CVE-2021-29093 – ArcGIS Server image service and raster analytics security update: use-after-free
https://notcve.org/view.php?id=CVE-2021-29093
A use-after-free vulnerability when parsing a specially crafted file in Esri ArcGIS Server 10.8.1 (and earlier) allows an authenticated attacker with specialized permissions to achieve arbitrary code execution in the context of the service account. Una vulnerabilidad de uso de la memoria previamente liberada cuando se analiza un archivo especialmente diseñado en Esri ArcGIS Server versiones 10.8.1 (y anteriores), permite a un atacante autenticado con permisos especializados lograr una ejecución de código arbitrario en el contexto de la cuenta de servicio • https://www.esri.com/arcgis-blog/products/arcgis-enterprise/administration/security-advisory-server-image • CWE-416: Use After Free •
CVE-2020-35712
https://notcve.org/view.php?id=CVE-2020-35712
Esri ArcGIS Server before 10.8 is vulnerable to SSRF in some configurations. Esri ArcGIS Server versiones anteriores a 10.8, es susceptible a una vulnerabilidad de tipo SSRF en algunas configuraciones • https://support.esri.com/en/bugs/nimbus/QlVHLTAwMDEyODA2MA== https://support.esri.com/en/technical-article/000022931 • CWE-918: Server-Side Request Forgery (SSRF) •
CVE-2014-9741
https://notcve.org/view.php?id=CVE-2014-9741
Multiple cross-site scripting (XSS) vulnerabilities in ESRI ArcGIS for Desktop, ArcGIS for Engine, and ArcGIS for Server 10.2.2 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. Múltiples vulnerabilidades de XSS en ESRI ArcGIS Desktop, ArcGIS Engine, y ArcGIS Server 10.2.2 y anteriores permiten a atacantes remotos inyectar secuencias de comandos web arbitrarios o HTML a través de vectores no especificados. • http://blogs.esri.com/esri/arcgis/2014/09/04/arcgis-for-server-security-patch-10-1-sp1-qip-10-2-1-10-2-2 http://support.esri.com/en/downloads/patches-servicepacks/view/productid/67/metaid/2223 http://www.securitytracker.com/id/1032733 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2014-5122
https://notcve.org/view.php?id=CVE-2014-5122
Open redirect vulnerability in ESRI ArcGIS for Server 10.1.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via an unspecified parameter, related to login. Vulnerabilidad de redirreción abierta en ESRI ArcGIS for Server 10.1.1 permite a atacantes remotos redirigir usuarios hacia sitios web arbitrarios y realizar ataques de phishing a través de un parámetro no especificado, relacionado con el inicio de sesión. • http://packetstormsecurity.com/files/127959/ArcGIS-For-Server-10.1.1-XSS-Open-Redirect.html http://www.securityfocus.com/archive/1/533189/100/0/threaded http://www.securityfocus.com/bid/69341 http://www.securitytracker.com/id/1030752 •
CVE-2014-5121
https://notcve.org/view.php?id=CVE-2014-5121
Multiple cross-site scripting (XSS) vulnerabilities in ESRI ArcGIS for Server 10.1.1 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters. Múltiples vulnerabilidades de XSS en ESRI ArcGIS for Server 10.1.1 permiten a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios a través de parámetros no especificados. • http://packetstormsecurity.com/files/127959/ArcGIS-For-Server-10.1.1-XSS-Open-Redirect.html http://www.securityfocus.com/archive/1/533189/100/0/threaded http://www.securitytracker.com/id/1030752 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •