Osgeo

Mapserver

18 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 11.5%
  • Veröffentlicht 23.10.2009 18:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Multiple heap-based buffer underflows in the readPostBody function in cgiutil.c in mapserv in MapServer 4.x through 4.10.4 and 5.x before 5.4.2 allow remote attackers to execute arbitrary code via (1) a crafted Content-Length HTTP header or (2) a lar...

Exploit
  • EPSS 8.32%
  • Veröffentlicht 31.03.2009 18:24:45
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Stack-based buffer overflow in mapserv.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2, when the server has a map with a long IMAGEPATH or NAME attribute, allows remote attackers to execute arbitrary code via a crafted id parameter i...

Exploit
  • EPSS 1.52%
  • Veröffentlicht 31.03.2009 18:24:45
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Multiple stack-based buffer overflows in maptemplate.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 have unknown impact and remote attack vectors.

Exploit
  • EPSS 2.03%
  • Veröffentlicht 31.03.2009 18:24:45
  • Zuletzt bearbeitet 09.04.2025 00:30:58

mapserv.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 does not ensure that the string holding the id parameter ends in a '\0' character, which allows remote attackers to conduct buffer-overflow attacks or have unspecified other imp...

  • EPSS 1.03%
  • Veröffentlicht 31.03.2009 18:24:45
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The msLoadQuery function in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 allows remote attackers to determine the existence of arbitrary files via a full pathname in the queryfile parameter, which triggers different error messages depe...

Exploit
  • EPSS 0.83%
  • Veröffentlicht 31.03.2009 18:24:45
  • Zuletzt bearbeitet 09.04.2025 00:30:58

mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 allows remote attackers to read arbitrary invalid .map files via a full pathname in the map parameter, which triggers the display of partial file contents within an error message, as demonst...

Exploit
  • EPSS 0.79%
  • Veröffentlicht 31.03.2009 18:24:45
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Directory traversal vulnerability in mapserv.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2, when running on Windows with Cygwin, allows remote attackers to create arbitrary files via a .. (dot dot) in the id parameter.

Exploit
  • EPSS 2.7%
  • Veröffentlicht 31.03.2009 18:24:45
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Heap-based buffer underflow in the readPostBody function in cgiutil.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 allows remote attackers to have an unknown impact via a negative value in the Content-Length HTTP header.