Home/Product/autodesk dwg trueview
Product

autodesk dwg trueview

22 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-1276
>= 2023 and < 2023.1.7
A maliciously crafted DWG file, when parsed through certain Autodesk applications, can force an Out-of-Bounds Write vulnerability.
7.8HIGH
CVE-2025-1275
>= 2023 and < 2023.1.7
A maliciously crafted JPG file, when linked or imported into certain Autodesk applications, can force a Heap-Based Overflow vulner
7.8HIGH
CVE-2024-9997
>= 2025 and < 2025.1.1
A maliciously crafted DWG file when parsed in acdb25.dll through Autodesk AutoCAD can force a Memory Corruption vulnerability. A m
7.8HIGH
CVE-2024-9996
>= 2025 and < 2025.1.1
A maliciously crafted DWG file, when parsed in acdb25.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability
7.8HIGH
CVE-2024-9489
>= 2025 and < 2025.1.1
A maliciously crafted DWG file when parsed in ACAD.exe through Autodesk AutoCAD can force a Memory Corruption vulnerability. A mal
7.8HIGH
CVE-2024-8896
>= 2025 and < 2025.1.1
A maliciously crafted DXF file when parsed in acdb25.dll through Autodesk AutoCAD can force to access a variable prior to initial
7.8HIGH
CVE-2024-7992
>= 2025 and < 2025.1.1
A maliciously crafted DWG file, when parsed through Autodesk AutoCAD and certain AutoCAD-based products, can force a Stack-based B
7.8HIGH
CVE-2024-7991
>= 2025 and < 2025.1.1
A maliciously crafted DWG file, when parsed through Autodesk AutoCAD and certain AutoCAD-based products, may force an Out-of-Bound
7.8HIGH
CVE-2024-7305
>= 2023 and < 2023.1.7
A maliciously crafted DWF file, when parsed in AdDwfPdk.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerabili
7.8HIGH
CVE-2024-23138
>= 2022 and < 2022.1.4
A maliciously crafted DWG file when parsed through Autodesk DWG TrueView can be used to cause a Stack-based Overflow. A malicious
7.8HIGH
CVE-2022-42945
all versions
DWG TrueViewTM 2023 version has a DLL Search Order Hijacking vulnerability. Successful exploitation by a malicious attacker could
7.8HIGH
CVE-2021-40166
>= 2019 and < 2019.1.4
A maliciously crafted PNG file in Autodesk Image Processing component may be used to attempt to free an object that has already be
7.8HIGH
CVE-2021-40165
>= 2019 and < 2019.1.4
A maliciously crafted TIFF, PICT, TGA, or RLC file in Autodesk Image Processing component may be used to write beyond the allocate
7.8HIGH
CVE-2021-40164
>= 2019 and < 2019.1.4
A heap-based buffer overflow could occur while parsing TIFF, PICT, TGA, or RLC files. This vulnerability may be exploited to execu
7.8HIGH
CVE-2021-40163
>= 2019 and < 2019.1.4
A Memory Corruption vulnerability may lead to code execution through maliciously crafted DLL files through Autodesk Image Processi
7.8HIGH
CVE-2021-40162
>= 2019 and < 2019.1.4
A maliciously crafted TIF, PICT, TGA, or RLC files in Autodesk Image Processing component may be forced to read beyond allocated b
7.8HIGH
CVE-2022-27524
>= 2019 and < 2019.1.4
An out-of-bounds read can be exploited in Autodesk TrueView 2022 may lead to an exposure of sensitive information or a crash throu
7.1HIGH
CVE-2022-27523
>= 2019 and < 2019.1.4
A buffer over-read can be exploited in Autodesk TrueView 2022 may lead to an exposure of sensitive information or a crash through
7.1HIGH
CVE-2022-25797
all versions
A maliciously crafted PDF file in Autodesk AutoCAD 2022, 2021, 2020, 2019 can be used to dereference for a write beyond the alloca
7.8HIGH
CVE-2021-27043
>= 2022 and < 2022.1.1
An Arbitrary Address Write issue in the Autodesk DWG application can allow a malicious user to leverage the application to write i
7.8HIGH
CVE-2021-27040
>= 2022 and < 2022.1.1
A maliciously crafted DWG file can be forced to read beyond allocated boundaries when parsing the DWG file. This vulnerability can
3.3LOW
CVE-2013-3665
all versions
Unspecified vulnerability in Autodesk AutoCAD through 2014, AutoCAD LT through 2014, and DWG TrueView through 2014 allows remote a
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin