Vendor
Autodesk 3ds Max Out-of-Bounds Write Vulnerability (CVE-2026-16783)
1 TTP 1 CVEAutodesk 3ds Max contains an out-of-bounds write vulnerability triggered by parsing maliciously crafted Alembic (.abc) files, potentially allowing arbitrary code execution upon user interaction.
Arbitrary Code Execution in Autodesk Revit via Malicious PDF
1 TTP 4 CVEsAutodesk Revit contains an out-of-bounds read vulnerability in its PDF parsing engine that can be exploited for arbitrary code execution or information disclosure.
Stack-based Buffer Overflow in Autodesk FBX SDK
2 TTPs 2 CVEsA stack-based buffer overflow vulnerability (CVE-2026-10709) in the Autodesk FBX SDK allows arbitrary code execution via maliciously crafted FBX files.
Heap-Based Buffer Overflow in Autodesk AutoCAD
1 TTP 1 CVEA heap-based buffer overflow vulnerability in Autodesk AutoCAD, AutoCAD LT, and DWG TrueView allows attackers to execute arbitrary code via maliciously crafted DXF files.
Autodesk 3ds Max Memory Corruption Vulnerability via Malformed WRL File (CVE-2026-7452)
2 rules 1 TTP 1 CVEA maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can trigger a memory corruption vulnerability (CVE-2026-7452) allowing arbitrary code execution in the context of the application.
CVE-2026-7454 - Autodesk 3ds Max Memory Corruption Vulnerability via Malicious WRL File
2 rules 1 TTP 1 CVEA maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can trigger CVE-2026-7454, a memory corruption vulnerability allowing arbitrary code execution in the context of the current process.
CVE-2026-7451 - Autodesk 3ds Max Out-of-Bounds Write Vulnerability via Malicious TIF File
2 rules 1 TTP 1 CVECVE-2026-7451 is an out-of-bounds write vulnerability in Autodesk 3ds Max that can be exploited via a maliciously crafted TIF file, potentially leading to a crash, data corruption, or arbitrary code execution.
Autodesk Fusion Stored XSS Vulnerability via Maliciously Crafted Design Name
2 rules 2 TTPs 1 CVE 2 IOCsA stored cross-site scripting (XSS) vulnerability exists in the Autodesk Fusion desktop application, where a maliciously crafted HTML payload stored in a design name and exported to CSV can be triggered, potentially leading to local file reads or arbitrary code execution.