Skip to main content

Vendor/product archive

osgeo / gdal CVEs

Beta · best-effort

12 CVEs tagged to osgeo / gdal1 Critical, 3 High, 2 Medium, 6 Low, 0 Unrated.

CVE-2026-49014

Published May 27, 2026

In GDAL 3.1.0 through 3.13.0, scanForGeometryContainers in the netCDF driver allows code execution via a stack-based buffer overflow. It reads a geometry attribute into a fixed-si…

CVSS 7.4 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-8213

Published May 9, 2026

A vulnerability has been found in OSGeo gdal up to 3.13.0dev-4. Affected by this issue is the function GDSDfldsrch of the file frmts/hdf4/hdf-eos/GDapi.c of the component Grid Fil…

CVSS 1.9 · Low
evidence mentions
8
Buzz score
37.5
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-8212

Published May 9, 2026

A flaw has been found in OSGeo gdal up to 3.13.0dev-4. Affected by this vulnerability is the function SWSDfldsrch of the file frmts/hdf4/hdf-eos/SWapi.c. Executing a manipulation…

CVSS 1.9 · Low
evidence mentions
8
Buzz score
37.5
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-8088

Published May 7, 2026

A weakness has been identified in OSGeo gdal up to 3.13.0dev-4. The affected element is the function GDfieldinfo of the file frmts/hdf4/hdf-eos/GDapi.c. Executing a manipulation c…

CVSS 1.9 · Low
evidence mentions
8
Buzz score
37.5
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-8087

Published May 7, 2026

A security flaw has been discovered in OSGeo gdal up to 3.13.0dev-4. Impacted is the function GDnentries of the file frmts/hdf4/hdf-eos/GDapi.c. Performing a manipulation of the a…

CVSS 1.9 · Low
evidence mentions
8
Buzz score
37.5
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-8086

Published May 7, 2026

A vulnerability was identified in OSGeo gdal up to 3.13.0dev-4. This issue affects the function SWnentries of the file frmts/hdf4/hdf-eos/SWapi.c. Such manipulation of the argumen…

CVSS 1.9 · Low
evidence mentions
9
Buzz score
38.5
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-8084

Published May 7, 2026

A vulnerability was determined in OSGeo gdal up to 3.13.0dev-4. This vulnerability affects the function memmove of the file frmts/hdf4/hdf-eos/SWapi.c of the component HDF-EOS Gri…

CVSS 1.9 · Low
evidence mentions
9
Buzz score
38.5
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-29480

Published Apr 7, 2025

Buffer Overflow vulnerability in gdal 3.10.2 allows a local attacker to cause a denial of service via the OGRSpatialReference::Release function. NOTE: the Supplier indicates that…

CVSS 5.5 · Medium
evidence mentions
2
Buzz score
20.5
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2019-25050

Published Jul 20, 2021

netCDF in GDAL 2.4.2 through 3.0.4 has a stack-based buffer overflow in nc4_get_att (called from nc4_get_att_tc and nc_get_att_text) and in uffd_cleanup (called from netCDFDataset…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-17546

Published Oct 14, 2019

tif_getimage.c in LibTIFF through 4.0.10, as used in GDAL through 3.0.1 and other products, has an integer overflow that potentially causes a heap-based buffer overflow via a craf…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-12 of 12 CVEsPage 1 of 1