← Back

Esri

esri

169 CVEs • 18 products

Products (18)

Click to collapse
Toggle

CVEs (169)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Esri
1Arcgis Server
Apr 29, 2026
Dec 30, 2013
N/A· v4
N/A· v3
3.5 LOW· v2
Multiple cross-site scripting (XSS) vulnerabilities in ESRI ArcGIS for Server 10.1 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
1Esri
1Arcgis Server
Apr 29, 2026
Sep 24, 2013
N/A· v4
N/A· v3
3.5 LOW· v2
The mobile-upload feature in Esri ArcGIS for Server 10.1 through 10.2 allows remote authenticated users to upload .exe files by leveraging (1) publisher or (2) administrator privileges.
1Esri
1Arcgis Server
Apr 29, 2026
Nov 14, 2012
N/A· v4
N/A· v3
6.5 MEDIUM· v2
SQL injection vulnerability in ESRI ArcGIS 10.1 allows remote authenticated users to execute arbitrary SQL commands via the where parameter to a query URI for a REST service.
1Esri
1Arcmap
Apr 29, 2026
Jul 12, 2012
N/A· v4
N/A· v3
9.3 HIGH· v2
ESRI ArcMap 9 and ArcGIS 10.0.2.3200 and earlier does not properly prompt users before executing embedded VBA macros, which allows user-assisted remote attackers to execute arbitrary VBA code via a crafted map (.mxd) fil...Show more
ESRI ArcMap 9 and ArcGIS 10.0.2.3200 and earlier does not properly prompt users before executing embedded VBA macros, which allows user-assisted remote attackers to execute arbitrary VBA code via a crafted map (.mxd) file.Show less
1Esri
1Arcsde
Apr 23, 2026
Aug 15, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
Stack-based buffer overflow in the giomgr process in ESRI ArcSDE service 9.2, as used with ArcGIS, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large number that...Show more
Stack-based buffer overflow in the giomgr process in ESRI ArcSDE service 9.2, as used with ArcGIS, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large number that requires more than 8 bytes to represent in ASCII, which triggers the overflow in an sprintf function call.Show less
1Esri
1Arcsde
Apr 23, 2026
Mar 30, 2007
N/A· v4
N/A· v3
10.0 HIGH· v2
Buffer overflow in the ArcSDE service (giomgr) in Environmental Systems Research Institute (ESRI) ArcGIS before 9.2 Service Pack 2, when using three tiered ArcSDE configurations, allows remote attackers to cause a denial...Show more
Buffer overflow in the ArcSDE service (giomgr) in Environmental Systems Research Institute (ESRI) ArcGIS before 9.2 Service Pack 2, when using three tiered ArcSDE configurations, allows remote attackers to cause a denial of service (giomgr crash) and execute arbitrary code via long parameters in crafted requests.Show less
1Esri
1Arcpad
Apr 16, 2026
Jan 5, 2006
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Buffer overflow in ESRI ArcPad 7.0.0.156 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a .amp file with a COORDSYS tag with a long string attribute.
1Esri
1Arcinfo Workstation
Apr 16, 2026
May 3, 2005
N/A· v4
N/A· v3
7.2 HIGH· v2
Format string vulnerability in ArcGIS for ESRI ArcInfo Workstation 9.0 allows local users to gain privileges via format string specifiers in the ARCHOME environment variable to (1) wservice or (2) lockmgr.
1Esri
1Arcinfo Workstation
Apr 16, 2026
May 3, 2005
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Multiple buffer overflows in ArcGIS for ESRI ArcInfo Workstation 9.0 allow local users to execute arbitrary code via long command line arguments to (1) asmaster, (2) asuser, (3) asutility, (4) se, or (5) asrecovery.