- EPSS 11.5%
- Published 23.10.2009 18:30:00
- Last modified 09.04.2025 00:30:58
Multiple heap-based buffer underflows in the readPostBody function in cgiutil.c in mapserv in MapServer 4.x through 4.10.4 and 5.x before 5.4.2 allow remote attackers to execute arbitrary code via (1) a crafted Content-Length HTTP header or (2) a lar...
- EPSS 8.32%
- Published 31.03.2009 18:24:45
- Last modified 09.04.2025 00:30:58
Stack-based buffer overflow in mapserv.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2, when the server has a map with a long IMAGEPATH or NAME attribute, allows remote attackers to execute arbitrary code via a crafted id parameter i...
- EPSS 1.52%
- Published 31.03.2009 18:24:45
- Last modified 09.04.2025 00:30:58
Multiple stack-based buffer overflows in maptemplate.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 have unknown impact and remote attack vectors.
- EPSS 2.03%
- Published 31.03.2009 18:24:45
- Last modified 09.04.2025 00:30:58
mapserv.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 does not ensure that the string holding the id parameter ends in a '\0' character, which allows remote attackers to conduct buffer-overflow attacks or have unspecified other imp...
CVE-2009-0843
- EPSS 1.03%
- Published 31.03.2009 18:24:45
- Last modified 09.04.2025 00:30:58
The msLoadQuery function in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 allows remote attackers to determine the existence of arbitrary files via a full pathname in the queryfile parameter, which triggers different error messages depe...
CVE-2009-0842
- EPSS 0.83%
- Published 31.03.2009 18:24:45
- Last modified 09.04.2025 00:30:58
mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 allows remote attackers to read arbitrary invalid .map files via a full pathname in the map parameter, which triggers the display of partial file contents within an error message, as demonst...
- EPSS 0.79%
- Published 31.03.2009 18:24:45
- Last modified 09.04.2025 00:30:58
Directory traversal vulnerability in mapserv.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2, when running on Windows with Cygwin, allows remote attackers to create arbitrary files via a .. (dot dot) in the id parameter.
- EPSS 2.7%
- Published 31.03.2009 18:24:45
- Last modified 09.04.2025 00:30:58
Heap-based buffer underflow in the readPostBody function in cgiutil.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 allows remote attackers to have an unknown impact via a negative value in the Content-Length HTTP header.