CVE-2009-0842
- EPSS 0.83%
- Veröffentlicht 31.03.2009 18:24:45
- Zuletzt bearbeitet 09.04.2025 00:30:58
mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 allows remote attackers to read arbitrary invalid .map files via a full pathname in the map parameter, which triggers the display of partial file contents within an error message, as demonst...
CVE-2009-0843
- EPSS 1.03%
- Veröffentlicht 31.03.2009 18:24:45
- Zuletzt bearbeitet 09.04.2025 00:30:58
The msLoadQuery function in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 allows remote attackers to determine the existence of arbitrary files via a full pathname in the queryfile parameter, which triggers different error messages depe...
- EPSS 2.03%
- Veröffentlicht 31.03.2009 18:24:45
- Zuletzt bearbeitet 09.04.2025 00:30:58
mapserv.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 does not ensure that the string holding the id parameter ends in a '\0' character, which allows remote attackers to conduct buffer-overflow attacks or have unspecified other imp...
- EPSS 1.52%
- Veröffentlicht 31.03.2009 18:24:45
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple stack-based buffer overflows in maptemplate.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 have unknown impact and remote attack vectors.