Osgeo Mapserver 5.6.4

CPE Details

Osgeo Mapserver 5.6.4
5.6.4
2019-12-11
13h55 +00:00
2019-12-11
13h55 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:osgeo:mapserver:5.6.4:*:*:*:*:*:*:*

Informations

Vendor

osgeo

Product

mapserver

Version

5.6.4

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2021-32062 2021-05-05 16h39 +00:00 MapServer before 7.0.8, 7.1.x and 7.2.x before 7.2.3, 7.3.x and 7.4.x before 7.4.5, and 7.5.x and 7.6.x before 7.6.3 does not properly enforce the MS_MAP_NO_PATH and MS_MAP_PATTERN restrictions that are intended to control the locations from which a mapfile may be loaded (with MapServer CGI).
5.3
Medium
CVE-2010-1678 2019-10-29 19h04 +00:00 Mapserver 5.2, 5.4 and 5.6 before 5.6.5-2 improperly validates symbol index values during Mapfile parsing.
7.5
High
CVE-2017-5522 2017-03-15 15h00 +00:00 Stack-based buffer overflow in MapServer before 6.0.6, 6.2.x before 6.2.4, 6.4.x before 6.4.5, and 7.0.x before 7.0.4 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via vectors involving WFS get feature requests.
9.8
Critical
CVE-2016-9839 2016-12-08 07h08 +00:00 In MapServer before 7.0.3, OGR driver error messages are too verbose and may leak sensitive information if data connection fails.
7.5
High
CVE-2013-7262 2014-01-05 19h00 +00:00 SQL injection vulnerability in the msPostGISLayerSetTimeFilter function in mappostgis.c in MapServer before 6.4.1, when a WMS-Time service is used, allows remote attackers to execute arbitrary SQL commands via a crafted string in a PostGIS TIME filter.
6.8
CVE-2011-2975 2011-08-01 20h00 +00:00 Double free vulnerability in the msAddImageSymbol function in mapsymbol.c in MapServer before 6.0.1 might allow remote attackers to cause a denial of service (application crash) or have unspecified other impact via crafted mapfile data.
6.8