VYPR

Mapserver

by Osgeo

Source repositories

CVEs (22)

  • CVE-2009-0841Mar 31, 2009
    risk 0.00cvss —epss 0.05

    Directory traversal vulnerability in mapserv.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2, when running on Windows with Cygwin, allows remote attackers to create arbitrary files via a .. (dot dot) in the id parameter.

  • CVE-2009-0840Mar 31, 2009
    risk 0.00cvss —epss 0.05

    Heap-based buffer underflow in the readPostBody function in cgiutil.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 allows remote attackers to have an unknown impact via a negative value in the Content-Length HTTP header.

Page 2 of 2