CVE-2014-3938: Autodesk Sketchbook Pro

High severity, CVSS 9.3. EPSS: 4.3% chance of exploitation in the next 30 days.

Integer overflow in Autodesk SketchBook Pro before 6.2.6 allows remote attackers to execute arbitrary code via crafted layer mask data in a PSD file, which triggers a heap-based buffer overflow.

Affected products

  • Autodesk Sketchbook Pro: up to and including 6.2.5; version 6.2.4 only

Published 2014-07-23. Last modified 2026-06-17.