MidnightBSD

Advisories for autodesk

CVE-2005-4710 MEDIUM

Unspecified vulnerability in multiple Autodesk and AutoCAD products and product families from 2006 and earlier allows remote attackers to "gain inappropriate access to another local user's computer," aka ID DL5549329.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
autodesk utility_design 2005
autodesk revit_structure 8.1
autodesk inventor 10
autodesk autocad_mechanical 2005
autodesk building_systems 2006
autodesk autocad 2006
autodesk map_3d 2006
autodesk viz 2006
autodesk autocad_lt 2005
autodesk autocad_civil_3d 2005
autodesk civil_design 2005
autodesk revit_structure 6
autodesk autocad 2005
autodesk autocad_lt 2006
autodesk revit 8
autodesk building_systems 2005
autodesk raster_design 2005
autodesk survey 2005
autodesk inventor 9
autodesk architectural_desktop 2005
autodesk autocad_electrical 2005
autodesk 3ds_max 7
autodesk survey 2006
autodesk map_3d 2005
autodesk raster_design 2006
autodesk autocad_mechanical 2006
autodesk land_desktop 2006
autodesk architectural_desktop 2006
autodesk revit 7
autodesk land_desktop 2005
autodesk autocad_civil_3d 2006
autodesk autocad_electrical 2006
CVE-2007-4749 MEDIUM

The cmdjob utility in Autodesk Backburner 3.0.2 allows remote attackers to execute arbitrary commands on render servers by queueing jobs that contain these commands. NOTE: this is only a vulnerability in environments in which the administrator has not followed documentation that outlines the security risks of operating Backburner on untrusted networks.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-16,

Products Affected

Vendor Product Version
autodesk backburner 3.0.2
CVE-2008-4471 HIGH

Directory traversal vulnerability in the CExpressViewerControl class in the DWF Viewer ActiveX control (AdView.dll 9.0.0.96), as used in Revit Architecture 2009 SP2 and Autodesk Design Review 2009, allows remote attackers to overwrite arbitrary files via "..\" sequences in the argument to the SaveAS method.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-22,

Products Affected

Vendor Product Version
autodesk dwf_viewer *
autodesk design_review 2009
autodesk revit_architecture 2009
CVE-2008-4472 HIGH

The UpdateEngine class in the LiveUpdate ActiveX control (LiveUpdate16.DLL 17.2.56), as used in Revit Architecture 2009 SP2 and Autodesk Design Review 2009, allows remote attackers to execute arbitrary programs via the second argument to the ApplyPatch method.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-264,

Products Affected

Vendor Product Version
autodesk dwf_viewer *
autodesk design_review 2009
autodesk revit_architecture 2009
CVE-2009-3576 HIGH

Autodesk Softimage 7.x and Softimage XSI 6.x allow remote attackers to execute arbitrary JavaScript code via a scene package containing a Scene Table of Contents (aka .scntoc) file with a Script_Content element, as demonstrated by code that loads the WScript.Shell ActiveX control.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-94,

Products Affected

Vendor Product Version
autodesk autodesk_softimage_xsi 6.0
autodesk autodesk_softimage 7.0
CVE-2009-3577 HIGH

Autodesk 3D Studio Max (3DSMax) 6 through 9 and 2008 through 2010 allows remote attackers to execute arbitrary code via a .max file with a MAXScript statement that calls the DOSCommand method, related to "application callbacks."

CVSS 2.0

Severity: HIGH

Problem Type: CWE-94,

Products Affected

Vendor Product Version
autodesk 3ds_max 7
autodesk 3ds_max 2010
autodesk 3ds_max 2008
autodesk 3ds_max 2009
autodesk 3ds_max 8
autodesk 3ds_max 6
autodesk 3ds_max 9
CVE-2009-3578 HIGH

Autodesk Maya 8.0, 8.5, 2008, 2009, and 2010 and Alias Wavefront Maya 6.5 and 7.0 allow remote attackers to execute arbitrary code via a (1) .ma or (2) .mb file that uses the Maya Embedded Language (MEL) python command or unspecified other MEL commands, related to "Script Nodes."

CVSS 2.0

Severity: HIGH

Problem Type: CWE-94,

Products Affected

Vendor Product Version
autodesk autodesk_maya 8.5
autodesk alias_wavefront_maya 7.0
autodesk alias_wavefront_maya 6.5
autodesk autodesk_maya 8.0
CVE-2010-5226 MEDIUM

Multiple untrusted search path vulnerabilities in Autodesk Design Review 2011 11.0.0.86 allow local users to gain privileges via a Trojan horse (1) dwmapi.dll, (2) whiptk_wt.7.12.601.dll, or (3) xaml_wt.7.6.0.dll file in the current working directory, as demonstrated by a directory that contains a .dwf file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
autodesk design_review_2011 11.0.0.86
CVE-2010-5241 MEDIUM

Multiple untrusted search path vulnerabilities in Autodesk AutoCAD 2010 allow local users to gain privileges via a Trojan horse (1) dwmapi.dll or (2) IBFS32.DLL file in the current working directory, as demonstrated by a directory that contains a .dwg file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
autodesk autocad 2010
CVE-2013-3665 MEDIUM

Unspecified vulnerability in Autodesk AutoCAD through 2014, AutoCAD LT through 2014, and DWG TrueView through 2014 allows remote attackers to execute arbitrary code via a crafted DWG file.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
autodesk autocad_map_3d 2013
autodesk autocad_plant_3d 2012
autodesk autocad_electrical 2014
autodesk autocad_electrical 2012
autodesk dwg_trueview 2013
autodesk autocad_civil_3d 2011
autodesk autocad_electrical 2011
autodesk dwg_trueview 2012
autodesk autocad 2011
autodesk autocad 2012
autodesk autocad_architecture 2011
autodesk dwg_trueview 2011
autodesk autocad_lt 2014
autodesk autocad_plant_3d 2013
autodesk autocad_ecscad 2014
autodesk autocad_mechanical 2011
autodesk autocad_civil_3d 2013
autodesk autocad_mep 2013
autodesk autocad_civil_3d 2012
autodesk autocad_lt 2011
autodesk autocad_map_3d 2011
autodesk autocad_ecscad 2012
autodesk autocad_ecscad 2011
autodesk dwg_trueview 2014
autodesk autocad_structural_detailing 2014
autodesk autocad_utility_design 2012
autodesk autocad_map_3d 2014
autodesk autocad_architecture 2012
autodesk autocad_architecture 2014
autodesk autocad_p&id 2013
autodesk autocad_electrical 2013
autodesk autocad_mechanical 2012
autodesk autocad_utility_design 2014
autodesk autocad_plant_3d 2011
autodesk autocad 2014
autodesk autocad_mep 2012
autodesk autocad_p&id 2014
autodesk autocad_utility_design 2013
autodesk autocad_plant_3d 2014
autodesk autocad 2013
autodesk autocad_mechanical 2013
autodesk autocad_architecture 2013
autodesk autocad_lt 2012
autodesk autocad_p&id 2011
autodesk autocad_lt 2013
autodesk autocad_mep 2014
autodesk autocad_structural_detailing 2013
autodesk autocad_utility_design 2011
autodesk autocad_map_3d 2012
autodesk autocad_mep 2011
autodesk autocad_p&id 2012
autodesk autocad_mechanical 2014
autodesk autocad_structural_detailing 2011
autodesk autocad_ecscad 2013
autodesk autocad_structural_detailing 2012
autodesk autocad_civil_3d 2014
CVE-2013-5365 HIGH

Heap-based buffer overflow in Autodesk SketchBook for Enterprise 2014, Pro, and Express before 6.25, and Copic Edition before 2.0.2 allows remote attackers to execute arbitrary code via RLE-compressed channel data in a PSD file.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
autodesk sketchbook_for_enterprise_2014 *
autodesk sketchbook *
autodesk sketchbook_pro *
autodesk sketchbook_express *
CVE-2014-0818 HIGH

Untrusted search path vulnerability in Autodesk AutoCAD before 2014 allows local users to gain privileges and execute arbitrary VBScript code via a Trojan horse FAS file in the FAS file search path.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-94,

Products Affected

Vendor Product Version
autodesk autocad *
CVE-2014-0819 MEDIUM

Untrusted search path vulnerability in Autodesk AutoCAD before 2014 allows local users to gain privileges via a Trojan horse DLL in the current working directory.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
autodesk autocad *
CVE-2014-2967 HIGH

Autodesk VRED Professional 2014 before SR1 SP8 allows remote attackers to execute arbitrary code via Python os library calls in Python API commands to the integrated web server.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-78,

Products Affected

Vendor Product Version
autodesk vred 2014
CVE-2014-3938 HIGH

Integer overflow in Autodesk SketchBook Pro before 6.2.6 allows remote attackers to execute arbitrary code via crafted layer mask data in a PSD file, which triggers a heap-based buffer overflow.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-189,

Products Affected

Vendor Product Version
autodesk sketchbook_pro *
autodesk sketchbook_pro 6.2.4
CVE-2014-3939 HIGH

Heap-based buffer overflow in Autodesk SketchBook Pro before 6.2.6 allows remote attackers to execute arbitrary code via crafted layer bitmap data in a PXD file.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
autodesk sketchbook_pro *
autodesk sketchbook_pro 6.2.4
CVE-2014-9268 MEDIUM

The AdView.AdViewer.1 ActiveX control in Autodesk Design Review (ADR) before 2013 Hotfix 1 allows remote attackers to execute arbitrary code via a crafted DWF file.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-20,

Products Affected

Vendor Product Version
autodesk design_review *
CVE-2015-8571 MEDIUM

Integer overflow in Autodesk Design Review (ADR) before 2013 Hotfix 2 allows remote attackers to execute arbitrary code via a crafted biClrUsed value in a BMP file, which triggers a buffer overflow.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-189,

Products Affected

Vendor Product Version
autodesk design_review 2013
CVE-2015-8572 MEDIUM

Multiple buffer overflows in Autodesk Design Review (ADR) before 2013 Hotfix 2 allow remote attackers to execute arbitrary code via crafted RLE data in a (1) BMP or (2) FLI file, (3) encoded scan lines in a PCX file, or (4) DataSubBlock or (5) GlobalColorTable in a GIF file.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
autodesk design_review 2013
CVE-2016-2344 HIGH

Stack-based buffer overflow in manager.exe in Backburner Manager in Autodesk Backburner 2016 2016.0.0.2150 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a crafted command. NOTE: this is only a vulnerability in environments in which the administrator has not followed documentation that outlines the security risks of operating Backburner on untrusted networks.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
autodesk autodesk_backburner *
CVE-2016-9303 HIGH

Multiple buffer overflows in the Autodesk FBX-SDK before 2017.1 can allow attackers to execute arbitrary code or cause an infinite loop condition when reading or converting malformed FBX format files.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
autodesk fbx_software_development_kit *
CVE-2016-9304 MEDIUM

Multiple buffer overflows in the Autodesk FBX-SDK before 2017.1 can allow attackers to execute arbitrary code when reading or converting malformed DFX format files.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-119,

Products Affected

Vendor Product Version
autodesk fbx_software_development_kit *
CVE-2016-9305 HIGH

Improper handling in the Autodesk FBX-SDK before 2017.1 of type mismatches and previously deleted objects related to reading and converting malformed FBX format files can allow attackers to gain access to uninitialized pointers.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-19,

Products Affected

Vendor Product Version
autodesk fbx_software_development_kit *
CVE-2016-9306 HIGH

Multiple buffer overflows in the Autodesk FBX-SDK before 2017.1 can allow attackers to execute arbitrary code when reading or converting malformed DAE format files.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
autodesk fbx_software_development_kit *
CVE-2016-9307 HIGH

Multiple buffer overflows in the Autodesk FBX-SDK before 2017.1 can allow attackers to execute arbitrary code when reading or converting malformed 3DS format files.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
autodesk fbx_software_development_kit *