Autodesk Navisworks vulnerabilities
47 known vulnerabilities affecting autodesk/navisworks.
Total CVEs
47
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH47
Vulnerabilities
Page 1 of 3
CVE-2024-7672P3HIGHCVSS 7.8v2025v2025.1+1 more2024-09-30
CVE-2024-7672 [HIGH] CWE-787 CVE-2024-7672: A maliciously crafted DWF file, when parsed in dwfcore.dll through Autodesk Autodesk Navisworks, may
A maliciously crafted DWF file, when parsed in dwfcore.dll through Autodesk Autodesk Navisworks, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
nvd
CVE-2024-12198P3HIGHCVSS 7.8≥ 2025, < 2025.42024-12-17
CVE-2024-12198 [HIGH] CWE-787 CVE-2024-12198: A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, may force an Out-of-Bounds
A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
nvd
CVE-2024-11422P3HIGHCVSS 7.8≥ 2025, < 2025.42024-12-17
CVE-2024-11422 [HIGH] CWE-787 CVE-2024-11422: A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can force an Out-of-Bounds
A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can force an Out-of-Bounds Write vulnerability. A malicious actor can leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
nvd
CVE-2024-12671P3HIGHCVSS 7.8≥ 2025, < 2025.42024-12-17
CVE-2024-12671 [HIGH] CWE-787 CVE-2024-12671: A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, may force an Out-of-Bounds
A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
nvd
CVE-2024-12670P3HIGHCVSS 7.8≥ 2025, < 2025.42024-12-17
CVE-2024-12670 [HIGH] CWE-122 CVE-2024-12670: A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can be used to cause a Hea
A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can be used to cause a Heap-based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
nvd
CVE-2024-12179P3HIGHCVSS 7.8≥ 2025, < 2025.42024-12-17
CVE-2024-12179 [HIGH] CWE-122 CVE-2024-12179: A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can be used to cause a Hea
A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can be used to cause a Heap-based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
nvd
CVE-2024-12178P3HIGHCVSS 7.8≥ 2025, < 2025.42024-12-17
CVE-2024-12178 [HIGH] CWE-787 CVE-2024-12178: A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can force a Memory Corrupt
A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
nvd
CVE-2024-12200P3HIGHCVSS 7.8≥ 2025, < 2025.42024-12-17
CVE-2024-12200 [HIGH] CWE-787 CVE-2024-12200: A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, may force an Out-of-Bounds
A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
nvd
CVE-2024-12669P3HIGHCVSS 7.8≥ 2025, < 2025.42024-12-17
CVE-2024-12669 [HIGH] CWE-122 CVE-2024-12669: A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can be used to cause a Hea
A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can be used to cause a Heap-based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
nvd
CVE-2024-12193P3HIGHCVSS 7.8≥ 2025, < 2025.42024-12-17
CVE-2024-12193 [HIGH] CWE-787 CVE-2024-12193: A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, may force an Out-of-Bounds
A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
nvd
CVE-2024-12197P3HIGHCVSS 7.8≥ 2025, < 2025.42024-12-17
CVE-2024-12197 [HIGH] CWE-787 CVE-2024-12197: A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, may force an Out-of-Bounds
A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
nvd
CVE-2024-12191P3HIGHCVSS 7.8≥ 2025, < 2025.42024-12-17
CVE-2024-12191 [HIGH] CWE-787 CVE-2024-12191: A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, may force an Out-of-Bounds
A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
nvd
CVE-2024-12192P3HIGHCVSS 7.8≥ 2025, < 2025.42024-12-17
CVE-2024-12192 [HIGH] CWE-787 CVE-2024-12192: A maliciously crafted DWF file, when parsed through Autodesk Navisworks, may force an Out-of-Bounds
A maliciously crafted DWF file, when parsed through Autodesk Navisworks, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
nvd
CVE-2024-12194P3HIGHCVSS 7.8≥ 2025, < 2025.42024-12-17
CVE-2024-12194 [HIGH] CWE-120 CVE-2024-12194: A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can force a Memory Corrupt
A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
nvd
CVE-2024-12199P3HIGHCVSS 7.8≥ 2025, < 2025.42024-12-17
CVE-2024-12199 [HIGH] CWE-787 CVE-2024-12199: A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, may force an Out-of-Bounds
A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
nvd
CVE-2025-1660P3HIGHCVSS 7.8≥ 2025, < 2025.52025-04-01
CVE-2025-1660 [HIGH] CWE-120 CVE-2025-1660: A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can force a Memory Corrupt
A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
nvd
CVE-2024-7671P3HIGHCVSS 7.8v2025v2025.1+1 more2024-09-30
CVE-2024-7671 [HIGH] CWE-787 CVE-2024-7671: A maliciously crafted DWFX file, when parsed in dwfcore.dll through Autodesk Navisworks, may force a
A maliciously crafted DWFX file, when parsed in dwfcore.dll through Autodesk Navisworks, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
nvd
CVE-2021-40162P3HIGHCVSS 7.8≥ 2019, < 2019.7≥ 2020, < 2020.5+2 more2022-10-07
CVE-2021-40162 [HIGH] CWE-125 CVE-2021-40162: A maliciously crafted TIF, PICT, TGA, or RLC files in Autodesk Image Processing component may be for
A maliciously crafted TIF, PICT, TGA, or RLC files in Autodesk Image Processing component may be forced to read beyond allocated boundaries when parsing the TIFF, PICT, TGA, or RLC files. This vulnerability may be exploited to execute arbitrary code.
nvd
CVE-2021-40165P3HIGHCVSS 7.8≥ 2019, < 2019.7≥ 2020, < 2020.5+2 more2022-10-07
CVE-2021-40165 [HIGH] CWE-787 CVE-2021-40165: A maliciously crafted TIFF, PICT, TGA, or RLC file in Autodesk Image Processing component may be use
A maliciously crafted TIFF, PICT, TGA, or RLC file in Autodesk Image Processing component may be used to write beyond the allocated buffer while parsing TIFF, PICT, TGA, or RLC files. This vulnerability may be exploited to execute arbitrary code.
nvd
CVE-2022-27871P3HIGHCVSS 7.8v2019v2020+1 more2022-06-21
CVE-2022-27871 [HIGH] CWE-770 CVE-2022-27871: Autodesk AutoCAD product suite, Revit, Design Review and Navisworks releases using PDFTron prior to
Autodesk AutoCAD product suite, Revit, Design Review and Navisworks releases using PDFTron prior to 9.1.17 version may be used to write beyond the allocated buffer while parsing PDF files. This vulnerability may be exploited to execute arbitrary code.
nvd
1 / 3Next →