Autodesk Design Review vulnerabilities
46 known vulnerabilities affecting autodesk/design_review.
Total CVEs
46
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH41MEDIUM3
Vulnerabilities
Page 3 of 3
CVE-2015-8572P3MEDIUMCVSS 6.8v20132015-12-15
CVE-2015-8572 [MEDIUM] CWE-119 CVE-2015-8572: Multiple buffer overflows in Autodesk Design Review (ADR) before 2013 Hotfix 2 allow remote attacker
Multiple buffer overflows in Autodesk Design Review (ADR) before 2013 Hotfix 2 allow remote attackers to execute arbitrary code via crafted RLE data in a (1) BMP or (2) FLI file, (3) encoded scan lines in a PCX file, or (4) DataSubBlock or (5) GlobalColorTable in a GIF file.
nvd
CVE-2022-33889P3HIGHCVSS 7.8fixed in 2018v20182022-10-03
CVE-2022-33889 [HIGH] CWE-787 CVE-2022-33889: A maliciously crafted GIF or JPEG files when parsed through Autodesk Design Review 2018, and AutoCAD
A maliciously crafted GIF or JPEG files when parsed through Autodesk Design Review 2018, and AutoCAD 2023 and 2022 could be used to write beyond the allocated heap buffer. This vulnerability could lead to arbitrary code execution.
nvd
CVE-2022-27865P3HIGHCVSS 7.8v2011v2012+3 more2022-07-29
CVE-2022-27865 [HIGH] CWE-787 CVE-2022-27865: A maliciously crafted TGA or PCX file may be used to write beyond the allocated buffer through Desig
A maliciously crafted TGA or PCX file may be used to write beyond the allocated buffer through DesignReview.exe application while parsing TGA and PCX files. This vulnerability may be exploited to execute arbitrary code.
nvd
CVE-2022-27866P3HIGHCVSS 7.8v2011v2012+3 more2022-07-29
CVE-2022-27866 [HIGH] CWE-125 CVE-2022-27866: A maliciously crafted TIFF file when consumed through DesignReview.exe application can be forced to
A maliciously crafted TIFF file when consumed through DesignReview.exe application can be forced to read beyond allocated boundaries when parsing the TIFF file. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.
nvd
CVE-2019-7362P3HIGHCVSS 7.8v2011v2012+2 more2019-08-23
CVE-2019-7362 [HIGH] CWE-427 CVE-2019-7362: DLL preloading vulnerability in Autodesk Design Review versions 2011, 2012, 2013, and 2018. An attac
DLL preloading vulnerability in Autodesk Design Review versions 2011, 2012, 2013, and 2018. An attacker may trick a user into opening a malicious DWF file that may leverage a DLL preloading vulnerability, which may result in code execution.
nvd
CVE-2015-8571P3MEDIUMCVSS 6.8v20132015-12-15
CVE-2015-8571 [MEDIUM] CWE-189 CVE-2015-8571: Integer overflow in Autodesk Design Review (ADR) before 2013 Hotfix 2 allows remote attackers to exe
Integer overflow in Autodesk Design Review (ADR) before 2013 Hotfix 2 allows remote attackers to execute arbitrary code via a crafted biClrUsed value in a BMP file, which triggers a buffer overflow.
nvd
← Previous3 / 3