VYPR

Mapserver

by Osgeo

Source repositories

CVEs (22)

  • CVE-2009-0841Mar 31, 2009
    risk 0.00cvss epss 0.05

    Directory traversal vulnerability in mapserv.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2, when running on Windows with Cygwin, allows remote attackers to create arbitrary files via a .. (dot dot) in the id parameter.

  • CVE-2009-0840Mar 31, 2009
    risk 0.00cvss epss 0.05

    Heap-based buffer underflow in the readPostBody function in cgiutil.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 allows remote attackers to have an unknown impact via a negative value in the Content-Length HTTP header.

Page 2 of 2