Show filters
31 Total Results
Displaying 11-20 of 31
Sort by:
Attacker Value
Unknown
CVE-2019-25050
Disclosure Date: July 20, 2021 (last updated February 23, 2025)
netCDF in GDAL 2.4.2 through 3.0.4 has a stack-based buffer overflow in nc4_get_att (called from nc4_get_att_tc and nc_get_att_text) and in uffd_cleanup (called from netCDFDataset::~netCDFDataset and netCDFDataset::~netCDFDataset).
0
Attacker Value
Unknown
CVE-2021-32062
Disclosure Date: May 06, 2021 (last updated February 22, 2025)
MapServer before 7.0.8, 7.1.x and 7.2.x before 7.2.3, 7.3.x and 7.4.x before 7.4.5, and 7.5.x and 7.6.x before 7.6.3 does not properly enforce the MS_MAP_NO_PATH and MS_MAP_PATTERN restrictions that are intended to control the locations from which a mapfile may be loaded (with MapServer CGI).
0
Attacker Value
Unknown
CVE-2010-1678
Disclosure Date: October 29, 2019 (last updated November 27, 2024)
Mapserver 5.2, 5.4 and 5.6 before 5.6.5-2 improperly validates symbol index values during Mapfile parsing.
0
Attacker Value
Unknown
CVE-2019-17545
Disclosure Date: October 14, 2019 (last updated November 08, 2023)
GDAL through 3.0.1 has a poolDestroy double free in OGRExpatRealloc in ogr/ogr_expat.cpp when the 10MB threshold is exceeded.
0
Attacker Value
Unknown
CVE-2019-17546
Disclosure Date: October 14, 2019 (last updated November 08, 2023)
tif_getimage.c in LibTIFF through 4.0.10, as used in GDAL through 3.0.1 and other products, has an integer overflow that potentially causes a heap-based buffer overflow via a crafted RGBA image, related to a "Negative-size-param" condition.
0
Attacker Value
Unknown
CVE-2017-5522
Disclosure Date: March 15, 2017 (last updated November 26, 2024)
Stack-based buffer overflow in MapServer before 6.0.6, 6.2.x before 6.2.4, 6.4.x before 6.4.5, and 7.0.x before 7.0.4 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via vectors involving WFS get feature requests.
0
Attacker Value
Unknown
CVE-2016-9839
Disclosure Date: December 08, 2016 (last updated November 25, 2024)
In MapServer before 7.0.3, OGR driver error messages are too verbose and may leak sensitive information if data connection fails.
0
Attacker Value
Unknown
CVE-2013-7262
Disclosure Date: January 05, 2014 (last updated October 05, 2023)
SQL injection vulnerability in the msPostGISLayerSetTimeFilter function in mappostgis.c in MapServer before 6.4.1, when a WMS-Time service is used, allows remote attackers to execute arbitrary SQL commands via a crafted string in a PostGIS TIME filter.
0
Attacker Value
Unknown
CVE-2011-2975
Disclosure Date: August 01, 2011 (last updated October 04, 2023)
Double free vulnerability in the msAddImageSymbol function in mapsymbol.c in MapServer before 6.0.1 might allow remote attackers to cause a denial of service (application crash) or have unspecified other impact via crafted mapfile data.
0
Attacker Value
Unknown
CVE-2011-2703
Disclosure Date: August 01, 2011 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in MapServer before 4.10.7, 5.x before 5.6.7, and 6.x before 6.0.1 allow remote attackers to execute arbitrary SQL commands via vectors related to (1) OGC filter encoding or (2) WMS time support.
0