Skip to main content

Vendor/product archive

apache / subversion CVEs

Beta · best-effort

48 CVEs tagged to apache / subversion1 Critical, 11 High, 28 Medium, 8 Low, 0 Unrated.

CVE-2024-45720

Published Oct 9, 2024

On Windows platforms, a "best fit" character encoding conversion of command line arguments to Subversion's executables (e.g., svn.exe, etc.) may lead to unexpected command line ar…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2020-17525

Published Mar 17, 2021

Subversion's mod_authz_svn module will crash if the server is using in-repository authz rules with the AuthzSVNReposRelativeAccessFile option and a client sends a request for a no…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-0203

Published Sep 26, 2019

In Apache Subversion versions up to and including 1.9.10, 1.10.4, 1.12.0, Subversion's svnserve server process may exit when a client sends certain sequences of protocol commands.…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-11782

Published Sep 26, 2019

In Apache Subversion versions up to and including 1.9.10, 1.10.4, 1.12.0, Subversion's svnserve server process may exit when a well-formed read-only request produces a particular…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-11803

Published Feb 5, 2019

Subversion's mod_dav_svn Apache HTTPD module versions 1.11.0 and 1.10.0 to 1.10.3 will crash after dereferencing an uninitialized pointer if the client omits the root path in a re…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2013-4246

Published Oct 30, 2017

libsvn_fs_fs/fs_fs.c in Apache Subversion 1.8.x before 1.8.2 might allow remote authenticated users with commit access to corrupt FSFS repositories and cause a denial of service o…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-8734

Published Oct 16, 2017

Apache Subversion's mod_dontdothat module and HTTP clients 1.4.0 through 1.8.16, and 1.9.0 through 1.9.4 are vulnerable to a denial-of-service attack caused by exponential XML ent…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-9800

Published Aug 11, 2017

A maliciously constructed svn+ssh:// URL would cause Subversion clients before 1.8.19, 1.9.x before 1.9.7, and 1.10.0.x through 1.10.0-alpha3 to run an arbitrary shell command. Su…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-2168

Published May 5, 2016

The req_check_access function in the mod_authz_svn module in the httpd server in Apache Subversion before 1.8.16 and 1.9.x before 1.9.4 allows remote authenticated users to cause…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-2167

Published May 5, 2016

The canonicalize_username function in svnserve/cyrus_auth.c in Apache Subversion before 1.8.16 and 1.9.x before 1.9.4, when Cyrus SASL authentication is used, allows remote attack…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-5343

Published Apr 14, 2016

Integer overflow in util.c in mod_dav_svn in Apache Subversion 1.7.x, 1.8.x before 1.8.15, and 1.9.x before 1.9.3 allows remote authenticated users to cause a denial of service (s…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2015-5259

Published Jan 8, 2016

Integer overflow in the read_string function in libsvn_ra_svn/marshal.c in Apache Subversion 1.9.x before 1.9.3 allows remote attackers to execute arbitrary code via an svn:// pro…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2015-3187

Published Aug 12, 2015

The svn_repos_trace_node_locations function in Apache Subversion before 1.7.21 and 1.8.x before 1.8.14, when path-based authorization is used, allows remote authenticated users to…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-0251

Published Apr 8, 2015

The mod_dav_svn server in Subversion 1.5.0 through 1.7.19 and 1.8.0 through 1.8.11 allows remote authenticated users to spoof the svn:author property via a crafted v1 HTTP protoco…

CVSS 4.0 · Medium

CVE-2015-0248

Published Apr 8, 2015

The (1) mod_dav_svn and (2) svnserve servers in Subversion 1.6.0 through 1.7.19 and 1.8.0 through 1.8.11 allow remote attackers to cause a denial of service (assertion failure and…

CVSS 5.0 · Medium

CVE-2015-0202

Published Apr 8, 2015

The mod_dav_svn server in Subversion 1.8.0 through 1.8.11 allows remote attackers to cause a denial of service (memory consumption) via a large number of REPORT requests, which tr…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2014-3528

Published Aug 19, 2014

Apache Subversion 1.0.0 through 1.7.x before 1.7.17 and 1.8.x before 1.8.10 uses an MD5 hash of the URL and authentication realm to store cached credentials, which makes it easier…

CVSS 4.0 · Medium
Showing 1-25 of 48 CVEsPage 1 of 2