Vulnerabilities > Apache > Subversion > 0.13.0

DATE CVE VULNERABILITY TITLE RISK
2019-09-26 CVE-2019-0203 Improper Input Validation vulnerability in Apache Subversion
In Apache Subversion versions up to and including 1.9.10, 1.10.4, 1.12.0, Subversion's svnserve server process may exit when a client sends certain sequences of protocol commands.
network
low complexity
apache CWE-20
5.0
2019-09-26 CVE-2018-11782 Improper Input Validation vulnerability in Apache Subversion
In Apache Subversion versions up to and including 1.9.10, 1.10.4, 1.12.0, Subversion's svnserve server process may exit when a well-formed read-only request produces a particular answer.
network
low complexity
apache CWE-20
4.0
2017-08-11 CVE-2017-9800 Improper Input Validation vulnerability in Apache Subversion
A maliciously constructed svn+ssh:// URL would cause Subversion clients before 1.8.19, 1.9.x before 1.9.7, and 1.10.0.x through 1.10.0-alpha3 to run an arbitrary shell command.
network
low complexity
apache CWE-20
critical
9.8
2016-05-05 CVE-2016-2168 Unspecified vulnerability in Apache Subversion
The req_check_access function in the mod_authz_svn module in the httpd server in Apache Subversion before 1.8.16 and 1.9.x before 1.9.4 allows remote authenticated users to cause a denial of service (NULL pointer dereference and crash) via a crafted header in a (1) MOVE or (2) COPY request, involving an authorization check.
network
low complexity
apache
6.5
2016-05-05 CVE-2016-2167 Improper Access Control vulnerability in Apache Subversion
The canonicalize_username function in svnserve/cyrus_auth.c in Apache Subversion before 1.8.16 and 1.9.x before 1.9.4, when Cyrus SASL authentication is used, allows remote attackers to authenticate and bypass intended access restrictions via a realm string that is a prefix of an expected repository realm string.
network
high complexity
apache CWE-284
6.8
2015-08-12 CVE-2015-3187 Information Exposure vulnerability in multiple products
The svn_repos_trace_node_locations function in Apache Subversion before 1.7.21 and 1.8.x before 1.8.14, when path-based authorization is used, allows remote authenticated users to obtain sensitive path information by reading the history of a node that has been moved from a hidden path.
network
low complexity
apache apple CWE-200
4.0
2013-07-31 CVE-2013-2112 Remote Denial of Service vulnerability in Apache Subversion
The svnserve server in Subversion before 1.6.23 and 1.7.x before 1.7.10 allows remote attackers to cause a denial of service (exit) by aborting a connection.
network
low complexity
apache collabnet canonical opensuse
7.8
2013-07-31 CVE-2013-2088 Improper Input Validation vulnerability in multiple products
contrib/hook-scripts/svn-keyword-check.pl in Subversion before 1.6.23 allows remote authenticated users with commit permissions to execute arbitrary commands via shell metacharacters in a filename.
network
high complexity
apache collabnet opensuse CWE-20
7.1
2013-07-31 CVE-2013-1968 Remote Denial of Service vulnerability in Apache Subversion
Subversion before 1.6.23 and 1.7.x before 1.7.10 allows remote authenticated users to cause a denial of service (FSFS repository corruption) via a newline character in a file name.
network
low complexity
apache collabnet canonical opensuse
5.5
2013-05-02 CVE-2013-1846 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products
The mod_dav_svn Apache HTTPD server module in Subversion 1.6.x before 1.6.21 and 1.7.0 through 1.7.8 allows remote authenticated users to cause a denial of service (NULL pointer dereference and crash) via a LOCK on an activity URL.
network
low complexity
apache opensuse CWE-119
4.0