Vulnerabilities > Esri > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-03-25 | CVE-2021-29094 | Classic Buffer Overflow vulnerability in Esri Arcgis Server Multiple buffer overflow vulnerabilities when parsing a specially crafted file in Esri ArcGIS Server 10.8.1 (and earlier) allows an authenticated attacker with specialized permissions to achieve arbitrary code execution in the context of the service account. | 6.8 |
2021-03-25 | CVE-2021-29093 | Use After Free vulnerability in Esri Arcgis Server A use-after-free vulnerability when parsing a specially crafted file in Esri ArcGIS Server 10.8.1 (and earlier) allows an authenticated attacker with specialized permissions to achieve arbitrary code execution in the context of the service account. | 6.8 |
2019-09-11 | CVE-2019-16193 | Cross-site Scripting vulnerability in Esri Arcgis Enterprise 10.6.1 In ArcGIS Enterprise 10.6.1, a crafted IFRAME element can be used to trigger a Cross Frame Scripting (XFS) attack through the EDIT MY PROFILE feature. | 5.4 |