CVE-2021-40159High· 7.8▾ Abyssal0dayAn Information Disclosure vulnerability for JT files in Autodesk Inventor 2022, 2021, 2020, 2019 in conjunction with other vulnerabilities may lead to code execution through maliciously crafted JT files in the context of the current proc…
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 42.9 · likelihood 0.5 · exploitation 25
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
2.3%
An Information Disclosure vulnerability for JT files in Autodesk Inventor 2022, 2021, 2020, 2019 in conjunction with other vulnerabilities may lead to code execution through maliciously crafted JT files in the context of the current process.
advance_steel >= 2022, < 2022.1.2autocad >= 2022, < 2022.1.2autocad_architecture >= 2022, < 2022.1.2autocad_electrical >= 2022, < 2022.1.2autocad_lt >= 2022, < 2022.1.2autocad_map_3d >= 2022, < 2022.1.2autocad_mechanical >= 2022, < 2022.1.2autocad_mep >= 2022, < 2022.1.2autocad_plant_3d >= 2022, < 2022.1.2civil_3d >= 2022, < 2022.1.2inventor = 2019inventor = 2020inventor = 2021inventor = 2022Upgrade past the affected range:
advance_steel 2022.1.2autocad 2022.1.2autocad_architecture 2022.1.2autocad_electrical 2022.1.2autocad_lt 2022.1.2autocad_map_3d 2022.1.2autocad_mechanical 2022.1.2autocad_mep 2022.1.2autocad_plant_3d 2022.1.2civil_3d 2022.1.2Connected by shared product, vendor, weakness, or advisory.
CVE-2022-25788High· 7.8A maliciously crafted JT file in Autodesk AutoCAD 2022 may be used to write beyond the allocated buffer while parsing JT files
CVE-2021-40158High· 7.8A maliciously crafted JT file in Autodesk Inventor 2022, 2021, 2020, 2019 and AutoCAD 2022 may be forced to read beyond allocated boundaries when parsing the JT file
CVE-2022-27867High· 7.8A maliciously crafted JT file in Autodesk AutoCAD 2022, 2021, 2020, 2019 can be used to trigger use-after-free vulnerability
CVE-2026-7405Medium· 5.5A maliciously crafted TIF file, when parsed through certain Autodesk products during image import, can cause an Out-of-Bounds Read in the image handling library
CVE-2026-7406High· 7.8A maliciously crafted BMP file, when parsed through certain Autodesk products, can force a Untrusted Pointer Dereference vulnerability
CVE-2020-17527High· 7.5While investigating bug 64830 it was discovered that Apache Tomcat 10.0.0-M1 to 10.0.0-M9, 9.0.0-M1 to 9.0.39 and 8.5.0 to 8.5.59 could re-use an HTTP request header value from the previous stream received on an HTTP/2 connection for the…