Home/Product/autodesk design review
Product

autodesk design review

46 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2022-42944
all versions
A malicious crafted dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerabil
7.8HIGH
CVE-2022-42943
all versions
A malicious crafted dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerabil
7.8HIGH
CVE-2022-42942
all versions
A malicious crafted dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerabil
7.8HIGH
CVE-2022-42941
all versions
A malicious crafted dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerabil
7.8HIGH
CVE-2022-42940
all versions
A malicious crafted TGA file when consumed through DesignReview.exe application could lead to memory corruption vulnerability. Thi
7.8HIGH
CVE-2022-42939
all versions
A malicious crafted TGA file when consumed through DesignReview.exe application could lead to memory corruption vulnerability. Thi
7.8HIGH
CVE-2022-42938
all versions
A malicious crafted TGA file when consumed through DesignReview.exe application could lead to memory corruption vulnerability. Thi
7.8HIGH
CVE-2022-42937
all versions
A malicious crafted .dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerabi
7.8HIGH
CVE-2022-42936
all versions
A malicious crafted .dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerabi
7.8HIGH
CVE-2022-42935
all versions
A malicious crafted .dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerabi
7.8HIGH
CVE-2022-42934
all versions
A malicious crafted .dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerabi
7.8HIGH
CVE-2022-42933
all versions
A malicious crafted .dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerabi
7.8HIGH
CVE-2022-41310
all versions
A malicious crafted .dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerabi
7.8HIGH
CVE-2022-41309
all versions
A malicious crafted .dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerabi
7.8HIGH
CVE-2022-41306
all versions
A maliciously crafted PCT file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by
7.8HIGH
CVE-2021-40166
all versions
A maliciously crafted PNG file in Autodesk Image Processing component may be used to attempt to free an object that has already be
7.8HIGH
CVE-2021-40165
all versions
A maliciously crafted TIFF, PICT, TGA, or RLC file in Autodesk Image Processing component may be used to write beyond the allocate
7.8HIGH
CVE-2021-40164
all versions
A heap-based buffer overflow could occur while parsing TIFF, PICT, TGA, or RLC files. This vulnerability may be exploited to execu
7.8HIGH
CVE-2021-40163
all versions
A Memory Corruption vulnerability may lead to code execution through maliciously crafted DLL files through Autodesk Image Processi
7.8HIGH
CVE-2021-40162
all versions
A maliciously crafted TIF, PICT, TGA, or RLC files in Autodesk Image Processing component may be forced to read beyond allocated b
7.8HIGH
CVE-2022-33890
all versions
A maliciously crafted PCT or DWF file when consumed through DesignReview.exe application could lead to memory corruption vulnerabi
7.8HIGH
CVE-2022-33889
< 2018
A maliciously crafted GIF or JPEG files when parsed through Autodesk Design Review 2018, and AutoCAD 2023 and 2022 could be used t
7.8HIGH
CVE-2022-27866
all versions
A maliciously crafted TIFF file when consumed through DesignReview.exe application can be forced to read beyond allocated boundari
7.8HIGH
CVE-2022-27865
all versions
A maliciously crafted TGA or PCX file may be used to write beyond the allocated buffer through DesignReview.exe application while
7.8HIGH
CVE-2022-27864
all versions
A Double Free vulnerability allows remote attackers to execute arbitrary code through DesignReview.exe application on PDF files wi
8.8HIGH
CVE-2022-27871
all versions
Autodesk AutoCAD product suite, Revit, Design Review and Navisworks releases using PDFTron prior to 9.1.17 version may be used to
7.8HIGH
CVE-2022-27526
all versions
A malicious crafted TGA file when consumed through DesignReview.exe application could lead to memory corruption vulnerability. Thi
7.8HIGH
CVE-2022-27525
all versions
A malicious crafted .dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerabi
7.8HIGH
CVE-2021-40167
all versions
A malicious crafted dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerabil
7.8HIGH
CVE-2021-40161
all versions
A Memory Corruption vulnerability may lead to code execution through maliciously crafted DLL files through PDFTron earlier than 9.
7.8HIGH
CVE-2021-40160
all versions
PDFTron prior to 9.0.7 version may be forced to read beyond allocated boundaries when parsing a maliciously crafted PDF file. This
7.8HIGH
CVE-2021-27039
all versions
A maliciously crafted TIFF and PCX file can be forced to read and write beyond allocated boundaries when parsing the TIFF and PCX
7.8HIGH
CVE-2021-27038
all versions
A Type Confusion vulnerability in Autodesk Design Review 2018, 2017, 2013, 2012, 2011 can occur when processing a maliciously craf
7.8HIGH
CVE-2021-27037
all versions
A maliciously crafted PNG, PDF or DWF file in Autodesk Design Review 2018, 2017, 2013, 2012, 2011 can be used to attempt to free a
7.8HIGH
CVE-2021-27036
all versions
A maliciously crafted PCX, PICT, RCL, TIF, BMP, PSD or TIFF file can be used to write beyond the allocated buffer while parsing PC
7.8HIGH
CVE-2021-27035
all versions
A maliciously crafted TIFF, TIF, PICT, TGA, or DWF files in Autodesk Design Review 2018, 2017, 2013, 2012, 2011 can be forced to r
7.8HIGH
CVE-2021-27034
all versions
A heap-based buffer overflow could occur while parsing PICT, PCX, RCL or TIFF files in Autodesk Design Review 2018, 2017, 2013, 20
7.8HIGH
CVE-2021-27033
all versions
A Double Free vulnerability allows remote attackers to execute arbitrary code on PDF files within affected installations of Autode
7.8HIGH
CVE-2021-27041
all versions
A maliciously crafted DWG file can be used to write beyond the allocated buffer while parsing DWG files. This vulnerability can be
7.8HIGH
CVE-2019-7363
all versions
Use-after-free vulnerability in Autodesk Design Review versions 2011, 2012, 2013, and 2018. An attacker may trick a user into open
7.8HIGH
CVE-2019-7362
all versions
DLL preloading vulnerability in Autodesk Design Review versions 2011, 2012, 2013, and 2018. An attacker may trick a user into open
7.8HIGH
CVE-2015-8572
all versions
Multiple buffer overflows in Autodesk Design Review (ADR) before 2013 Hotfix 2 allow remote attackers to execute arbitrary code vi
CVE-2015-8571
all versions
Integer overflow in Autodesk Design Review (ADR) before 2013 Hotfix 2 allows remote attackers to execute arbitrary code via a craf
CVE-2014-9268
<= 2013
The AdView.AdViewer.1 ActiveX control in Autodesk Design Review (ADR) before 2013 Hotfix 1 allows remote attackers to execute arbi
CVE-2008-4472
all versions
The UpdateEngine class in the LiveUpdate ActiveX control (LiveUpdate16.DLL 17.2.56), as used in Revit Architecture 2009 SP2 and Au
CVE-2008-4471
all versions
Directory traversal vulnerability in the CExpressViewerControl class in the DWF Viewer ActiveX control (AdView.dll 9.0.0.96), as u
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin