Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Umn

First CVE: Mar 31, 2009Active for: 17 yearsTotal CVEs: 14
55.8
VTI Score
TOP TARGET

Umn's vulnerability profile centers on MapServer, a widely embedded geospatial web mapping application found in government, research, and enterprise GIS deployments. The recurring weakness classes—memory-buffer violations, SQL injection, sensitive information exposure, input validation, and path-traversal flaws—reflect the application's role parsing user-supplied map requests and database queries, and public exploit code has been associated with vulnerabilities in this product. Current severity and exploitation activity are shown alongside this summary.

FAUCET AI Generated
14
Total CVEs
More Total CVEs than 94% of tracked vendors
3.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
8.1
Avg CVSS Score
Higher Avg CVSS Score than 78% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Umn over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 31, 2009
17 years ago
Most Recent CVE
Jan 5, 2014
4,583 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (14 CVEs).

14 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2011-2975MEDIUM
Double free vulnerability in the msAddImageSymbol function in mapsymbol.c in MapServer before 6.0.1 might allow remote attackers to cause a denial of service (application crash) or
Aug 1, 20116.833NOYES
CVE-2010-2540HIGH
mapserv.c in mapserv in MapServer before 4.10.6 and 5.x before 5.6.4 does not properly restrict the use of CGI command-line arguments that were intended for debugging, which allows
Aug 2, 201010.029NONO
CVE-2009-0839HIGH
Stack-based buffer overflow in mapserv.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2, when the server has a map with a long IMAGEPATH or NAME attribute, allows r
Mar 31, 200910.028NONO
CVE-2009-2281HIGH
Multiple heap-based buffer underflows in the readPostBody function in cgiutil.c in mapserv in MapServer 4.x through 4.10.4 and 5.x before 5.4.2 allow remote attackers to execute ar
Oct 23, 200910.027NONO
CVE-2009-1176HIGH
mapserv.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 does not ensure that the string holding the id parameter ends in a '\0' character, which allows remote atta
Mar 31, 200910.026NONO
CVE-2009-0841HIGH
Directory traversal vulnerability in mapserv.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2, when running on Windows with Cygwin, allows remote attackers to creat
Mar 31, 200910.026NONO
CVE-2009-0840HIGH
Heap-based buffer underflow in the readPostBody function in cgiutil.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 allows remote attackers to have an unknown impa
Mar 31, 200910.026NONO
CVE-2009-1177HIGH
Multiple stack-based buffer overflows in maptemplate.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 have unknown impact and remote attack vectors.
Mar 31, 200910.025NONO
CVE-2011-2704HIGH
Stack-based buffer overflow in MapServer before 4.10.7 and 5.x before 5.6.7 allows remote attackers to execute arbitrary code via vectors related to OGC filter encoding.
Aug 1, 20117.524NONO
CVE-2013-7262MEDIUM
SQL injection vulnerability in the msPostGISLayerSetTimeFilter function in mappostgis.c in MapServer before 6.4.1, when a WMS-Time service is used, allows remote attackers to execu
Jan 5, 20146.823NONO
View all 14 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products14 CVEs
21%
71%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown14 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown14 (100.0%)
User Interaction
None0 (0.0%)
Unknown14 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown14 (100.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (14 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
7.1% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Umn.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Umn — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Umn's Products

View all 2 CNAs →

Top CWEs