Vulnerabilities > Esri

DATE CVE VULNERABILITY TITLE RISK
2019-09-11 CVE-2019-16193 Cross-site Scripting vulnerability in Esri Arcgis Enterprise 10.6.1
In ArcGIS Enterprise 10.6.1, a crafted IFRAME element can be used to trigger a Cross Frame Scripting (XFS) attack through the EDIT MY PROFILE feature.
network
low complexity
esri CWE-79
5.4
2018-03-29 CVE-2015-2002 Range Error vulnerability in Esri Arcgisruntime SDK
The ESRI ArcGis Runtime SDK before 10.2.6-2 for Android might allow attackers to execute arbitrary code by leveraging a finalize method in a Serializable class that improperly passes an attacker-controlled pointer to a native function.
network
low complexity
esri CWE-118
critical
9.8