Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
osgeo vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2009-0842
mapserv in MapServer 4.x prior to 4.10.4 and 5.x prior to 5.2.2 allows remote malicious users to read arbitrary invalid .map files via a full pathname in the map parameter, which triggers the display of partial file contents within an error message, as demonstrated by a /tmp/sekr...
Osgeo Mapserver 4.10.1
Osgeo Mapserver 4.10.0
Osgeo Mapserver 4.8.0
Osgeo Mapserver 4.6.0
Osgeo Mapserver 4.4.0
Osgeo Mapserver 5.2.0
Osgeo Mapserver 5.0.0
Osgeo Mapserver 4.2.0
Umn Mapserver 4.0
Osgeo Mapserver 4.10.2
Osgeo Mapserver 4.10.3
Osgeo Mapserver 5.2.1
NA
CVE-2009-0843
The msLoadQuery function in mapserv in MapServer 4.x prior to 4.10.4 and 5.x prior to 5.2.2 allows remote malicious users to determine the existence of arbitrary files via a full pathname in the queryfile parameter, which triggers different error messages depending on whether thi...
Osgeo Mapserver 4.10.0
Osgeo Mapserver 4.8.0
Osgeo Mapserver 4.6.0
Umn Mapserver 4.0
Osgeo Mapserver 4.10.2
Osgeo Mapserver 4.10.3
Osgeo Mapserver 4.4.0
Osgeo Mapserver 5.2.1
Osgeo Mapserver 5.2.0
Osgeo Mapserver 5.0.0
Osgeo Mapserver 4.10.1
Osgeo Mapserver 4.2.0
NA
CVE-2009-1176
mapserv.c in mapserv in MapServer 4.x prior to 4.10.4 and 5.x prior to 5.2.2 does not ensure that the string holding the id parameter ends in a '\0' character, which allows remote malicious users to conduct buffer-overflow attacks or have unspecified other impact via a ...
Osgeo Mapserver 4.10.0
Osgeo Mapserver 4.10.2
Osgeo Mapserver 4.8.0
Osgeo Mapserver 4.6.0
Osgeo Mapserver 4.4.0
Umn Mapserver 4.0
Osgeo Mapserver 5.2.1
Osgeo Mapserver 5.2.0
Osgeo Mapserver 5.0.0
Osgeo Mapserver 4.10.3
Osgeo Mapserver 4.10.1
Osgeo Mapserver 4.2.0
NA
CVE-2011-2703
Multiple SQL injection vulnerabilities in MapServer prior to 4.10.7, 5.x prior to 5.6.7, and 6.x prior to 6.0.1 allow remote malicious users to execute arbitrary SQL commands via vectors related to (1) OGC filter encoding or (2) WMS time support.
Osgeo Mapserver 4.10.3
Osgeo Mapserver 4.10.1
Osgeo Mapserver 4.8.0
Osgeo Mapserver 4.6.0
Osgeo Mapserver 4.10.0
Osgeo Mapserver 4.10.2
Osgeo Mapserver 4.4.0
Osgeo Mapserver 4.10.5
Osgeo Mapserver 4.10.4
Osgeo Mapserver 4.2.0
Osgeo Mapserver
Osgeo Mapserver 5.2.0
Osgeo Mapserver 5.0.0
Osgeo Mapserver 5.4.0
Osgeo Mapserver 5.6.1
Osgeo Mapserver 5.6.3
Osgeo Mapserver 5.4.2
Osgeo Mapserver 5.6.0
Umn Mapserver 5.2.3
Osgeo Mapserver 5.2.1
Osgeo Mapserver 5.4.1
Umn Mapserver 5.6.4
NA
CVE-2011-2975
Double free vulnerability in the msAddImageSymbol function in mapsymbol.c in MapServer prior to 6.0.1 might allow remote malicious users to cause a denial of service (application crash) or have unspecified other impact via crafted mapfile data.
Osgeo Mapserver 5.0.0
Osgeo Mapserver 5.2.0
Osgeo Mapserver 5.2.1
Osgeo Mapserver 4.10.0
Osgeo Mapserver 5.4.0
Osgeo Mapserver 4.10.2
Osgeo Mapserver 4.10.3
Osgeo Mapserver 4.8.0
Osgeo Mapserver 5.6.0
Osgeo Mapserver 4.2.0
Umn Mapserver 5.6.4
Umn Mapserver 5.6.5
Umn Mapserver 5.6.6
Osgeo Mapserver
Osgeo Mapserver 5.4.1
Osgeo Mapserver 4.4.0
Osgeo Mapserver 4.6.0
Umn Mapserver 6.0.0
Osgeo Mapserver 5.4.2
Osgeo Mapserver 5.6.3
Umn Mapserver 5.2.2
Umn Mapserver 5.6.7
1 EDB exploit
7.5
CVSSv3
CVE-2010-1678
Mapserver 5.2, 5.4 and 5.6 prior to 5.6.5-2 improperly validates symbol index values during Mapfile parsing.
Osgeo Mapserver 5.2.0
Osgeo Mapserver 5.4.0
Osgeo Mapserver
7.2
CVSSv3
CVE-2021-28398
A privileged attacker in GeoNetwork prior to 3.12.0 and 4.x prior to 4.0.4 can use the directory harvester before-script to execute arbitrary OS commands remotely on the hosting infrastructure. A User Administrator or Administrator account is required to perform this. This occurs...
Osgeo Geonetwork
Osgeo Geonetwork 4.0.0
7.5
CVSSv3
CVE-2021-39371
An XML external entity (XXE) injection in PyWPS prior to 4.4.5 allows an malicious user to view files on the application server filesystem by assigning a path to the entity. OWSLib 0.24.1 may also be affected.
Osgeo Owslib 0.24.1
Osgeo Pywps
Debian Debian Linux 9.0
7.2
CVSSv3
CVE-2022-24847
GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. The GeoServer security mechanism can perform an unchecked JNDI lookup, which in turn can be used to perform class deserialization and result in arbitrary code executio...
Osgeo Geoserver
9.8
CVSSv3
CVE-2023-25157
GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. GeoServer includes support for the OGC Filter expression language and the OGC Common Query Language (CQL) as part of the Web Feature Service (WFS) and Web Map Service ...
Osgeo Geoserver
8 Github repositories
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
validation
CVE-2012-1823
malicious code
CVE-2024-5770
CVE-2023-45866
CVE-2024-35687
local users
CVE-2024-31246
CVE-2024-35730
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
NEXT »