U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Search Results (Refine Search)

Search Parameters:
  • Results Type: Overview
  • Keyword (text search): autocad
  • Search Type: Search All
  • CPE Name Search: false
There are 67 matching records.
Displaying matches 1 through 20.
Vuln ID Summary CVSS Severity
CVE-2024-23137

A maliciously crafted STP or SLDPRT file in ODXSW_DLL.dll when parsed through Autodesk AutoCAD can be used to uninitialized variable. This vulnerability, along with other vulnerabilities, could lead to code execution in the current process.

Published: February 22, 2024; 12:15:09 AM -0500
V3.x:(not available)
V2.0:(not available)
CVE-2024-23136

A maliciously crafted STP file in ASMKERN228A.dll when parsed through Autodesk AutoCAD can be used to dereference an untrusted pointer. This vulnerability, along with other vulnerabilities, could lead to code execution in the current process.

Published: February 22, 2024; 12:15:09 AM -0500
V3.x:(not available)
V2.0:(not available)
CVE-2024-23135

A maliciously crafted SLDPRT file in ASMkern228A.dll when parsed through Autodesk AutoCAD can be used in user-after-free vulnerability. This vulnerability, along with other vulnerabilities, could lead to code execution in the current process.

Published: February 22, 2024; 12:15:09 AM -0500
V3.x:(not available)
V2.0:(not available)
CVE-2024-23134

A maliciously crafted IGS file in tbb.dll when parsed through Autodesk AutoCAD can be used in user-after-free vulnerability. This vulnerability, along with other vulnerabilities, could lead to code execution in the current process.

Published: February 22, 2024; 12:15:09 AM -0500
V3.x:(not available)
V2.0:(not available)
CVE-2024-23133

A maliciously crafted STP file in ASMDATAX228A.dll when parsed through Autodesk AutoCAD could lead to a memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.

Published: February 21, 2024; 11:15:08 PM -0500
V3.x:(not available)
V2.0:(not available)
CVE-2024-23132

A maliciously crafted STP file in atf_dwg_consumer.dll when parsed through Autodesk AutoCAD could lead to a memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.

Published: February 21, 2024; 11:15:08 PM -0500
V3.x:(not available)
V2.0:(not available)
CVE-2024-23131

A maliciously crafted STP file in ASMKERN228A.dll or ASMDATAX228A.dll when parsed through Autodesk AutoCAD could lead to a memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.

Published: February 21, 2024; 11:15:08 PM -0500
V3.x:(not available)
V2.0:(not available)
CVE-2024-23130

A maliciously crafted SLDASM, or SLDPRT files in ODXSW_DLL.dll when parsed through Autodesk AutoCAD could lead to a memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.

Published: February 21, 2024; 11:15:08 PM -0500
V3.x:(not available)
V2.0:(not available)
CVE-2024-23129

A maliciously crafted MODEL 3DM, STP or SLDASM files in opennurbs.dll when parsed through Autodesk AutoCAD could lead to a memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.

Published: February 21, 2024; 11:15:08 PM -0500
V3.x:(not available)
V2.0:(not available)
CVE-2024-23128

A maliciously crafted MODEL file in libodxdll.dll when parsed through Autodesk AutoCAD could lead to a memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.

Published: February 21, 2024; 11:15:08 PM -0500
V3.x:(not available)
V2.0:(not available)
CVE-2024-23127

A maliciously crafted MODEL, SLDPRT or SLDASM file in VCRUNTIME140.dll when parsed through Autodesk AutoCAD can be used to cause a Heap-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

Published: February 21, 2024; 10:15:08 PM -0500
V3.x:(not available)
V2.0:(not available)
CVE-2024-23126

A maliciously crafted CATPART file in CC5Dll.dll when parsed through Autodesk AutoCAD can be used to cause a Stack-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

Published: February 21, 2024; 10:15:08 PM -0500
V3.x:(not available)
V2.0:(not available)
CVE-2024-23125

A maliciously crafted SLDPRT file when parsed ODXSW_DLL.dll through Autodesk AutoCAD can be used to cause a Stack-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

Published: February 21, 2024; 10:15:08 PM -0500
V3.x:(not available)
V2.0:(not available)
CVE-2024-23124

A maliciously crafted STP file in ASMIMPORT228A.dll when parsed through Autodesk AutoCAD can force an Out-of-Bound Write. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or execute arbitrary code in the context of the current process.

Published: February 21, 2024; 10:15:08 PM -0500
V3.x:(not available)
V2.0:(not available)
CVE-2024-23123

A maliciously crafted CATPART file in CC5Dll.dll or ASMBASE228A.dll when parsed through Autodesk AutoCAD can force an Out-of-Bound Write. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or execute arbitrary code in the context of the current process.

Published: February 21, 2024; 9:15:49 PM -0500
V3.x:(not available)
V2.0:(not available)
CVE-2024-23122

A maliciously crafted 3DM file in opennurbs.dll when parsed through Autodesk AutoCAD can force an Out-of-Bound Write. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or execute arbitrary code in the context of the current process.

Published: February 21, 2024; 9:15:49 PM -0500
V3.x:(not available)
V2.0:(not available)
CVE-2024-23121

A maliciously crafted MODEL file in libodxdll.dll when parsed through Autodesk AutoCAD can force an Out-of-Bound Write. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or execute arbitrary code in the context of the current process.

Published: February 21, 2024; 9:15:49 PM -0500
V3.x:(not available)
V2.0:(not available)
CVE-2024-23120

A maliciously crafted STP file in ASMIMPORT228A.dll when parsed through Autodesk AutoCAD can force an Out-of-Bound Write. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or execute arbitrary code in the context of the current process.

Published: February 21, 2024; 7:15:52 PM -0500
V3.x:(not available)
V2.0:(not available)
CVE-2024-0446

A maliciously crafted STP, CATPART or MODEL file in ASMKERN228A.dll when parsed through Autodesk AutoCAD can force an Out-of-Bound Write. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or execute arbitrary code in the context of the current process.

Published: February 21, 2024; 7:15:51 PM -0500
V3.x:(not available)
V2.0:(not available)
CVE-2023-41140

A maliciously crafted PRT file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to cause a Heap-Based Buffer Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

Published: November 22, 2023; 11:15:07 PM -0500
V3.1: 7.8 HIGH
V2.0:(not available)