OSGeo MapServer 5.4

CPE Details

OSGeo MapServer 5.4
5.4
2019-12-11
13h55 +00:00
2021-06-01
11h57 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:osgeo:mapserver:5.4:*:*:*:*:*:*:*

Informations

Vendor

osgeo

Product

mapserver

Version

5.4

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2021-32062 2021-05-05 16h39 +00:00 MapServer before 7.0.8, 7.1.x and 7.2.x before 7.2.3, 7.3.x and 7.4.x before 7.4.5, and 7.5.x and 7.6.x before 7.6.3 does not properly enforce the MS_MAP_NO_PATH and MS_MAP_PATTERN restrictions that are intended to control the locations from which a mapfile may be loaded (with MapServer CGI).
5.3
Medium
CVE-2017-5522 2017-03-15 15h00 +00:00 Stack-based buffer overflow in MapServer before 6.0.6, 6.2.x before 6.2.4, 6.4.x before 6.4.5, and 7.0.x before 7.0.4 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via vectors involving WFS get feature requests.
9.8
Critical
CVE-2016-9839 2016-12-08 07h08 +00:00 In MapServer before 7.0.3, OGR driver error messages are too verbose and may leak sensitive information if data connection fails.
7.5
High
CVE-2013-7262 2014-01-05 19h00 +00:00 SQL injection vulnerability in the msPostGISLayerSetTimeFilter function in mappostgis.c in MapServer before 6.4.1, when a WMS-Time service is used, allows remote attackers to execute arbitrary SQL commands via a crafted string in a PostGIS TIME filter.
6.8
CVE-2011-2975 2011-08-01 20h00 +00:00 Double free vulnerability in the msAddImageSymbol function in mapsymbol.c in MapServer before 6.0.1 might allow remote attackers to cause a denial of service (application crash) or have unspecified other impact via crafted mapfile data.
6.8
CVE-2010-2539 2010-08-02 19h00 +00:00 Buffer overflow in the msTmpFile function in maputil.c in mapserv in MapServer before 4.10.6 and 5.x before 5.6.4 allows local users to cause a denial of service via vectors involving names of temporary files.
2.1
CVE-2010-2540 2010-08-02 19h00 +00:00 mapserv.c in mapserv in MapServer before 4.10.6 and 5.x before 5.6.4 does not properly restrict the use of CGI command-line arguments that were intended for debugging, which allows remote attackers to have an unspecified impact via crafted arguments.
10