Esri

Arcgis Pro

6 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.01%
  • Veröffentlicht 26.01.2026 17:24:12
  • Zuletzt bearbeitet 13.02.2026 19:41:55

There is a Cross‑Site Scripting (XSS) issue in Esri ArcGIS Pro versions 3.6.0 and earlier. ArcGIS Pro is a desktop application, and exploitation is limited to local users interacting with the application; no privileged role or elevated permissions ar...

  • EPSS 0.03%
  • Veröffentlicht 25.02.2025 17:15:13
  • Zuletzt bearbeitet 04.03.2025 17:37:53

There is an untrusted search path vulnerability in Esri ArcGIS Pro 3.3 and 3.4 that may allow a low privileged attacker with write privileges to the local file system to introduce a malicious executable to the filesystem. When the victim performs a s...

  • EPSS 0.03%
  • Veröffentlicht 25.02.2025 17:15:13
  • Zuletzt bearbeitet 04.03.2025 17:37:41

There is an untrusted search path vulnerability in Esri ArcGIS AllSource 1.2 and 1.3 that may allow a low privileged attacker with write privileges to the local file system to introduce a malicious executable to the filesystem. When the victim perfor...

  • EPSS 0.44%
  • Veröffentlicht 25.03.2021 21:15:13
  • Zuletzt bearbeitet 21.11.2024 06:00:42

Multiple buffer overflow vulnerabilities when parsing a specially crafted file in Esri ArcReader, ArcGIS Desktop, ArcGIS Engine 10.8.1 (and earlier) and ArcGIS Pro 2.7 (and earlier) allow an unauthenticated attacker to achieve arbitrary code executio...

  • EPSS 0.46%
  • Veröffentlicht 25.03.2021 21:15:13
  • Zuletzt bearbeitet 05.05.2025 14:12:43

Multiple uninitialized pointer vulnerabilities when parsing a specially crafted file in Esri ArcReader, ArcGIS Desktop, ArcGIS Engine 10.8.1 (and earlier) and ArcGIS Pro 2.7 (and earlier) allow an unauthenticated attacker to achieve arbitrary code ex...

  • EPSS 0.28%
  • Veröffentlicht 25.03.2021 19:15:14
  • Zuletzt bearbeitet 21.11.2024 06:00:42

A use-after-free vulnerability when parsing a specially crafted file in Esri ArcReader, ArcGIS Desktop, ArcGIS Engine 10.8.1 (and earlier) and ArcGIS Pro 2.7 (and earlier) allows an unauthenticated attacker to achieve arbitrary code execution in the ...