Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-33721

Опубликовано: 27 мар. 2026
Источник: nvd
CVSS3: 5.3
CVSS3: 7.5
EPSS Низкий

Описание

MapServer is a system for developing web-based GIS applications. Starting in version 4.2 and prior to version 8.6.1, a heap-buffer-overflow write in MapServer’s SLD (Styled Layer Descriptor) parser lets a remote, unauthenticated attacker crash the MapServer process by sending a crafted SLD with more than 100 Threshold elements inside a ColorMap/Categorize structure (commonly reachable via WMS GetMap with SLD_BODY). Version 8.6.1 patches the issue.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:osgeo:mapserver:*:*:*:*:*:*:*:*
Версия от 4.2.0 (включая) до 8.6.1 (исключая)

EPSS

Процентиль: 55%
0.00865
Низкий

5.3 Medium

CVSS3

7.5 High

CVSS3

Дефекты

CWE-787

Связанные уязвимости

CVSS3: 5.3
ubuntu
5 месяцев назад

MapServer is a system for developing web-based GIS applications. Starting in version 4.2 and prior to version 8.6.1, a heap-buffer-overflow write in MapServer’s SLD (Styled Layer Descriptor) parser lets a remote, unauthenticated attacker crash the MapServer process by sending a crafted SLD with more than 100 Threshold elements inside a ColorMap/Categorize structure (commonly reachable via WMS GetMap with SLD_BODY). Version 8.6.1 patches the issue.

CVSS3: 7.5
redhat
5 месяцев назад

MapServer is a system for developing web-based GIS applications. Starting in version 4.2 and prior to version 8.6.1, a heap-buffer-overflow write in MapServer’s SLD (Styled Layer Descriptor) parser lets a remote, unauthenticated attacker crash the MapServer process by sending a crafted SLD with more than 100 Threshold elements inside a ColorMap/Categorize structure (commonly reachable via WMS GetMap with SLD_BODY). Version 8.6.1 patches the issue.

CVSS3: 5.3
debian
5 месяцев назад

MapServer is a system for developing web-based GIS applications. Start ...

suse-cvrf
4 месяца назад

Security update for mapserver

suse-cvrf
2 месяца назад

Security update for mapserver

EPSS

Процентиль: 55%
0.00865
Низкий

5.3 Medium

CVSS3

7.5 High

CVSS3

Дефекты

CWE-787