Vulnerabilities > Esri
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2019-09-11 | CVE-2019-16193 | Cross-site Scripting vulnerability in Esri Arcgis Enterprise 10.6.1 In ArcGIS Enterprise 10.6.1, a crafted IFRAME element can be used to trigger a Cross Frame Scripting (XFS) attack through the EDIT MY PROFILE feature. | 5.4 |
2018-03-29 | CVE-2015-2002 | Range Error vulnerability in Esri Arcgisruntime SDK The ESRI ArcGis Runtime SDK before 10.2.6-2 for Android might allow attackers to execute arbitrary code by leveraging a finalize method in a Serializable class that improperly passes an attacker-controlled pointer to a native function. | 9.8 |