Vulnerability index

Browse CVEs

121 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Arcgis Enterprise MEDIUM 5.3
CVE-2021-29115

An information disclosure vulnerability in the ArcGIS Service Directory in Esri ArcGIS Enterprise versions 10.9.0 and below may allows a remote attac…

Fix: after 10.9
Fix from $1,600 2021-12-07
Portal For Arcgis HIGH 8.8
CVE-2021-29108

There is an privilege escalation vulnerability in organization-specific logins in Esri Portal for ArcGIS versions 10.9 and below that may allow a rem…

Fix: after 10.9
Fix from $1,950 2021-10-01
Portal For Arcgis MEDIUM 6.1
CVE-2021-29109

A reflected XSS vulnerability in Esri Portal for ArcGIS version 10.9 and below may allow a remote attacker able to convince a user to click on a craf…

Fix: after 10.9
Fix from $1,600 2021-10-01
Portal For Arcgis MEDIUM 5.4
CVE-2021-29110

Stored cross-site scripting (XSS) issue in Esri Portal for ArcGIS may allow a remote unauthenticated attacker to pass and store malicious strings in …

Fix: after 10.9
Fix from $1,600 2021-10-01
Arcgis Server CRITICAL 9.1
CVE-2021-29102

A Server-Side Request Forgery (SSRF) vulnerability in ArcGIS Server Manager version 10.8.1 and below may allow a remote, unauthenticated attacker to …

Fix: 10.9.0+
Fix from $2,300 2021-07-11
Arcgis Server MEDIUM 6.1
CVE-2021-29103

A reflected Cross Site Scripting (XXS) vulnerability in ArcGIS Server version 10.8.1 and below may allow a remote attacker able to convince a user to…

Fix: 10.9.0+
Fix from $1,600 2021-07-11
Arcgis Server MEDIUM 6.1
CVE-2021-29104

A stored Cross Site Scripting (XXS) vulnerability in ArcGIS Server Manager version 10.8.1 and below may allow a remote unauthenticated attacker to pa…

Fix: 10.9.0+
Fix from $1,600 2021-07-11
Arcgis Server MEDIUM 5.4
CVE-2021-29105

A stored Cross Site Scripting (XSS) vulnerability in Esri ArcGIS Server Services Directory version 10.8.1 and below may allow a remote authenticated …

Fix: 10.9.0+
Fix from $1,600 2021-07-11
Arcgis Server MEDIUM 6.1
CVE-2021-29106

A reflected Cross Site Scripting (XSS) vulnerability in Esri ArcGIS Server version 10.8.1 and below may allow a remote attacker able to convince a us…

Fix: 10.9.0+
Fix from $1,600 2021-07-10
Arcgis Server MEDIUM 6.1
CVE-2021-29107

A stored Cross Site Scripting (XXS) vulnerability in ArcGIS Server Manager version 10.8.1 and below may allow a remote unauthenticated attacker to pa…

Mitigation only
Fix from $1,600 2021-07-10
Arcgis Server MEDIUM 5.3
CVE-2021-29099

A SQL injection vulnerability exists in some configurations of ArcGIS Server versions 10.8.1 and earlier. Specially crafted web requests can expose i…

Fix: after 10.8.1
Fix from $1,600 2021-06-07
Arcgis Geoevent Server HIGH 7.5
CVE-2021-29101

ArcGIS GeoEvent Server versions 10.8.1 and below has a read-only directory path traversal vulnerability that could allow an unauthenticated, remote a…

Fix: after 10.8.1
Fix from $1,950 2021-05-05
Arcgis Earth HIGH 7.8
CVE-2021-29100

A path traversal vulnerability exists in Esri ArcGIS Earth versions 1.11.0 and below which allows arbitrary file creation on an affected system throu…

Fix: after 1.11.0
Fix from $1,950 2021-05-05
Arcgis Enterprise MEDIUM 5.4
CVE-2021-3012

A cross-site scripting (XSS) vulnerability in the Document Link of documents in ESRI Enterprise before 10.9 allows remote authenticated users to inje…

Fix: 10.9+
Fix from $1,600 2021-04-08
Arcgis Engine HIGH 7.8
CVE-2021-29097

Multiple buffer overflow vulnerabilities when parsing a specially crafted file in Esri ArcReader, ArcGIS Desktop, ArcGIS Engine 10.8.1 (and earlier) …

Fix: after 10.8.1
Fix from $1,950 2021-03-25
Arcgis Engine HIGH 7.8
CVE-2021-29098

Multiple uninitialized pointer vulnerabilities when parsing a specially crafted file in Esri ArcReader, ArcGIS Desktop, ArcGIS Engine 10.8.1 (and ear…

Fix: after 10.8.1
Fix from $1,950 2021-03-25
Arcgis Server MEDIUM 6.8
CVE-2021-29093

A use-after-free vulnerability when parsing a specially crafted file in Esri ArcGIS Server 10.8.1 (and earlier) allows an authenticated attacker with…

Fix: after 10.8.1
Fix from $1,600 2021-03-25
Arcgis Server MEDIUM 6.8
CVE-2021-29094

Multiple buffer overflow vulnerabilities when parsing a specially crafted file in Esri ArcGIS Server 10.8.1 (and earlier) allows an authenticated att…

Fix: after 10.8.1
Fix from $1,600 2021-03-25
Arcgis Server MEDIUM 6.8
CVE-2021-29095

Multiple uninitialized pointer vulnerabilities when parsing a specially crafted file in Esri ArcGIS Server 10.8.1 (and earlier) allows an authenticat…

Fix: after 10.8.1
Fix from $1,600 2021-03-25
Arcgis Engine HIGH 7.8
CVE-2021-29096

A use-after-free vulnerability when parsing a specially crafted file in Esri ArcReader, ArcGIS Desktop, ArcGIS Engine 10.8.1 (and earlier) and ArcGIS…

Fix: after 10.8.1
Fix from $1,950 2021-03-25
Arcgis Server CRITICAL 9.8
CVE-2020-35712

Esri ArcGIS Server before 10.8 is vulnerable to SSRF in some configurations.

Fix: 10.8+
Fix from $2,300 2020-12-26
Arcgis Enterprise MEDIUM 5.4
CVE-2019-16193

In ArcGIS Enterprise 10.6.1, a crafted IFRAME element can be used to trigger a Cross Frame Scripting (XFS) attack through the EDIT MY PROFILE feature.

Mitigation only
Fix from $1,600 2019-09-11
Arcgisruntime Sdk CRITICAL 9.8
CVE-2015-2002

The ESRI ArcGis Runtime SDK before 10.2.6-2 for Android might allow attackers to execute arbitrary code by leveraging a finalize method in a Serializ…

Fix: 10.2.6-2+
Fix from $2,300 2018-03-29
Arcgis Server MEDIUM 5.8
CVE-2014-5122

Open redirect vulnerability in ESRI ArcGIS for Server 10.1.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing at…

No fix yet
Fix from $1,600 2014-08-22
Arcgis Server HIGH 7.5
CVE-2013-7232

SQL injection vulnerability in ESRI ArcGIS for Server through 10.2 allows remote attackers to execute arbitrary SQL commands via unspecified input to…

Fix: after 10.2
Fix from $1,950 2013-12-30
Arcgis Server MEDIUM 6.5
CVE-2012-4949

SQL injection vulnerability in ESRI ArcGIS 10.1 allows remote authenticated users to execute arbitrary SQL commands via the where parameter to a quer…

Mitigation only
Fix from $1,600 2012-11-14
Arcmap HIGH 9.3
CVE-2012-1661EPSS 24%

ESRI ArcMap 9 and ArcGIS 10.0.2.3200 and earlier does not properly prompt users before executing embedded VBA macros, which allows user-assisted remo…

Fix: after 10.0.2.3200
Fix from $1,950 2012-07-12
Arcsde HIGH 7.5
CVE-2007-4278

Stack-based buffer overflow in the giomgr process in ESRI ArcSDE service 9.2, as used with ArcGIS, allows remote attackers to cause a denial of servi…

Mitigation only
Fix from $1,950 2007-08-15
Arcsde HIGH 10.0
CVE-2007-1770EPSS 17%

Buffer overflow in the ArcSDE service (giomgr) in Environmental Systems Research Institute (ESRI) ArcGIS before 9.2 Service Pack 2, when using three …

Mitigation only
Fix from $1,950 2007-03-30
Arcpad MEDIUM 5.0
CVE-2006-0089

Buffer overflow in ESRI ArcPad 7.0.0.156 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code…

Fix: after 7.0.0.156
Fix from $1,600 2006-01-05