3ds Max

Vendor:

First CVE: Dec 31, 2005 · Active for 20 years

55
Total CVEs
More Total CVEs than 98% of tracked products
9.2
Avg CVEs / Year
Higher CVE frequency than 95% of tracked products
7.7
Avg CVSS
Higher Avg CVSS than 62% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact 3ds Max over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2005
20 years ago
Most Recent CVE
May 26, 2026
61 days ago

CVE Severity & Scoring

3ds Max55 CVEs
All CVEs352,719 CVEs
MediumHigh
Attack Vector
Local53 (96.4%)
Network0 (0.0%)
Unknown2 (3.6%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low53 (96.4%)
High0 (0.0%)
Unknown2 (3.6%)
User Interaction
None4 (7.3%)
Unknown2 (3.6%)
Required49 (89.1%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None53 (96.4%)
Unknown2 (3.6%)

Top CVEs

Signals from CVEs in this product scope (55 CVEs).

55 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Autodesk 3D Studio Max (3DSMax) 6 through 9 and 2008 through 2010 allows remote attackers to execute arbitrary code via a .max file with a MAXScript statement that calls the DOSCom
Nov 24, 20099.334NOYES
A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbi
May 26, 20267.833NONO
A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbi
May 26, 20267.829NONO
A maliciously crafted TIF file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a c
May 26, 20267.829NONO
A maliciously crafted CATPRODUCT file, when parsed through certain Autodesk products, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerabili
Dec 16, 20257.827NONO
A maliciously crafted SLDPRT file, when parsed through certain Autodesk products, can force a Memory corruption vulnerability. A malicious actor can leverage this vulnerability to
Dec 16, 20257.827NONO
A maliciously crafted RGB file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbi
Feb 4, 20268.426NONO
A maliciously crafted GIF file, when parsed through Autodesk 3ds Max, can cause a Stack-Based Buffer Overflow vulnerability. A malicious actor can leverage this vulnerability to ex
Feb 4, 20268.426NONO
A maliciously crafted GIF file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor can leverage this vulnerability to execute a
Feb 4, 20268.426NONO
A maliciously crafted RGB file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbi
Feb 4, 20268.426NONO

Exploit Exposure

Signals from CVEs in this product scope (55 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
1.8% of CVEs· 87th percentile

Social Chatter

Signals from CVEs in this product scope (55 CVEs).

Media Mentions

Signals from CVEs in this product scope (55 CVEs).

Top CNAs Publishing CVEs For 3ds Max

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
919.35.1%01
819.35.1%01
727.02.8%01
619.35.1%01
202756.90.1%00
202656.90.1%00
202317.80.4%00
202227.80.5%00
202117.80.7%00
201019.35.1%01
200919.35.1%01
200819.35.1%01