CVE-2014-3938

Autodesk SketchBook Pro <6.2.6 - RCE

Title source: llm
STIX 2.1

Description

Integer overflow in Autodesk SketchBook Pro before 6.2.6 allows remote attackers to execute arbitrary code via crafted layer mask data in a PSD file, which triggers a heap-based buffer overflow.

References (2)

Core 2
Core References
Third Party Advisory x_refsource_misc
http://secunia.com/secunia_research/2014-6/
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/58000

Scores

EPSS 0.1055
EPSS Percentile 93.4%

Details

CWE
CWE-189
Status published
Products (2)
autodesk/sketchbook_pro 6.2.4
autodesk/sketchbook_pro < 6.2.5
Published Jul 23, 2014
Tracked Since Feb 18, 2026