umn records
14 published records for vendor umn.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 5
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer7
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-399 Resource Management Errors1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
14 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
43Plan | CVE-2009-0839No exploit | Stack-based buffer overflow in mapserv.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2, when the server has a map with a loosgeo · mapserver · CWE-119 | Critical10.0 | — | 9.0% | Mar 31, 2009 |
42Plan | CVE-2009-2281No exploit | Multiple heap-based buffer underflows in the readPostBody function in cgiutil.c in mapserv in MapServer 4.x through 4.10.4 and 5.x before 5.osgeo · mapserver · CWE-119 | Critical10.0 | — | 5.9% | Oct 23, 2009 |
42Plan | CVE-2009-0840No exploit | Heap-based buffer underflow in the readPostBody function in cgiutil.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 allows osgeo · mapserver · CWE-119 | Critical10.0 | — | 5.3% | Mar 31, 2009 |
42Plan | CVE-2009-0841No exploit | Directory traversal vulnerability in mapserv.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2, when running on Windows with osgeo · mapserver · CWE-22 | Critical10.0 | — | 5.3% | Mar 31, 2009 |
41Plan | CVE-2009-1176No exploit | mapserv.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 does not ensure that the string holding the id parameter ends in a osgeo · mapserver · CWE-119 | Critical10.0 | — | 4.1% | Mar 31, 2009 |
41Plan | CVE-2010-2540No exploit | mapserv.c in mapserv in MapServer before 4.10.6 and 5.x before 5.6.4 does not properly restrict the use of CGI command-line arguments that wosgeo · mapserver · CWE-264 | Critical10.0 | — | 3.8% | Aug 2, 2010 |
41Plan | CVE-2009-1177No exploit | Multiple stack-based buffer overflows in maptemplate.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 have unknown impact anosgeo · mapserver · CWE-119 | Critical10.0 | — | 2.9% | Mar 31, 2009 |
32Monitor | CVE-2011-2704No exploit | Stack-based buffer overflow in MapServer before 4.10.7 and 5.x before 5.6.7 allows remote attackers to execute arbitrary code via vectors reosgeo · mapserver · CWE-119 | High7.5 | — | 5.2% | Aug 1, 2011 |
32Monitor | CVE-2009-0843No exploit | The msLoadQuery function in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 allows remote attackers to determine the existence oosgeo · mapserver · CWE-20 | High7.8 | — | 3.1% | Mar 31, 2009 |
31Monitor | CVE-2011-2703No exploit | Multiple SQL injection vulnerabilities in MapServer before 4.10.7, 5.x before 5.6.7, and 6.x before 6.0.1 allow remote attackers to execute osgeo · mapserver · CWE-89 | High7.5 | — | 2.7% | Aug 1, 2011 |
28Monitor | CVE-2011-2975Proof of concept | Double free vulnerability in the msAddImageSymbol function in mapsymbol.c in MapServer before 6.0.1 might allow remote attackers to cause a osgeo · mapserver · CWE-399 | Medium6.8 | — | 4.6% | Aug 1, 2011 |
28Monitor | CVE-2013-7262No exploit | SQL injection vulnerability in the msPostGISLayerSetTimeFilter function in mappostgis.c in MapServer before 6.4.1, when a WMS-Time service iosgeo · mapserver · CWE-89 | Medium6.8 | — | 2.2% | Jan 5, 2014 |
18Monitor | CVE-2009-0842No exploit | mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 allows remote attackers to read arbitrary invalid .map files via a full pathnameosgeo · mapserver · CWE-200 | Medium4.3 | — | 2.6% | Mar 31, 2009 |
8Monitor | CVE-2010-2539No exploit | Buffer overflow in the msTmpFile function in maputil.c in mapserv in MapServer before 4.10.6 and 5.x before 5.6.4 allows local users to causosgeo · mapserver · CWE-119 | Low2.1 | — | 0.3% | Aug 2, 2010 |
- CVE-2009-083943Plan
Stack-based buffer overflow in mapserv.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2, when the server has a map with a lo
CriticalCVSS 10.0No exploitEPSS 9%osgeo · mapserverMar 31, 2009
- CVE-2009-228142Plan
Multiple heap-based buffer underflows in the readPostBody function in cgiutil.c in mapserv in MapServer 4.x through 4.10.4 and 5.x before 5.
CriticalCVSS 10.0No exploitEPSS 6%osgeo · mapserverOct 23, 2009
- CVE-2009-084042Plan
Heap-based buffer underflow in the readPostBody function in cgiutil.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 allows
CriticalCVSS 10.0No exploitEPSS 5%osgeo · mapserverMar 31, 2009
- CVE-2009-084142Plan
Directory traversal vulnerability in mapserv.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2, when running on Windows with
CriticalCVSS 10.0No exploitEPSS 5%osgeo · mapserverMar 31, 2009
- CVE-2009-117641Plan
mapserv.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 does not ensure that the string holding the id parameter ends in a
CriticalCVSS 10.0No exploitEPSS 4%osgeo · mapserverMar 31, 2009
- CVE-2010-254041Plan
mapserv.c in mapserv in MapServer before 4.10.6 and 5.x before 5.6.4 does not properly restrict the use of CGI command-line arguments that w
CriticalCVSS 10.0No exploitEPSS 4%osgeo · mapserverAug 2, 2010
- CVE-2009-117741Plan
Multiple stack-based buffer overflows in maptemplate.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 have unknown impact an
CriticalCVSS 10.0No exploitEPSS 3%osgeo · mapserverMar 31, 2009
- CVE-2011-270432Monitor
Stack-based buffer overflow in MapServer before 4.10.7 and 5.x before 5.6.7 allows remote attackers to execute arbitrary code via vectors re
HighCVSS 7.5No exploitEPSS 5%osgeo · mapserverAug 1, 2011
- CVE-2009-084332Monitor
The msLoadQuery function in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 allows remote attackers to determine the existence o
HighCVSS 7.8No exploitEPSS 3%osgeo · mapserverMar 31, 2009
- CVE-2011-270331Monitor
Multiple SQL injection vulnerabilities in MapServer before 4.10.7, 5.x before 5.6.7, and 6.x before 6.0.1 allow remote attackers to execute
HighCVSS 7.5No exploitEPSS 3%osgeo · mapserverAug 1, 2011
- CVE-2011-297528Monitor
Double free vulnerability in the msAddImageSymbol function in mapsymbol.c in MapServer before 6.0.1 might allow remote attackers to cause a
MediumCVSS 6.8Proof of conceptEPSS 5%osgeo · mapserverAug 1, 2011
- CVE-2013-726228Monitor
SQL injection vulnerability in the msPostGISLayerSetTimeFilter function in mappostgis.c in MapServer before 6.4.1, when a WMS-Time service i
MediumCVSS 6.8No exploitEPSS 2%osgeo · mapserverJan 5, 2014
- CVE-2009-084218Monitor
mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 allows remote attackers to read arbitrary invalid .map files via a full pathname
MediumCVSS 4.3No exploitEPSS 3%osgeo · mapserverMar 31, 2009
- CVE-2010-25398Monitor
Buffer overflow in the msTmpFile function in maputil.c in mapserv in MapServer before 4.10.6 and 5.x before 5.6.4 allows local users to caus
LowCVSS 2.1No exploitEPSS 0%osgeo · mapserverAug 2, 2010