Show filters
109 Total Results
Displaying 61-70 of 109
Sort by:
Attacker Value
Unknown

CVE-2022-38192

Disclosure Date: June 28, 2022 (last updated February 24, 2025)
A stored Cross Site Scripting (XSS) vulnerability in Esri Portal for ArcGIS may allow a remote, authenticated attacker to pass and store malicious strings via crafted queries which when accessed could potentially execute arbitrary JavaScript code in the user’s browser.
Attacker Value
Unknown

CVE-2022-38191

Disclosure Date: June 28, 2022 (last updated February 24, 2025)
There is an HTML injection issue in Esri Portal for ArcGIS versions 10.9.0 and below which may allow a remote, authenticated attacker to inject HTML into some locations in the home application.
Attacker Value
Unknown

CVE-2022-38190

Disclosure Date: June 28, 2022 (last updated February 24, 2025)
A stored Cross Site Scripting (XSS) vulnerability in Esri Portal for ArcGIS configurable apps may allow a remote, unauthenticated attacker to pass and store malicious strings via crafted queries which when accessed could potentially execute arbitrary JavaScript code in the user’s browser
Attacker Value
Unknown

CVE-2022-38188

Disclosure Date: June 28, 2022 (last updated February 24, 2025)
There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.9.1 which may allow a remote attacker able to convince a user to click on a crafted link which could potentially execute arbitrary JavaScript code in the victim’s browser.
Attacker Value
Unknown

CVE-2022-38186

Disclosure Date: June 28, 2022 (last updated February 24, 2025)
There is a reflected XSS vulnerability in Esri Portal for ArcGIS versions 10.8.1 and below which may allow a remote attacker able to convince a user to click on a crafted link which could potentially execute arbitrary JavaScript code in the victim’s browser.
Attacker Value
Unknown

CVE-2022-38184

Disclosure Date: June 28, 2022 (last updated February 24, 2025)
There is an improper access control vulnerability in Portal for ArcGIS versions 10.8.1 and below which could allow a remote, unauthenticated attacker to access an API that may induce Esri Portal for ArcGIS to read arbitrary URLs.
Attacker Value
Unknown

CVE-2021-29117

Disclosure Date: February 07, 2022 (last updated February 24, 2025)
A use-after-free vulnerability when parsing a specially crafted file in Esri ArcReader 10.8.1 (and earlier) allows an unauthenticated attacker to achieve arbitrary code execution in the context of the current user.
Attacker Value
Unknown

CVE-2021-29118

Disclosure Date: February 07, 2022 (last updated February 24, 2025)
An out-of-bounds read vulnerability exists when parsing a specially crafted file in Esri ArcReader 10.8.1 (and earlier) which allow an unauthenticated attacker to induce an information disclosure issue in the context of the current user.
Attacker Value
Unknown

CVE-2021-29112

Disclosure Date: February 07, 2022 (last updated February 24, 2025)
An out-of-bounds read vulnerability exists when parsing a specially crafted file in Esri ArcReader 10.8.1 (and earlier) which allow an unauthenticated attacker to induce an information disclosure issue in the context of the current user.
Attacker Value
Unknown

CVE-2021-29115

Disclosure Date: December 06, 2021 (last updated February 23, 2025)
An information disclosure vulnerability in the ArcGIS Service Directory in Esri ArcGIS Enterprise versions 10.9.0 and below may allows a remote attacker to view hidden field names in feature layers. This issue may reveal field names, but not not disclose features.