Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
osgeo vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2023-43795
GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. The OGC Web Processing Service (WPS) specification is designed to process information from any server using GET and POST requests. This presents the opportunity for Se...
Osgeo Geoserver
NA
CVE-2023-41339
GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. The WMS specification defines an ``sld=<url>`` parameter for GetMap, GetLegendGraphic and GetFeatureInfo operations for user supplied "dynamic styling"...
Osgeo Geoserver
NA
CVE-2023-27476
OWSLib is a Python package for client programming with Open Geospatial Consortium (OGC) web service interface standards, and their related content models. OWSLib's XML parser (which supports both `lxml` and `xml.etree`) does not disable entity resolution, and could lead to a...
Osgeo Owslib
NA
CVE-2023-25157
GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. GeoServer includes support for the OGC Filter expression language and the OGC Common Query Language (CQL) as part of the Web Feature Service (WFS) and Web Map Service ...
Osgeo Geoserver
8 Github repositories
NA
CVE-2022-0699
A double-free condition exists in contrib/shpsort.c of shapelib 1.5.0 and older releases. This issue may allow an malicious user to cause a denial of service or have other unspecified impact via control over malloc.
Osgeo Shapelib
NA
CVE-2021-28398
A privileged attacker in GeoNetwork prior to 3.12.0 and 4.x prior to 4.0.4 can use the directory harvester before-script to execute arbitrary OS commands remotely on the hosting infrastructure. A User Administrator or Administrator account is required to perform this. This occurs...
Osgeo Geonetwork
Osgeo Geonetwork 4.0.0
5
CVSSv2
CVE-2021-40822
GeoServer up to and including 2.18.5 and 2.19.x up to and including 2.19.2 allows SSRF via the option for setting a proxy host.
Osgeo Geoserver
2 Github repositories
6.5
CVSSv2
CVE-2022-24847
GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. The GeoServer security mechanism can perform an unchecked JNDI lookup, which in turn can be used to perform class deserialization and result in arbitrary code executio...
Osgeo Geoserver
4.3
CVSSv2
CVE-2021-45943
GDAL 3.3.0 up to and including 3.4.0 has a heap-based buffer overflow in PCIDSK::CPCIDSKFile::ReadFromFile (called from PCIDSK::CPCIDSKSegment::ReadFromFile and PCIDSK::CPCIDSKBinarySegment::CPCIDSKBinarySegment).
Osgeo Gdal
Debian Debian Linux 9.0
Debian Debian Linux 10.0
Debian Debian Linux 11.0
Fedoraproject Fedora 34
Fedoraproject Fedora 35
Oracle Spatial And Graph 19c
Oracle Spatial And Graph 21c
5
CVSSv2
CVE-2021-39371
An XML external entity (XXE) injection in PyWPS prior to 4.4.5 allows an malicious user to view files on the application server filesystem by assigning a path to the entity. OWSLib 0.24.1 may also be affected.
Osgeo Owslib 0.24.1
Osgeo Pywps
Debian Debian Linux 9.0
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
blind SQL injection
SSRF
buffer overflow
CVE-2023-28952
CVE-2023-41822
CVE-2024-27956
CVE-2023-7028
CVE-2024-34447
CVE-2024-34460
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
NEXT »