Show filters
272 Total Results
Displaying 221-230 of 272
Sort by:
Attacker Value
Unknown

CVE-2021-27035

Disclosure Date: July 09, 2021 (last updated February 23, 2025)
A maliciously crafted TIFF, TIF, PICT, TGA, or DWF files in Autodesk Design Review 2018, 2017, 2013, 2012, 2011 can be forced to read beyond allocated boundaries when parsing the TIFF, PICT, TGA or DWF files. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.
Attacker Value
Unknown

CVE-2021-27043

Disclosure Date: June 25, 2021 (last updated February 22, 2025)
An Arbitrary Address Write issue in the Autodesk DWG application can allow a malicious user to leverage the application to write in unexpected paths. In order to exploit this the attacker would need the victim to enable full page heap in the application.
Attacker Value
Unknown

CVE-2021-27040

Disclosure Date: June 25, 2021 (last updated February 22, 2025)
A maliciously crafted DWG file can be forced to read beyond allocated boundaries when parsing the DWG file. This vulnerability can be exploited to execute arbitrary code.
Attacker Value
Unknown

CVE-2021-27042

Disclosure Date: June 25, 2021 (last updated February 22, 2025)
A maliciously crafted DWG file can be used to write beyond the allocated buffer while parsing DWG files. The vulnerability exists because the application fails to handle a crafted DWG file, which causes an unhandled exception. An attacker can leverage this vulnerability to execute arbitrary code.
Attacker Value
Unknown

CVE-2021-27041

Disclosure Date: June 25, 2021 (last updated February 22, 2025)
A maliciously crafted DWG file can be used to write beyond the allocated buffer while parsing DWG files. This vulnerability can be exploited to execute arbitrary code
Attacker Value
Unknown

CVE-2021-27032

Disclosure Date: May 28, 2021 (last updated February 22, 2025)
Autodesk Licensing Installer was found to be vulnerable to privilege escalation issues. A malicious user with limited privileges could run any number of tools on a system to identify services that are configured with weak permissions and are running under elevated privileges. These weak permissions could allow all users on the operating system to modify the service configuration and take ownership of the service.
Attacker Value
Unknown

CVE-2021-27031

Disclosure Date: April 19, 2021 (last updated February 22, 2025)
A user may be tricked into opening a malicious FBX file which may exploit a use-after-free vulnerability in FBX's Review causing the application to reference a memory location controlled by an unauthorized third party, thereby running arbitrary code on the system.
Attacker Value
Unknown

CVE-2021-27027

Disclosure Date: April 19, 2021 (last updated February 22, 2025)
An Out-Of-Bounds Read Vulnerability in Autodesk FBX Review version 1.5.0 and prior may lead to code execution through maliciously crafted DLL files or information disclosure.
Attacker Value
Unknown

CVE-2021-27029

Disclosure Date: April 19, 2021 (last updated February 22, 2025)
The user may be tricked into opening a malicious FBX file which may exploit a Null Pointer Dereference vulnerability in FBX's Review version 1.5.0 and prior causing the application to crash leading to a denial of service.
Attacker Value
Unknown

CVE-2021-27028

Disclosure Date: April 19, 2021 (last updated February 22, 2025)
A Memory Corruption Vulnerability in Autodesk FBX Review version 1.5.0 and prior may lead to remote code execution through maliciously crafted DLL files.