Known vulnerabilities in Autodesk Infraworks - page 3
Vendor:
Autodesk
Software:
Autodesk Infraworks
Software CPE:
cpe:2.3:a:autodesk:autodesk_infraworks:*:*:*:*:*:*:*:*
Website:
https://www.autodesk.com/
Total vulnerabilities:
88
Public exploits:
12
Known exploited (KEV):
3
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
2026.3
2026.2
2026.1
2026.0
2022.1.10.363
2023.1.5.251
2024.1.4.152
2025.02.86
2021.2 Hotfix 9
2023.1 Hotfix 1
2023.0.2
2023.0.1 Hotfix 1
2023.0.1
2022.1.5 Hotfix 5
2022.1.5
2021.2 Hotfix 7
2020.2 Hotfix 7
2022.1 Hotfix 4
2022.1 Hotfix 3
2022.1 Hotfix 1
2021.2 Hotfix 6
2021.2 Hotfix 5
2021.2 Hotfix 3
2021.2 Hotfix 2
2021.2 Hotfix 1
2020.2 Hotfix 6
2020.2 Hotfix 5
2020.2 Hotfix 3
2020.2 Hotfix 2
2020.2 Hotfix 1
2019.3 Hotfix 5
2020.2 Hotfix 4
2021.2 Hotfix 4
2022.0 Hotfix 3
2022.1 Hotfix 2
2019.3
2020.2
2021.2
2022.1
2022.0
Vulnerabilities (88)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU75516 - Heap-based Buffer Overflow CVE-2021-4214 |
CWE-122 | Low | 2021.2 Hotfix 9, 2023.1 Hotfix 1 | 26.04.2023 |
SB2023042621 SB2023042635 |
||
| #VU67414 - Improper Validation of Array Index CVE-2022-35737 |
CWE-129 | Medium | 2021.2 Hotfix 9, 2023.1 Hotfix 1 | 15.09.2022 |
SB2022091537 SB2022092034 SB2022092682 and 72 more |
||
| #VU64922 - Missing Encryption of Sensitive Data CVE-2022-2097 |
CWE-311 | Low | 2021.2 Hotfix 9, 2023.1 Hotfix 1 | 05.07.2022 |
SB2022070509 SB2022070522 SB2022070531 and 112 more |
||
| #VU63127 - Resource exhaustion CVE-2021-37136 |
CWE-400 | Medium | 2021.2 Hotfix 9, 2023.1 Hotfix 1 | 12.05.2022 |
SB2021101948 SB2022051235 SB2022060838 and 36 more |
||
| #VU61756 - Improper Control of Generation of Code ('Code Injection') CVE-2022-22965 |
CWE-94 | Critical | 2021.2 Hotfix 9, 2023.1 Hotfix 1 | 31.03.2022 |
SB2022033109 SB2022040109 SB2022040110 and 78 more |
||
| #VU59924 - Improper input validation CVE-2021-37137 |
CWE-20 | Medium | 2021.2 Hotfix 9, 2023.1 Hotfix 1 | 23.01.2022 |
SB2022012310 SB2022012745 SB2022012753 and 43 more |
||
| #VU51836 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2021-21295 |
CWE-444 | Medium | 2021.2 Hotfix 9, 2023.1 Hotfix 1 | 01.04.2021 |
SB2021040115 SB2021040626 SB2021050706 and 26 more |
||
| #VU28773 - Use After Free CVE-2020-13871 |
CWE-416 | High | 2021.2 Hotfix 9, 2023.1 Hotfix 1 | 07.06.2020 |
SB2020060705 SB2020072756 SB2020102002 and 8 more |
||
| #VU24065 - Missing release of memory after effective lifetime CVE-2019-20218 |
CWE-401 | Low | 2021.2 Hotfix 9, 2023.1 Hotfix 1 | 07.01.2020 |
SB2019122301 SB2020072756 SB2020110913 and 13 more |
||
| #VU24064 - Resource Management Errors CVE-2019-19959 |
CWE-399 | Low | 2021.2 Hotfix 9, 2023.1 Hotfix 1 | 07.01.2020 |
SB2019122301 SB2020042838 SB2022041131 and 6 more |
||
| #VU23915 - Unrestricted Upload of File with Dangerous Type CVE-2019-19925 |
CWE-434 | High | 2021.2 Hotfix 9, 2023.1 Hotfix 1 | 03.01.2020 |
SB2019122301 SB2020020601 SB2020020614 and 14 more |
||
| #VU23794 - Untrusted Pointer Dereference CVE-2019-19880 |
CWE-822 | High | 2021.2 Hotfix 9, 2023.1 Hotfix 1 | 23.12.2019 |
SB2019122301 SB2020020601 SB2020020614 and 13 more |
||
| #VU23793 - Improper input validation CVE-2019-19926 |
CWE-20 | Medium | 2021.2 Hotfix 9, 2023.1 Hotfix 1 | 23.12.2019 |
SB2019122301 SB2020020601 SB2020020614 and 14 more |
||
| #VU23790 - Improper input validation CVE-2019-19603 |
CWE-20 | Medium | 2021.2 Hotfix 9, 2023.1 Hotfix 1 | 23.12.2019 |
SB2019122301 SB2022031104 SB2022041131 and 17 more |
||
| #VU23789 - Improper input validation CVE-2019-19317 |
CWE-20 | Medium | 2021.2 Hotfix 9, 2023.1 Hotfix 1 | 23.12.2019 |
SB2019122301 SB2022031104 SB2022041131 and 6 more |
||
| #VU18060 - NULL Pointer Dereference CVE-2019-9937 |
CWE-476 | Medium | 2021.2 Hotfix 9, 2023.1 Hotfix 1 | 22.03.2019 |
SB2019032205 SB2019051006 SB2019081527 and 7 more |
||
| #VU18059 - Out-of-bounds read CVE-2019-9936 |
CWE-125 | Low | 2021.2 Hotfix 9, 2023.1 Hotfix 1 | 22.03.2019 |
SB2019032205 SB2019051006 SB2019081527 and 7 more |
||
| #VU17049 - Permissions, Privileges, and Access Controls CVE-2018-11212 |
CWE-369 | Low | 2021.2 Hotfix 9, 2023.1 Hotfix 1 | 17.01.2019 |
SB2019011702 SB2019021208 SB2019031810 and 21 more |
||
| #VU15467 - Improper input validation CVE-2018-15756 |
CWE-20 | Low | 2021.2 Hotfix 9, 2023.1 Hotfix 1 | 22.10.2018 |
SB2018102305 SB2020012203 SB2020032701 and 28 more |
||
| #VU11918 - Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') CVE-2018-1273 |
CWE-113 | High | 2021.2 Hotfix 9, 2023.1 Hotfix 1 | 18.04.2018 |
SB2018041815 SB2022072013 SB2023011758 and 2 more |
Showing elements 41 - 60 out of 88