Show filters
33 Total Results
Displaying 21-30 of 33
Sort by:
Attacker Value
Unknown

CVE-2021-29101

Disclosure Date: May 03, 2021 (last updated February 22, 2025)
ArcGIS GeoEvent Server versions 10.8.1 and below has a read-only directory path traversal vulnerability that could allow an unauthenticated, remote attacker to perform directory traversal attacks and read arbitrary files on the system.
Attacker Value
Unknown

CVE-2021-29095

Disclosure Date: March 16, 2021 (last updated February 22, 2025)
Multiple uninitialized pointer vulnerabilities when parsing a specially crafted file in Esri ArcGIS Server 10.8.1 (and earlier) allows an authenticated attacker with specialized permissions to achieve arbitrary code execution in the context of the service account.
Attacker Value
Unknown

CVE-2021-29093

Disclosure Date: March 16, 2021 (last updated February 22, 2025)
A use-after-free vulnerability when parsing a specially crafted file in Esri ArcGIS Server 10.8.1 (and earlier) allows an authenticated attacker with specialized permissions to achieve arbitrary code execution in the context of the service account.
Attacker Value
Unknown

CVE-2021-29094

Disclosure Date: March 16, 2021 (last updated February 22, 2025)
Multiple buffer overflow vulnerabilities when parsing a specially crafted file in Esri ArcGIS Server 10.8.1 (and earlier) allows an authenticated attacker with specialized permissions to achieve arbitrary code execution in the context of the service account.
Attacker Value
Unknown

CVE-2020-35712

Disclosure Date: December 26, 2020 (last updated February 22, 2025)
Esri ArcGIS Server before 10.8 is vulnerable to SSRF in some configurations.
Attacker Value
Unknown

CVE-2014-9741

Disclosure Date: July 08, 2015 (last updated May 22, 2024)
Multiple cross-site scripting (XSS) vulnerabilities in ESRI ArcGIS for Desktop, ArcGIS for Engine, and ArcGIS for Server 10.2.2 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2014-5122

Disclosure Date: August 22, 2014 (last updated May 22, 2024)
Open redirect vulnerability in ESRI ArcGIS for Server 10.1.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via an unspecified parameter, related to login.
0
Attacker Value
Unknown

CVE-2014-5121

Disclosure Date: August 22, 2014 (last updated May 22, 2024)
Multiple cross-site scripting (XSS) vulnerabilities in ESRI ArcGIS for Server 10.1.1 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters.
0
Attacker Value
Unknown

CVE-2013-5222

Disclosure Date: December 30, 2013 (last updated July 12, 2024)
Multiple cross-site scripting (XSS) vulnerabilities in ESRI ArcGIS for Server 10.1 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2013-7232

Disclosure Date: December 30, 2013 (last updated July 12, 2024)
SQL injection vulnerability in ESRI ArcGIS for Server through 10.2 allows remote attackers to execute arbitrary SQL commands via unspecified input to the map or feature service.
0