Vulnerability index

Browse CVEs

121 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.3 CVE-2021-29115 An information disclosure vulnerability in the ArcGIS Service Directory in Esri ArcGIS Enterprise versions 10.9.0 and below may allows a remote attac… Arcgis Enterprise after 10.9 Fix from $1,6002021-12-07 HIGH 8.8 CVE-2021-29108 There is an privilege escalation vulnerability in organization-specific logins in Esri Portal for ArcGIS versions 10.9 and below that may allow a rem… Portal For Arcgis after 10.9 Fix from $1,9502021-10-01 MEDIUM 6.1 CVE-2021-29109 A reflected XSS vulnerability in Esri Portal for ArcGIS version 10.9 and below may allow a remote attacker able to convince a user to click on a craf… Portal For Arcgis after 10.9 Fix from $1,6002021-10-01 MEDIUM 5.4 CVE-2021-29110 Stored cross-site scripting (XSS) issue in Esri Portal for ArcGIS may allow a remote unauthenticated attacker to pass and store malicious strings in … Portal For Arcgis after 10.9 Fix from $1,6002021-10-01 CRITICAL 9.1 CVE-2021-29102 A Server-Side Request Forgery (SSRF) vulnerability in ArcGIS Server Manager version 10.8.1 and below may allow a remote, unauthenticated attacker to … Arcgis Server 10.9.0+ Fix from $2,3002021-07-11 MEDIUM 6.1 CVE-2021-29103 A reflected Cross Site Scripting (XXS) vulnerability in ArcGIS Server version 10.8.1 and below may allow a remote attacker able to convince a user to… Arcgis Server 10.9.0+ Fix from $1,6002021-07-11 MEDIUM 6.1 CVE-2021-29104 A stored Cross Site Scripting (XXS) vulnerability in ArcGIS Server Manager version 10.8.1 and below may allow a remote unauthenticated attacker to pa… Arcgis Server 10.9.0+ Fix from $1,6002021-07-11 MEDIUM 5.4 CVE-2021-29105 A stored Cross Site Scripting (XSS) vulnerability in Esri ArcGIS Server Services Directory version 10.8.1 and below may allow a remote authenticated … Arcgis Server 10.9.0+ Fix from $1,6002021-07-11 MEDIUM 6.1 CVE-2021-29106 A reflected Cross Site Scripting (XSS) vulnerability in Esri ArcGIS Server version 10.8.1 and below may allow a remote attacker able to convince a us… Arcgis Server 10.9.0+ Fix from $1,6002021-07-10 MEDIUM 6.1 CVE-2021-29107 A stored Cross Site Scripting (XXS) vulnerability in ArcGIS Server Manager version 10.8.1 and below may allow a remote unauthenticated attacker to pa… Arcgis Server Mitigation only Fix from $1,6002021-07-10 MEDIUM 5.3 CVE-2021-29099 A SQL injection vulnerability exists in some configurations of ArcGIS Server versions 10.8.1 and earlier. Specially crafted web requests can expose i… Arcgis Server after 10.8.1 Fix from $1,6002021-06-07 HIGH 7.5 CVE-2021-29101 ArcGIS GeoEvent Server versions 10.8.1 and below has a read-only directory path traversal vulnerability that could allow an unauthenticated, remote a… Arcgis Geoevent Server after 10.8.1 Fix from $1,9502021-05-05 HIGH 7.8 CVE-2021-29100 A path traversal vulnerability exists in Esri ArcGIS Earth versions 1.11.0 and below which allows arbitrary file creation on an affected system throu… Arcgis Earth after 1.11.0 Fix from $1,9502021-05-05 MEDIUM 5.4 CVE-2021-3012 A cross-site scripting (XSS) vulnerability in the Document Link of documents in ESRI Enterprise before 10.9 allows remote authenticated users to inje… Arcgis Enterprise 10.9+ Fix from $1,6002021-04-08 HIGH 7.8 CVE-2021-29097 Multiple buffer overflow vulnerabilities when parsing a specially crafted file in Esri ArcReader, ArcGIS Desktop, ArcGIS Engine 10.8.1 (and earlier) … Arcgis Engine after 10.8.1 Fix from $1,9502021-03-25 HIGH 7.8 CVE-2021-29098 Multiple uninitialized pointer vulnerabilities when parsing a specially crafted file in Esri ArcReader, ArcGIS Desktop, ArcGIS Engine 10.8.1 (and ear… Arcgis Engine after 10.8.1 Fix from $1,9502021-03-25 MEDIUM 6.8 CVE-2021-29093 A use-after-free vulnerability when parsing a specially crafted file in Esri ArcGIS Server 10.8.1 (and earlier) allows an authenticated attacker with… Arcgis Server after 10.8.1 Fix from $1,6002021-03-25 MEDIUM 6.8 CVE-2021-29094 Multiple buffer overflow vulnerabilities when parsing a specially crafted file in Esri ArcGIS Server 10.8.1 (and earlier) allows an authenticated att… Arcgis Server after 10.8.1 Fix from $1,6002021-03-25 MEDIUM 6.8 CVE-2021-29095 Multiple uninitialized pointer vulnerabilities when parsing a specially crafted file in Esri ArcGIS Server 10.8.1 (and earlier) allows an authenticat… Arcgis Server after 10.8.1 Fix from $1,6002021-03-25 HIGH 7.8 CVE-2021-29096 A use-after-free vulnerability when parsing a specially crafted file in Esri ArcReader, ArcGIS Desktop, ArcGIS Engine 10.8.1 (and earlier) and ArcGIS… Arcgis Engine after 10.8.1 Fix from $1,9502021-03-25 CRITICAL 9.8 CVE-2020-35712 Esri ArcGIS Server before 10.8 is vulnerable to SSRF in some configurations. Arcgis Server 10.8+ Fix from $2,3002020-12-26 MEDIUM 5.4 CVE-2019-16193 In ArcGIS Enterprise 10.6.1, a crafted IFRAME element can be used to trigger a Cross Frame Scripting (XFS) attack through the EDIT MY PROFILE feature. Arcgis Enterprise Mitigation only Fix from $1,6002019-09-11 CRITICAL 9.8 CVE-2015-2002 The ESRI ArcGis Runtime SDK before 10.2.6-2 for Android might allow attackers to execute arbitrary code by leveraging a finalize method in a Serializ… Arcgisruntime Sdk 10.2.6-2+ Fix from $2,3002018-03-29 MEDIUM 5.8 CVE-2014-5122 Open redirect vulnerability in ESRI ArcGIS for Server 10.1.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing at… Arcgis Server No fix yet Fix from $1,6002014-08-22 HIGH 7.5 CVE-2013-7232 SQL injection vulnerability in ESRI ArcGIS for Server through 10.2 allows remote attackers to execute arbitrary SQL commands via unspecified input to… Arcgis Server after 10.2 Fix from $1,9502013-12-30 MEDIUM 6.5 CVE-2012-4949 SQL injection vulnerability in ESRI ArcGIS 10.1 allows remote authenticated users to execute arbitrary SQL commands via the where parameter to a quer… Arcgis Server Mitigation only Fix from $1,6002012-11-14 HIGH 9.3 CVE-2012-1661EPSS 24% ESRI ArcMap 9 and ArcGIS 10.0.2.3200 and earlier does not properly prompt users before executing embedded VBA macros, which allows user-assisted remo… Arcmap after 10.0.2.3200 Fix from $1,9502012-07-12 HIGH 7.5 CVE-2007-4278 Stack-based buffer overflow in the giomgr process in ESRI ArcSDE service 9.2, as used with ArcGIS, allows remote attackers to cause a denial of servi… Arcsde Mitigation only Fix from $1,9502007-08-15 HIGH 10.0 CVE-2007-1770EPSS 17% Buffer overflow in the ArcSDE service (giomgr) in Environmental Systems Research Institute (ESRI) ArcGIS before 9.2 Service Pack 2, when using three … Arcsde Mitigation only Fix from $1,9502007-03-30 MEDIUM 5.0 CVE-2006-0089 Buffer overflow in ESRI ArcPad 7.0.0.156 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code… Arcpad after 7.0.0.156 Fix from $1,6002006-01-05