Geopp's vulnerability footprint centers on GNSS correction and positioning software, with the durable signal rooted in authentication and input-handling weaknesses such as improper authentication, sensitive-information exposure, and buffer-boundary violations. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Geopp over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-0552HIGH Geo++ GNCASTER 1.4.0.7 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via multiple requests for a non-exis | Feb 4, 2010 | 7.5 | 29 | NO | YES |
CVE-2010-0553MEDIUM Geo++ GNCASTER 1.4.0.7 and earlier allows remote authenticated users to cause a denial of service (application crash) and possibly execute arbitrary code via a long NMEA data sente | Feb 4, 2010 | 6.5 | 26 | NO | YES |
CVE-2010-0554HIGH The HTTP Authentication implementation in Geo++ GNCASTER 1.4.0.7 and earlier uses the same nonce for all authentication, which allows remote attackers to hijack web sessions or byp | Feb 4, 2010 | 7.5 | 21 | NO | NO |
CVE-2010-0551MEDIUM HTTP authentication implementation in Geo++ GNCASTER 1.4.0.7 and earlier allows remote attackers to read authentication headers of other users via a large request with an incorrect | Feb 4, 2010 | 5.0 | 16 | NO | NO |
CVE-2010-0550MEDIUM admin.htm in Geo++ GNCASTER 1.4.0.7 and earlier does not properly enforce HTTP Digest Authentication, which allows remote authenticated users to use HTTP Basic Authentication, bypa | Feb 4, 2010 | 4.0 | 14 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Geopp.
Media articles that mention a CVE ID that affects a product developed by Geopp — matched by CVE ID, not by vendor name.