Osgeo

Mapserver

22 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 7.65%
  • Veröffentlicht 01.08.2011 19:55:01
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Stack-based buffer overflow in MapServer before 4.10.7 and 5.x before 5.6.7 allows remote attackers to execute arbitrary code via vectors related to OGC filter encoding.

  • EPSS 1.57%
  • Veröffentlicht 01.08.2011 19:55:01
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Multiple SQL injection vulnerabilities in MapServer before 4.10.7, 5.x before 5.6.7, and 6.x before 6.0.1 allow remote attackers to execute arbitrary SQL commands via vectors related to (1) OGC filter encoding or (2) WMS time support.

  • EPSS 1.98%
  • Veröffentlicht 02.08.2010 22:00:01
  • Zuletzt bearbeitet 29.04.2026 01:13:23

mapserv.c in mapserv in MapServer before 4.10.6 and 5.x before 5.6.4 does not properly restrict the use of CGI command-line arguments that were intended for debugging, which allows remote attackers to have an unspecified impact via crafted arguments.

  • EPSS 0.06%
  • Veröffentlicht 02.08.2010 22:00:01
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Buffer overflow in the msTmpFile function in maputil.c in mapserv in MapServer before 4.10.6 and 5.x before 5.6.4 allows local users to cause a denial of service via vectors involving names of temporary files.

  • EPSS 11.5%
  • Veröffentlicht 23.10.2009 18:30:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

Multiple heap-based buffer underflows in the readPostBody function in cgiutil.c in mapserv in MapServer 4.x through 4.10.4 and 5.x before 5.4.2 allow remote attackers to execute arbitrary code via (1) a crafted Content-Length HTTP header or (2) a lar...

Exploit
  • EPSS 8.32%
  • Veröffentlicht 31.03.2009 18:24:45
  • Zuletzt bearbeitet 23.04.2026 00:35:47

Stack-based buffer overflow in mapserv.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2, when the server has a map with a long IMAGEPATH or NAME attribute, allows remote attackers to execute arbitrary code via a crafted id parameter i...

Exploit
  • EPSS 1.52%
  • Veröffentlicht 31.03.2009 18:24:45
  • Zuletzt bearbeitet 23.04.2026 00:35:47

Multiple stack-based buffer overflows in maptemplate.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 have unknown impact and remote attack vectors.

Exploit
  • EPSS 2.03%
  • Veröffentlicht 31.03.2009 18:24:45
  • Zuletzt bearbeitet 23.04.2026 00:35:47

mapserv.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 does not ensure that the string holding the id parameter ends in a '\0' character, which allows remote attackers to conduct buffer-overflow attacks or have unspecified other imp...

  • EPSS 1.03%
  • Veröffentlicht 31.03.2009 18:24:45
  • Zuletzt bearbeitet 23.04.2026 00:35:47

The msLoadQuery function in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 allows remote attackers to determine the existence of arbitrary files via a full pathname in the queryfile parameter, which triggers different error messages depe...

Exploit
  • EPSS 0.83%
  • Veröffentlicht 31.03.2009 18:24:45
  • Zuletzt bearbeitet 23.04.2026 00:35:47

mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 allows remote attackers to read arbitrary invalid .map files via a full pathname in the map parameter, which triggers the display of partial file contents within an error message, as demonst...