GSI's vulnerability footprint is a narrow one centered on file-path and directory-handling mechanisms within its legacy mapping and patching utilities, including products such as GSI, PatchJGD, Old GSI Maps, SemiDynaExe, and TKY2JGD. The recurring weakness classes—untrusted search path, path traversal, and uncontrolled search path elements—reflect common pitfalls in how these tools resolve and access files, a pattern typical of older utilities that predate modern secure-path conventions. Current severity, exploitation activity, and CVE counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gsi over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-2213HIGH Untrusted search path vulnerability in SemiDynaEXE (SemiDynaEXE2008.EXE) ver. 1.0.2 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | Jun 9, 2017 | 7.8 | 24 | NO | NO |
CVE-2017-2212HIGH Untrusted search path vulnerability in TKY2JGD (TKY2JGD1379.EXE) ver. 1.3.79 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | Jun 9, 2017 | 7.8 | 24 | NO | NO |
CVE-2017-2211HIGH Untrusted search path vulnerability in PatchJGD (Hyoko) (PatchJGDh101.EXE) ver. 1.0.1 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | Jun 9, 2017 | 7.8 | 24 | NO | NO |
CVE-2016-4814HIGH Directory traversal vulnerability in kml2jsonp.php in Geospatial Information Authority of Japan (aka GSI) Old_GSI_Maps before January 2015 on Windows allows remote attackers to rea | Jun 19, 2016 | 7.5 | 23 | NO | NO |
CVE-2017-2210HIGH Untrusted search path vulnerability in PatchJGD (PatchJGD101.EXE) ver. 1.0.1 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | Jun 9, 2017 | 7.8 | 20 | NO | NO |
CVE-2018-13540HIGH The mintToken function of a smart contract implementation for GSI, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitra | Jul 9, 2018 | 7.5 | 19 | NO | NO |
CVE-2018-13233HIGH The sell function of a smart contract implementation for GSI, an Ethereum token, has an integer overflow in which "amount * sellPrice" can be zero, consequently reducing a seller's | Jul 5, 2018 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gsi.
Media articles that mention a CVE ID that affects a product developed by Gsi — matched by CVE ID, not by vendor name.