esri

168 tracked vulnerabilities.

CVE-2021-29118 MEDIUM
Esri ArcReader < 10.8.1 - Unauthenticated Out-of-bounds Read via Crafted File
Aug 12, 2022
CVSS 5.5
EPSS 0.00
CVE-2021-29117 HIGH
Esri ArcReader < 10.8.1 - Use-After-Free via Crafted File Parsing
Aug 12, 2022
CVSS 7.8
EPSS 0.00
CVE-2021-29112 MEDIUM
Esri ArcReader < 10.8.1 - Unauthenticated Out-of-bounds Read via Crafted File
Aug 12, 2022
CVSS 5.5
EPSS 0.00
CVE-2021-29116 MEDIUM
Esri ArcGIS Server 10.8.1 and 10.9 - Unauthenticated Stored Cross-Site Scripting via Feature Service Queries
Dec 07, 2021
CVSS 6.1
EPSS 0.00
CVE-2021-29115 MEDIUM
Esri ArcGIS Enterprise < 10.9 - Information Disclosure via ArcGIS Service Directory
Dec 07, 2021
CVSS 5.3
EPSS 0.01
CVE-2021-29114 CRITICAL
Esri ArcGIS Server < 10.9.0 - Unauthenticated SQL Injection via Feature Service Queries
Dec 07, 2021
CVSS 9.8
EPSS 0.00
CVE-2021-29113 MEDIUM
ArcGIS Server < 10.9.0 - Unauthenticated Remote File Inclusion in Help Documentation
Dec 07, 2021
CVSS 4.7
EPSS 0.00
CVE-2021-29110 MEDIUM
Esri Portal for ArcGIS < 10.9 - Unauthenticated Stored Cross-Site Scripting in Home Application
Oct 01, 2021
CVSS 5.4
EPSS 0.00
CVE-2021-29109 MEDIUM
Esri Portal for ArcGIS < 10.9 - Reflected Cross-Site Scripting
Oct 01, 2021
CVSS 6.1
EPSS 0.00
CVE-2021-29108 HIGH
Esri Portal for ArcGIS < 10.9 - Authenticated Privilege Escalation via SAML Assertion XML Signature Wrapping
Oct 01, 2021
CVSS 8.8
EPSS 0.00
CVE-2021-29105 MEDIUM
Esri ArcGIS Server < 10.9.0 - Authenticated Stored Cross-Site Scripting
Jul 11, 2021
CVSS 5.4
EPSS 0.00
CVE-2021-29104 MEDIUM
ArcGIS Server < 10.9.0 - Unauthenticated Stored Cross-Site Scripting
Jul 11, 2021
CVSS 6.1
EPSS 0.01
CVE-2021-29103 MEDIUM
ArcGIS Server < 10.9.0 - Reflected Cross-Site Scripting
Jul 11, 2021
CVSS 6.1
EPSS 0.00
CVE-2021-29102 CRITICAL
ArcGIS Server < 10.9.0 - Unauthenticated Server-Side Request Forgery
Jul 11, 2021
CVSS 9.1
EPSS 0.01
CVE-2021-29107 MEDIUM
ArcGIS Server Manager <= 10.8.1 - Unauthenticated Stored Cross-Site Scripting
Jul 10, 2021
CVSS 6.1
EPSS 0.01
CVE-2021-29106 MEDIUM
Esri ArcGIS Server < 10.9.0 - Reflected Cross-Site Scripting
Jul 10, 2021
CVSS 6.1
EPSS 0.00
CVE-2021-29099 MEDIUM
ArcGIS Server < 10.8.1 - SQL Injection
Jun 07, 2021
CVSS 5.3
EPSS 0.00
CVE-2021-29101 HIGH
ArcGIS GeoEvent Server <= 10.8.1 - Unauthenticated Path Traversal
May 05, 2021
CVSS 7.5
EPSS 0.02
CVE-2021-29100 HIGH
Esri ArcGIS Earth < 1.11.0 - Path Traversal and Arbitrary File Write via Crafted File Upload
May 05, 2021
CVSS 7.8
EPSS 0.00
CVE-2021-3012 MEDIUM
ESRI ArcGIS Enterprise < 10.9 - Authenticated Stored Cross-Site Scripting via Document Link URL Parameter
Apr 08, 2021
CVSS 5.4
EPSS 0.00
CVE-2021-29098 HIGH
Esri ArcGIS Engine/Pro/Map/Reader < 10.8.1/2.7 - RCE via Crafted File
Mar 25, 2021
CVSS 7.8
EPSS 0.00
CVE-2021-29097 HIGH
Esri ArcGIS Engine/Pro/Map/Reader < 10.8.1/2.7 - Unauthenticated Buffer Overflow via Crafted File
Mar 25, 2021
CVSS 7.8
EPSS 0.00
CVE-2021-29095 MEDIUM
Esri ArcGIS Server < 10.8.1 - Authenticated Arbitrary Code Execution via Crafted File Parsing
Mar 25, 2021
CVSS 6.8
EPSS 0.00
CVE-2021-29094 MEDIUM
Esri ArcGIS Server < 10.8.1 - Authenticated Remote Code Execution via Crafted File Parsing
Mar 25, 2021
CVSS 6.8
EPSS 0.01
CVE-2021-29093 MEDIUM
Esri ArcGIS Server < 10.8.1 - Authenticated Use-After-Free via Crafted File Parsing
Mar 25, 2021
CVSS 6.8
EPSS 0.00