Skip to content
Noroxi

umn records

14 published records for vendor umn.

All records

14 records
  • Stack-based buffer overflow in mapserv.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2, when the server has a map with a lo

    CriticalCVSS 10.0No exploitEPSS 9%

    osgeo · mapserverMar 31, 2009

  • Multiple heap-based buffer underflows in the readPostBody function in cgiutil.c in mapserv in MapServer 4.x through 4.10.4 and 5.x before 5.

    CriticalCVSS 10.0No exploitEPSS 6%

    osgeo · mapserverOct 23, 2009

  • Heap-based buffer underflow in the readPostBody function in cgiutil.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 allows

    CriticalCVSS 10.0No exploitEPSS 5%

    osgeo · mapserverMar 31, 2009

  • Directory traversal vulnerability in mapserv.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2, when running on Windows with

    CriticalCVSS 10.0No exploitEPSS 5%

    osgeo · mapserverMar 31, 2009

  • mapserv.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 does not ensure that the string holding the id parameter ends in a

    CriticalCVSS 10.0No exploitEPSS 4%

    osgeo · mapserverMar 31, 2009

  • mapserv.c in mapserv in MapServer before 4.10.6 and 5.x before 5.6.4 does not properly restrict the use of CGI command-line arguments that w

    CriticalCVSS 10.0No exploitEPSS 4%

    osgeo · mapserverAug 2, 2010

  • Multiple stack-based buffer overflows in maptemplate.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 have unknown impact an

    CriticalCVSS 10.0No exploitEPSS 3%

    osgeo · mapserverMar 31, 2009

  • CVE-2011-2704
    32Monitor

    Stack-based buffer overflow in MapServer before 4.10.7 and 5.x before 5.6.7 allows remote attackers to execute arbitrary code via vectors re

    HighCVSS 7.5No exploitEPSS 5%

    osgeo · mapserverAug 1, 2011

  • CVE-2009-0843
    32Monitor

    The msLoadQuery function in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 allows remote attackers to determine the existence o

    HighCVSS 7.8No exploitEPSS 3%

    osgeo · mapserverMar 31, 2009

  • CVE-2011-2703
    31Monitor

    Multiple SQL injection vulnerabilities in MapServer before 4.10.7, 5.x before 5.6.7, and 6.x before 6.0.1 allow remote attackers to execute

    HighCVSS 7.5No exploitEPSS 3%

    osgeo · mapserverAug 1, 2011

  • CVE-2011-2975
    28Monitor

    Double free vulnerability in the msAddImageSymbol function in mapsymbol.c in MapServer before 6.0.1 might allow remote attackers to cause a

    MediumCVSS 6.8Proof of conceptEPSS 5%

    osgeo · mapserverAug 1, 2011

  • CVE-2013-7262
    28Monitor

    SQL injection vulnerability in the msPostGISLayerSetTimeFilter function in mappostgis.c in MapServer before 6.4.1, when a WMS-Time service i

    MediumCVSS 6.8No exploitEPSS 2%

    osgeo · mapserverJan 5, 2014

  • CVE-2009-0842
    18Monitor

    mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 allows remote attackers to read arbitrary invalid .map files via a full pathname

    MediumCVSS 4.3No exploitEPSS 3%

    osgeo · mapserverMar 31, 2009

  • Buffer overflow in the msTmpFile function in maputil.c in mapserv in MapServer before 4.10.6 and 5.x before 5.6.4 allows local users to caus

    LowCVSS 2.1No exploitEPSS 0%

    osgeo · mapserverAug 2, 2010