Autodesk 3Ds Max vulnerabilities
25 known vulnerabilities affecting autodesk/3ds_max.
Total CVEs
25
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH21MEDIUM3
Vulnerabilities
Page 2 of 2
CVE-2022-27531P3HIGHCVSS 7.8≥ 2021, < 2021.3.8≥ 2022, < 2022.3.32022-06-16
CVE-2022-27531 [HIGH] CWE-125 CVE-2022-27531: A maliciously crafted TIF file can be forced to read beyond allocated boundaries in Autodesk 3ds Max
A maliciously crafted TIF file can be forced to read beyond allocated boundaries in Autodesk 3ds Max 2022, and 2021 when parsing the TIF files. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.
nvd
CVE-2023-25002P3HIGHCVSS 7.8v2022v20232023-06-27
CVE-2023-25002 [HIGH] CWE-416 CVE-2023-25002: A maliciously crafted SKP file in Autodesk products is used to trigger use-after-free vulnerability.
A maliciously crafted SKP file in Autodesk products is used to trigger use-after-free vulnerability. Exploitation of this vulnerability may lead to code execution.
nvd
CVE-2026-7453P4MEDIUMCVSS 5.5v2026v2027+2 more2026-05-26
CVE-2026-7453 [MEDIUM] CWE-674 CVE-2026-7453: A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can cause a Stack Exhaustion v
A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can cause a Stack Exhaustion vulnerability, leading to a denial-of-service condition.
nvd
CVE-2026-7450P4MEDIUMCVSS 5.5v2026v2027+2 more2026-05-26
CVE-2026-7450 [MEDIUM] CWE-476 CVE-2026-7450: A maliciously crafted PAR file, when parsed through Autodesk 3ds Max, can force a NULL Pointer Deref
A maliciously crafted PAR file, when parsed through Autodesk 3ds Max, can force a NULL Pointer Dereference vulnerability. Successful exploitation may cause the application to crash, leading to a denial-of-service condition.
nvd
CVE-2005-4710P4MEDIUMCVSS 4.6v72005-12-31
CVE-2005-4710 [MEDIUM] CVE-2005-4710: Unspecified vulnerability in multiple Autodesk and AutoCAD products and product families from 2006 a
Unspecified vulnerability in multiple Autodesk and AutoCAD products and product families from 2006 and earlier allows remote attackers to "gain inappropriate access to another local user's computer," aka ID DL5549329.
nvd
← Previous2 / 2