CVE-2024-7674
published 2024-09-30CVE-2024-7674: A maliciously crafted DWFX file, when parsed in dwfcore.dll through Autodesk Navisworks, can force a Heap-based Buffer Overflow. A malicious actor can leverage…
PriorityP337high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.23%
13.5th percentile
A maliciously crafted DWFX file, when parsed in dwfcore.dll through Autodesk Navisworks, can force a Heap-based Buffer Overflow. A malicious actor can leverage this vulnerability to cause a crash or execute arbitrary code in the context of the current process.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| autodesk | navisworks | — | — |
| autodesk | navisworks | — | — |
| autodesk | navisworks | — | — |
| autodesk | navisworks_freedom | >= 2022 < 2022.6 | 2022.6 |
| autodesk | navisworks_freedom | >= 2023 < 2023.5 | 2023.5 |
| autodesk | navisworks_freedom | >= 2024 < 2024.3 | 2024.3 |
| autodesk | navisworks_freedom | >= 2025 < 2025.3 | 2025.3 |
| autodesk | navisworks_manage | >= 2022 < 2022.6 | 2022.6 |
| autodesk | navisworks_manage | >= 2023 < 2023.5 | 2023.5 |
| autodesk | navisworks_manage | >= 2024 < 2024.3 | 2024.3 |
| autodesk | navisworks_manage | >= 2025 < 2025.3 | 2025.3 |
| autodesk | navisworks_simulate | >= 2022 < 2022.6 | 2022.6 |
| autodesk | navisworks_simulate | >= 2023 < 2023.5 | 2023.5 |
| autodesk | navisworks_simulate | >= 2024 < 2024.3 | 2024.3 |
| autodesk | navisworks_simulate | >= 2025 < 2025.3 | 2025.3 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Suricata
GPL FTP CWD Root directory transversal attempt
suricata·2010-09-23
CVE-2003-0392 GPL FTP CWD Root directory transversal attempt
GPL FTP CWD Root directory transversal attempt
Rule: alert tcp $EXTERNAL_NET any -> $HOME_NET 21 (msg:"GPL FTP CWD Root directory transversal attempt"; flow:established,to_server; content:"CWD"; nocase; content:"C|3A 5C|"; distance:1; fast_pattern; reference:bugtraq,7674; reference:cve,2003-0392; reference:nessus,11677; classtype:protocol-command-decode; sid:2102125; rev:11; metadata:created_at 2010_09_23, cve CVE_2003_0392, signature_severity Unknown, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_03_08;)
No public exploits indexed.
No writeups or analysis indexed.
2024-09-30
Published