Show filters
31 Total Results
Displaying 11-20 of 31
Sort by:
Attacker Value
Unknown

CVE-2019-25050

Disclosure Date: July 20, 2021 (last updated February 23, 2025)
netCDF in GDAL 2.4.2 through 3.0.4 has a stack-based buffer overflow in nc4_get_att (called from nc4_get_att_tc and nc_get_att_text) and in uffd_cleanup (called from netCDFDataset::~netCDFDataset and netCDFDataset::~netCDFDataset).
Attacker Value
Unknown

CVE-2021-32062

Disclosure Date: May 06, 2021 (last updated February 22, 2025)
MapServer before 7.0.8, 7.1.x and 7.2.x before 7.2.3, 7.3.x and 7.4.x before 7.4.5, and 7.5.x and 7.6.x before 7.6.3 does not properly enforce the MS_MAP_NO_PATH and MS_MAP_PATTERN restrictions that are intended to control the locations from which a mapfile may be loaded (with MapServer CGI).
Attacker Value
Unknown

CVE-2010-1678

Disclosure Date: October 29, 2019 (last updated November 27, 2024)
Mapserver 5.2, 5.4 and 5.6 before 5.6.5-2 improperly validates symbol index values during Mapfile parsing.
Attacker Value
Unknown

CVE-2019-17545

Disclosure Date: October 14, 2019 (last updated November 08, 2023)
GDAL through 3.0.1 has a poolDestroy double free in OGRExpatRealloc in ogr/ogr_expat.cpp when the 10MB threshold is exceeded.
Attacker Value
Unknown

CVE-2019-17546

Disclosure Date: October 14, 2019 (last updated November 08, 2023)
tif_getimage.c in LibTIFF through 4.0.10, as used in GDAL through 3.0.1 and other products, has an integer overflow that potentially causes a heap-based buffer overflow via a crafted RGBA image, related to a "Negative-size-param" condition.
Attacker Value
Unknown

CVE-2017-5522

Disclosure Date: March 15, 2017 (last updated November 26, 2024)
Stack-based buffer overflow in MapServer before 6.0.6, 6.2.x before 6.2.4, 6.4.x before 6.4.5, and 7.0.x before 7.0.4 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via vectors involving WFS get feature requests.
0
Attacker Value
Unknown

CVE-2016-9839

Disclosure Date: December 08, 2016 (last updated November 25, 2024)
In MapServer before 7.0.3, OGR driver error messages are too verbose and may leak sensitive information if data connection fails.
Attacker Value
Unknown

CVE-2013-7262

Disclosure Date: January 05, 2014 (last updated October 05, 2023)
SQL injection vulnerability in the msPostGISLayerSetTimeFilter function in mappostgis.c in MapServer before 6.4.1, when a WMS-Time service is used, allows remote attackers to execute arbitrary SQL commands via a crafted string in a PostGIS TIME filter.
0
Attacker Value
Unknown

CVE-2011-2975

Disclosure Date: August 01, 2011 (last updated October 04, 2023)
Double free vulnerability in the msAddImageSymbol function in mapsymbol.c in MapServer before 6.0.1 might allow remote attackers to cause a denial of service (application crash) or have unspecified other impact via crafted mapfile data.
0
Attacker Value
Unknown

CVE-2011-2703

Disclosure Date: August 01, 2011 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in MapServer before 4.10.7, 5.x before 5.6.7, and 6.x before 6.0.1 allow remote attackers to execute arbitrary SQL commands via vectors related to (1) OGC filter encoding or (2) WMS time support.
0