Vulnerabilities (CVE)

Filtered by vendor University Of Minnesota Subscribe
Filtered by product Mapserver
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2007-4629 1 University Of Minnesota 1 Mapserver 2023-12-10 7.5 HIGH N/A
Buffer overflow in the processLine function in maptemplate.c in MapServer before 4.10.3 allows attackers to cause a denial of service and possibly execute arbitrary code via a mapfile with a long layer name, group name, or metadata entry name.
CVE-2007-4542 1 University Of Minnesota 1 Mapserver 2023-12-10 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in MapServer before 4.10.3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors involving the (1) processLine function in maptemplate.c and the (2) writeError function in mapserv.c in the mapserv CGI program.