Apache / Subversion
47 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2024-46901 | Apache Subversion: mod_dav_svn denial-of-service via control characters in paths | MEDIUM | 4.3 | Dec 9, 2024 |
| CVE-2024-45720 | Apache Subversion: Command line argument injection on Windows platforms | HIGH | 8.2 | Oct 9, 2024 |
| CVE-2022-24070 | Apache Subversion mod_dav_svn is vulnerable to memory corruption | HIGH | 7.5 | Apr 12, 2022 |
| CVE-2021-28544 | Apache Subversion SVN authz protected copyfrom paths regression | MEDIUM | 4.3 | Apr 12, 2022 |
| CVE-2020-17525 | Remote unauthenticated denial-of-service in Subversion mod_authz_svn | HIGH | 7.5 | Mar 17, 2021 |
| CVE-2019-0203 | subversion: NULL pointer dereference in svnserve leading to an unauthenticated remote DoS | HIGH | 7.5 | Sep 26, 2019 |
| CVE-2018-11782 | subversion: remotely triggerable DoS vulnerability in svnserve 'get-deleted-rev' | MEDIUM | 6.5 | Sep 26, 2019 |
| CVE-2018-11803 | subversion: malicious SVN clients can crash mod_dav_svn | HIGH | 7.5 | Feb 5, 2019 |
| CVE-2013-4246 | subversion: FSFS repository corruption due to editing packed revision properties | HIGH | 8.8 | Oct 30, 2017 |
| CVE-2016-8734 | subversion: unrestricted XML entity expansion in mod_dontdothat and Subversion clients using http(s):// | MEDIUM | 6.5 | Oct 16, 2017 |
| CVE-2017-9800 | subversion: Command injection through clients via malicious svn+ssh URLs | CRITICAL | 9.8 | Aug 11, 2017 |
| CVE-2016-2168 | subversion: DoS in mod_authz_svn during COPY/MOVE authorization check | MEDIUM | 6.5 | May 5, 2016 |
| CVE-2016-2167 | subversion: svnserve/sasl may authenticate users using the wrong realm | MEDIUM | 6.8 | May 5, 2016 |
| CVE-2015-5343 | subversion: (mod_dav_svn) integer overflow when parsing skel-encoded request bodies | HIGH | 7.6 | Apr 14, 2016 |
| CVE-2015-5259 | subversion: integer overflow in the svn:// protocol parser | HIGH | 8.6 | Jan 8, 2016 |
| CVE-2015-3187 | subversion: svn_repos_trace_node_locations() reveals paths hidden by authz | MEDIUM | 4.0 | Aug 12, 2015 |
| CVE-2015-3184 | subversion: Mixed anonymous/authenticated path-based authz with httpd 2.4 | MEDIUM | 5.0 | Aug 12, 2015 |
| CVE-2015-0251 | subversion: (mod_dav_svn) spoofing svn:author property values for new revisions | MEDIUM | 4.0 | Apr 8, 2015 |
| CVE-2015-0248 | subversion: (mod_dav_svn) remote denial of service with certain requests with dynamically evaluated revision numbers | MEDIUM | 5.0 | Apr 8, 2015 |
| CVE-2015-0202 | subversion: (mod_dav_svn) remote denial of service with certain REPORT requests | HIGH | 7.8 | Apr 8, 2015 |
| CVE-2014-8108 | subversion: NULL pointer dereference flaw in mod_dav_svn when handling URIs for virtual transaction names | MEDIUM | 5.0 | Dec 18, 2014 |
| CVE-2014-3580 | subversion: NULL pointer dereference flaw in mod_dav_svn when handling REPORT requests | MEDIUM | 5.0 | Dec 18, 2014 |
| CVE-2014-3528 | subversion: credentials leak via MD5 collision | MEDIUM | 4.0 | Aug 19, 2014 |
| CVE-2014-3522 | subversion: incorrect SSL certificate validation in Serf RA (repository access) layer | MEDIUM | 4.0 | Aug 19, 2014 |
| CVE-2014-3504 | The (1) serf_ssl_cert_issuer, (2) serf_ssl_cert_subject, and (3) serf_ssl_cert_certificate functions in Serf 0.2.0 through 1.3.x before 1.3.7 does not properly… | MEDIUM | 4.0 | Aug 19, 2014 |
Showing 1 to 25 of 47 CVEs