Osgeo / Mapserver
22 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-45104 | MapServer: NULL pointer dereference in SLD `<ElseFilter>` rule parsing reachable via WMS `SLD_BODY` | HIGH | 7.5 | May 27, 2026 |
| CVE-2026-42030 | MapServer: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in OpenLayers viewer | MEDIUM | 6.1 | May 8, 2026 |
| CVE-2026-33721 | MapServer has heap buffer overflow in SLD `Categorize` Threshold parsing | HIGH | 7.5 | Mar 27, 2026 |
| CVE-2025-59431 | MapServer - WFS XML Filter Query SQL injection | HIGH | 8.9 | Sep 19, 2025 |
| CVE-2021-32062 | MapServer before 7.0.8, 7.1.x and 7.2.x before 7.2.3, 7.3.x and 7.4.x before 7.4.5, and 7.5.x and 7.6.x before 7.6.3 does not properly enforce the MS_MAP_NO_PA… | MEDIUM | 5.3 | May 5, 2021 |
| CVE-2010-1678 | Mapserver 5.2, 5.4 and 5.6 before 5.6.5-2 improperly validates symbol index values during Mapfile parsing. | HIGH | 7.5 | Oct 29, 2019 |
| CVE-2017-5522 | Stack-based buffer overflow in MapServer before 6.0.6, 6.2.x before 6.2.4, 6.4.x before 6.4.5, and 7.0.x before 7.0.4 allows remote attackers to cause a denial… | CRITICAL | 9.8 | Mar 15, 2017 |
| CVE-2016-9839 | In MapServer before 7.0.3, OGR driver error messages are too verbose and may leak sensitive information if data connection fails. | HIGH | 7.5 | Dec 8, 2016 |
| CVE-2013-7262 | SQL injection vulnerability in the msPostGISLayerSetTimeFilter function in mappostgis.c in MapServer before 6.4.1, when a WMS-Time service is used, allows remo… | MEDIUM | 6.8 | Jan 5, 2014 |
| CVE-2011-2975 | Double free vulnerability in the msAddImageSymbol function in mapsymbol.c in MapServer before 6.0.1 might allow remote attackers to cause a denial of service (… | MEDIUM | 6.8 | Aug 1, 2011 |
| CVE-2011-2704 | Stack-based buffer overflow in MapServer before 4.10.7 and 5.x before 5.6.7 allows remote attackers to execute arbitrary code via vectors related to OGC filter… | HIGH | 7.5 | Aug 1, 2011 |
| CVE-2011-2703 | Multiple SQL injection vulnerabilities in MapServer before 4.10.7, 5.x before 5.6.7, and 6.x before 6.0.1 allow remote attackers to execute arbitrary SQL comma… | HIGH | 7.5 | Aug 1, 2011 |
| CVE-2010-2540 | mapserv.c in mapserv in MapServer before 4.10.6 and 5.x before 5.6.4 does not properly restrict the use of CGI command-line arguments that were intended for de… | HIGH | 10.0 | Aug 2, 2010 |
| CVE-2010-2539 | Buffer overflow in the msTmpFile function in maputil.c in mapserv in MapServer before 4.10.6 and 5.x before 5.6.4 allows local users to cause a denial of servi… | LOW | 2.1 | Aug 2, 2010 |
| CVE-2009-2281 | mapserver: incomplete upstream fix for CVE-2009-0840 | HIGH | 10.0 | Oct 23, 2009 |
| CVE-2009-1177 | mapserver: multiple security fixes in 5.2.2 and 4.10.4 (CVE-2009-0839, CVE-2009-0840, CVE-2009-0841, CVE-2009-0842, CVE-2009-0843, CVE-2009-1176, CVE-2009-1177) | HIGH | 10.0 | Mar 31, 2009 |
| CVE-2009-1176 | mapserver: multiple security fixes in 5.2.2 and 4.10.4 (CVE-2009-0839, CVE-2009-0840, CVE-2009-0841, CVE-2009-0842, CVE-2009-0843, CVE-2009-1176, CVE-2009-1177) | HIGH | 10.0 | Mar 31, 2009 |
| CVE-2009-0843 | mapserver: multiple security fixes in 5.2.2 and 4.10.4 (CVE-2009-0839, CVE-2009-0840, CVE-2009-0841, CVE-2009-0842, CVE-2009-0843, CVE-2009-1176, CVE-2009-1177) | HIGH | 7.8 | Mar 31, 2009 |
| CVE-2009-0842 | mapserver: multiple security fixes in 5.2.2 and 4.10.4 (CVE-2009-0839, CVE-2009-0840, CVE-2009-0841, CVE-2009-0842, CVE-2009-0843, CVE-2009-1176, CVE-2009-1177) | MEDIUM | 4.3 | Mar 31, 2009 |
| CVE-2009-0841 | mapserver: multiple security fixes in 5.2.2 and 4.10.4 (CVE-2009-0839, CVE-2009-0840, CVE-2009-0841, CVE-2009-0842, CVE-2009-0843, CVE-2009-1176, CVE-2009-1177) | HIGH | 10.0 | Mar 31, 2009 |
| CVE-2009-0840 | mapserver: multiple security fixes in 5.2.2 and 4.10.4 (CVE-2009-0839, CVE-2009-0840, CVE-2009-0841, CVE-2009-0842, CVE-2009-0843, CVE-2009-1176, CVE-2009-1177) | HIGH | 10.0 | Mar 31, 2009 |
| CVE-2009-0839 | mapserver: multiple security fixes in 5.2.2 and 4.10.4 (CVE-2009-0839, CVE-2009-0840, CVE-2009-0841, CVE-2009-0842, CVE-2009-0843, CVE-2009-1176, CVE-2009-1177) | HIGH | 10.0 | Mar 31, 2009 |
Showing 1 to 22 of 22 CVEs