 3DM file, when parsed in opennurbs.dll and ASMkern229A.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, along with other vulnerabilities, can lead to code execution in the current process.
0
Attacker Value
Unknown

CVE-2024-23155

Disclosure Date: June 25, 2024 (last updated June 25, 2024)
A maliciously crafted MODEL file, when parsed in atf_asm_interface.dll through Autodesk applications, can be used to cause a Heap-based Buffer Overflow. A malicious actor can leverage this vulnerability to cause a crash or execute arbitrary code in the context of the current process.
0
Attacker Value
Unknown

CVE-2024-23154

Disclosure Date: June 25, 2024 (last updated June 25, 2024)
A maliciously crafted SLDPRT file, when parsed in ODXSW_DLL.dll through Autodesk applications, can be used to cause a Heap-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
0
Attacker Value
Unknown

CVE-2024-23153

Disclosure Date: June 25, 2024 (last updated June 25, 2024)
A maliciously crafted MODEL file, when parsed in libodx.dll through Autodesk applications, can force an Out-of-Bounds Read. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
0