Autodesk Civil 3D vulnerabilities
114 known vulnerabilities affecting autodesk/civil_3d.
Total CVEs
114
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH113LOW1
Vulnerabilities
Page 4 of 6
CVE-2024-23149P3HIGHCVSS 7.8≥ 2022, < 2022.1.5≥ 2023, < 2023.1.6+2 more2024-06-25
CVE-2024-23149 [HIGH] CWE-125 CVE-2024-23149: A maliciously crafted SLDDRW file, when parsed in ODXSW_DLL.dll through Autodesk applications, can f
A maliciously crafted SLDDRW file, when parsed in ODXSW_DLL.dll through Autodesk applications, can force an Out-of-Bound Read. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
nvd
CVE-2024-37006P3HIGHCVSS 7.8≥ 2022, < 2022.1.5≥ 2023, < 2023.1.6+2 more2024-06-25
CVE-2024-37006 [HIGH] CWE-787 CVE-2024-37006: A maliciously crafted CATPRODUCT file, when parsed in CC5Dll.dll through Autodesk applications, can
A maliciously crafted CATPRODUCT file, when parsed in CC5Dll.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, in conjunction with other vulnerabilities, can lead to code execution in the context of the current process.
nvd
CVE-2024-23129P3HIGHCVSS 7.8≥ 2021, < 2021.1.4≥ 2022, < 2022.1.4+3 more2024-02-22
CVE-2024-23129 [HIGH] CWE-119 CVE-2024-23129: A maliciously crafted MODEL 3DM, STP, or SLDASM file, when in opennurbs.dll parsed through Autodesk
A maliciously crafted MODEL 3DM, STP, or SLDASM file, when in opennurbs.dll parsed through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, in conjunction with other vulnerabilities, can lead to code execution in the context of the current process.
nvd
CVE-2024-23125P3HIGHCVSS 7.8≥ 2021, < 2021.1.4≥ 2022, < 2022.1.4+3 more2024-02-22
CVE-2024-23125 [HIGH] CWE-121 CVE-2024-23125: A maliciously crafted SLDPRT file when parsed ODXSW_DLL.dll through Autodesk applications can be use
A maliciously crafted SLDPRT file when parsed ODXSW_DLL.dll through Autodesk applications can be used to cause a Stack-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
nvd
CVE-2024-37003P3HIGHCVSS 7.8≥ 2022, < 2022.1.5≥ 2023, < 2023.1.6+2 more2024-06-25
CVE-2024-37003 [HIGH] CWE-121 CVE-2024-37003: A maliciously crafted DWG and SLDPRT file, when parsed in opennurbs.dll and ODXSW_DLL.dll through Au
A maliciously crafted DWG and SLDPRT file, when parsed in opennurbs.dll and ODXSW_DLL.dll through Autodesk applications, can be used to cause a Stack-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
nvd
CVE-2024-23148P3HIGHCVSS 7.8≥ 2022, < 2022.1.5≥ 2023, < 2023.1.6+2 more2024-06-25
CVE-2024-23148 [HIGH] CWE-787 CVE-2024-23148: A maliciously crafted CATPRODUCT file, when parsed in CC5Dll.dll through Autodesk applications, can
A maliciously crafted CATPRODUCT file, when parsed in CC5Dll.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, in conjunction with other vulnerabilities, can lead to code execution in the context of the current process.
nvd
CVE-2025-1428P3HIGHCVSS 7.8≥ 2022, < 2022.1.6≥ 2023, < 2023.1.7+2 more2025-03-13
CVE-2025-1428 [HIGH] CWE-125 CVE-2025-1428: A maliciously crafted CATPART file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds
A maliciously crafted CATPART file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
nvd
CVE-2025-1427P3HIGHCVSS 7.8≥ 2022, < 2022.1.6≥ 2023, < 2023.1.7+2 more2025-03-13
CVE-2025-1427 [HIGH] CWE-457 CVE-2025-1427: A maliciously crafted CATPRODUCT file, when parsed through Autodesk AutoCAD, can force an Uninitiali
A maliciously crafted CATPRODUCT file, when parsed through Autodesk AutoCAD, can force an Uninitialized Variable vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
nvd
CVE-2025-1649P3HIGHCVSS 7.8≥ 2022, < 2022.1.6≥ 2023, < 2023.1.7+2 more2025-03-13
CVE-2025-1649 [HIGH] CWE-457 CVE-2025-1649: A maliciously crafted CATPRODUCT file, when parsed through Autodesk AutoCAD, can force an Uninitiali
A maliciously crafted CATPRODUCT file, when parsed through Autodesk AutoCAD, can force an Uninitialized Variable vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
nvd
CVE-2025-1652P3HIGHCVSS 7.8≥ 2022, < 2022.1.6≥ 2023, < 2023.1.7+2 more2025-03-13
CVE-2025-1652 [HIGH] CWE-125 CVE-2025-1652: A maliciously crafted MODEL file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds R
A maliciously crafted MODEL file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
nvd
CVE-2025-1650P3HIGHCVSS 7.8≥ 2022, < 2022.1.6≥ 2023, < 2023.1.7+2 more2025-03-13
CVE-2025-1650 [HIGH] CWE-457 CVE-2025-1650: A maliciously crafted CATPRODUCT file, when parsed through Autodesk AutoCAD, can force an Uninitiali
A maliciously crafted CATPRODUCT file, when parsed through Autodesk AutoCAD, can force an Uninitialized Variable vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
nvd
CVE-2025-1429P3HIGHCVSS 7.8≥ 2022, < 2022.1.6≥ 2023, < 2023.1.7+2 more2025-03-13
CVE-2025-1429 [HIGH] CWE-122 CVE-2025-1429: A maliciously crafted MODEL file, when parsed through Autodesk AutoCAD, can force a Heap-Based Overf
A maliciously crafted MODEL file, when parsed through Autodesk AutoCAD, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
nvd
CVE-2025-1651P3HIGHCVSS 7.8≥ 2022, < 2022.1.6≥ 2023, < 2023.1.7+2 more2025-03-13
CVE-2025-1651 [HIGH] CWE-122 CVE-2025-1651: A maliciously crafted MODEL file, when parsed through Autodesk AutoCAD, can force a Heap-Based Overf
A maliciously crafted MODEL file, when parsed through Autodesk AutoCAD, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
nvd
CVE-2025-1431P3HIGHCVSS 7.8≥ 2022, < 2022.1.6≥ 2023, < 2023.1.7+2 more2025-03-13
CVE-2025-1431 [HIGH] CWE-125 CVE-2025-1431: A maliciously crafted SLDPRT file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds
A maliciously crafted SLDPRT file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
nvd
CVE-2025-1433P3HIGHCVSS 7.8≥ 2022, < 2022.1.6≥ 2023, < 2023.1.7+2 more2025-03-13
CVE-2025-1433 [HIGH] CWE-125 CVE-2025-1433: A maliciously crafted MODEL file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds R
A maliciously crafted MODEL file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
nvd
CVE-2024-9826P3HIGHCVSS 7.8≥ 2025, < 2025.1.1≥ 2024, < 2024.1.7+2 more2024-10-29
CVE-2024-9826 [HIGH] CWE-416 CVE-2024-9826: A maliciously crafted 3DM file when parsed in atf_api.dll through Autodesk AutoCAD can force a Use-A
A maliciously crafted 3DM file when parsed in atf_api.dll through Autodesk AutoCAD can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or execute arbitrary code in the context of the current process.
nvd
CVE-2024-8590P3HIGHCVSS 7.8≥ 2025, < 2025.1.1≥ 2024, < 2024.1.7+2 more2024-10-29
CVE-2024-8590 [HIGH] CWE-416 CVE-2024-8590: A maliciously crafted 3DM file when parsed in atf_api.dll through Autodesk AutoCAD can force a Use-A
A maliciously crafted 3DM file when parsed in atf_api.dll through Autodesk AutoCAD can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or execute arbitrary code in the context of the current process.
nvd
CVE-2024-8595P3HIGHCVSS 7.8≥ 2025, < 2025.1.1≥ 2024, < 2024.1.7+2 more2024-10-29
CVE-2024-8595 [HIGH] CWE-416 CVE-2024-8595: A maliciously crafted MODEL file when parsed in libodxdll.dll through Autodesk AutoCAD can force a U
A maliciously crafted MODEL file when parsed in libodxdll.dll through Autodesk AutoCAD can force a Use-After-Free vulnerability. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or execute arbitrary code in the context of the current process.
nvd
CVE-2024-8594P3HIGHCVSS 7.8≥ 2025, < 2025.1.1≥ 2024, < 2024.1.7+2 more2024-10-29
CVE-2024-8594 [HIGH] CWE-122 CVE-2024-8594: A maliciously crafted MODEL file when parsed in libodxdll.dll through Autodesk AutoCAD can force a H
A maliciously crafted MODEL file when parsed in libodxdll.dll through Autodesk AutoCAD can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, write sensitive data, or execute arbitrary code in the context of the current process.
nvd
CVE-2025-1273P3HIGHCVSS 7.8≥ 2025, < 2025.1.3≥ 2024, < 2024.1.8+1 more2025-04-15
CVE-2025-1273 [HIGH] CWE-122 CVE-2025-1273: A maliciously crafted PDF file, when linked or imported into Autodesk applications, can force a Heap
A maliciously crafted PDF file, when linked or imported into Autodesk applications, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
nvd