Show filters
21 Total Results
Displaying 1-10 of 21
Sort by:
Attacker Value
Unknown

CVE-2021-32062

Disclosure Date: May 06, 2021 (last updated February 22, 2025)
MapServer before 7.0.8, 7.1.x and 7.2.x before 7.2.3, 7.3.x and 7.4.x before 7.4.5, and 7.5.x and 7.6.x before 7.6.3 does not properly enforce the MS_MAP_NO_PATH and MS_MAP_PATTERN restrictions that are intended to control the locations from which a mapfile may be loaded (with MapServer CGI).
Attacker Value
Unknown

CVE-2012-2950

Disclosure Date: January 09, 2020 (last updated February 21, 2025)
Gateway Geomatics MapServer for Windows before 3.0.6 contains a Local File Include Vulnerability which allows remote attackers to execute local PHP code and obtain sensitive information.
Attacker Value
Unknown

CVE-2010-1678

Disclosure Date: October 29, 2019 (last updated November 27, 2024)
Mapserver 5.2, 5.4 and 5.6 before 5.6.5-2 improperly validates symbol index values during Mapfile parsing.
Attacker Value
Unknown

CVE-2017-5522

Disclosure Date: March 15, 2017 (last updated November 26, 2024)
Stack-based buffer overflow in MapServer before 6.0.6, 6.2.x before 6.2.4, 6.4.x before 6.4.5, and 7.0.x before 7.0.4 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via vectors involving WFS get feature requests.
0
Attacker Value
Unknown

CVE-2016-9839

Disclosure Date: December 08, 2016 (last updated November 25, 2024)
In MapServer before 7.0.3, OGR driver error messages are too verbose and may leak sensitive information if data connection fails.
Attacker Value
Unknown

CVE-2013-7262

Disclosure Date: January 05, 2014 (last updated October 05, 2023)
SQL injection vulnerability in the msPostGISLayerSetTimeFilter function in mappostgis.c in MapServer before 6.4.1, when a WMS-Time service is used, allows remote attackers to execute arbitrary SQL commands via a crafted string in a PostGIS TIME filter.
0
Attacker Value
Unknown

CVE-2011-2975

Disclosure Date: August 01, 2011 (last updated October 04, 2023)
Double free vulnerability in the msAddImageSymbol function in mapsymbol.c in MapServer before 6.0.1 might allow remote attackers to cause a denial of service (application crash) or have unspecified other impact via crafted mapfile data.
0
Attacker Value
Unknown

CVE-2011-2703

Disclosure Date: August 01, 2011 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in MapServer before 4.10.7, 5.x before 5.6.7, and 6.x before 6.0.1 allow remote attackers to execute arbitrary SQL commands via vectors related to (1) OGC filter encoding or (2) WMS time support.
0
Attacker Value
Unknown

CVE-2011-2704

Disclosure Date: August 01, 2011 (last updated October 04, 2023)
Stack-based buffer overflow in MapServer before 4.10.7 and 5.x before 5.6.7 allows remote attackers to execute arbitrary code via vectors related to OGC filter encoding.
0
Attacker Value
Unknown

CVE-2010-2540

Disclosure Date: August 02, 2010 (last updated October 04, 2023)
mapserv.c in mapserv in MapServer before 4.10.6 and 5.x before 5.6.4 does not properly restrict the use of CGI command-line arguments that were intended for debugging, which allows remote attackers to have an unspecified impact via crafted arguments.
0