Show filters
109 Total Results
Displaying 61-70 of 109
Sort by:
Attacker Value
Unknown
CVE-2022-38192
Disclosure Date: June 28, 2022 (last updated February 24, 2025)
A stored Cross Site Scripting (XSS) vulnerability in Esri Portal for ArcGIS may allow a remote, authenticated attacker to pass and store malicious strings via crafted queries which when accessed could potentially execute arbitrary JavaScript code in the user’s browser.
0
Attacker Value
Unknown
CVE-2022-38191
Disclosure Date: June 28, 2022 (last updated February 24, 2025)
There is an HTML injection issue in Esri Portal for ArcGIS versions 10.9.0 and below which may allow a remote, authenticated attacker to inject HTML into some locations in the home application.
0
Attacker Value
Unknown
CVE-2022-38190
Disclosure Date: June 28, 2022 (last updated February 24, 2025)
A stored Cross Site Scripting (XSS) vulnerability in Esri Portal for ArcGIS configurable apps may allow a remote, unauthenticated attacker to pass and store malicious strings via crafted queries which when accessed could potentially execute arbitrary JavaScript code in the user’s browser
0
Attacker Value
Unknown
CVE-2022-38188
Disclosure Date: June 28, 2022 (last updated February 24, 2025)
There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1 which may allow a remote attacker able to convince a user to click on a crafted link which could potentially execute arbitrary JavaScript code in the victim’s browser.
0
Attacker Value
Unknown
CVE-2022-38186
Disclosure Date: June 28, 2022 (last updated February 24, 2025)
There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.8.1 and below which may allow a remote attacker able to convince a user to click on a crafted link which could potentially execute arbitrary JavaScript code in the victim’s browser.
0
Attacker Value
Unknown
CVE-2022-38184
Disclosure Date: June 28, 2022 (last updated February 24, 2025)
There is an improper access control vulnerability in Portal for ArcGIS versions 10.8.1 and below which could allow a remote, unauthenticated attacker to access an API that may induce Esri Portal for ArcGIS to read arbitrary URLs.
0
Attacker Value
Unknown
CVE-2021-29117
Disclosure Date: February 07, 2022 (last updated February 24, 2025)
A use-after-free vulnerability when parsing a specially crafted file in Esri ArcReader 10.8.1 (and earlier) allows an unauthenticated attacker to achieve arbitrary code execution in the context of the current user.
0
Attacker Value
Unknown
CVE-2021-29118
Disclosure Date: February 07, 2022 (last updated February 24, 2025)
An out-of-bounds read vulnerability exists when parsing a specially crafted file in Esri ArcReader 10.8.1 (and earlier) which allow an unauthenticated attacker to induce an information disclosure issue in the context of the current user.
0
Attacker Value
Unknown
CVE-2021-29112
Disclosure Date: February 07, 2022 (last updated February 24, 2025)
An out-of-bounds read vulnerability exists when parsing a specially crafted file in Esri ArcReader 10.8.1 (and earlier) which allow an unauthenticated attacker to induce an information disclosure issue in the context of the current user.
0
Attacker Value
Unknown
CVE-2021-29115
Disclosure Date: December 06, 2021 (last updated February 23, 2025)
An information disclosure vulnerability in the ArcGIS Service Directory in Esri ArcGIS Enterprise versions 10.9.0 and below may allows a remote attacker to view hidden field names in feature layers. This issue may reveal field names, but not not disclose features.
0