Vulnerabilities > Apache > Subversion > 1.6.0
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2014-12-18 | CVE-2014-3580 | Remote Denial of Service vulnerability in Apache Subversion The mod_dav_svn Apache HTTPD server module in Apache Subversion 1.x before 1.7.19 and 1.8.x before 1.8.11 allows remote attackers to cause a denial of service (NULL pointer dereference and server crash) via a REPORT request for a resource that does not exist. | 5.0 |
2014-08-19 | CVE-2014-3528 | Credentials Management vulnerability in multiple products Apache Subversion 1.0.0 through 1.7.x before 1.7.17 and 1.8.x before 1.8.10 uses an MD5 hash of the URL and authentication realm to store cached credentials, which makes it easier for remote servers to obtain the credentials via a crafted authentication realm. | 4.0 |
2014-08-19 | CVE-2014-3522 | Improper Validation of Certificate With Host Mismatch vulnerability in multiple products The Serf RA layer in Apache Subversion 1.4.0 through 1.7.x before 1.7.18 and 1.8.x before 1.8.10 does not properly handle wildcards in the Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof servers via a crafted certificate. | 4.0 |
2013-12-07 | CVE-2013-4505 | Permissions, Privileges, and Access Controls vulnerability in Apache MOD Dontdothat and Subversion The is_this_legal function in mod_dontdothat for Apache Subversion 1.4.0 through 1.7.13 and 1.8.0 through 1.8.4 allows remote attackers to bypass intended access restrictions and possibly cause a denial of service (resource consumption) via a relative URL in a REPORT request. | 2.6 |
2013-09-16 | CVE-2013-4277 | Permissions, Privileges, and Access Controls vulnerability in Apache Subversion Svnserve in Apache Subversion 1.4.0 through 1.7.12 and 1.8.0 through 1.8.1 allows local users to overwrite arbitrary files or kill arbitrary processes via a symlink attack on the file specified by the --pid-file option. | 3.3 |
2013-07-31 | CVE-2013-2112 | Remote Denial of Service vulnerability in Apache Subversion The svnserve server in Subversion before 1.6.23 and 1.7.x before 1.7.10 allows remote attackers to cause a denial of service (exit) by aborting a connection. | 7.8 |
2013-07-31 | CVE-2013-2088 | Improper Input Validation vulnerability in multiple products contrib/hook-scripts/svn-keyword-check.pl in Subversion before 1.6.23 allows remote authenticated users with commit permissions to execute arbitrary commands via shell metacharacters in a filename. | 7.1 |
2013-07-31 | CVE-2013-1968 | Remote Denial of Service vulnerability in Apache Subversion Subversion before 1.6.23 and 1.7.x before 1.7.10 allows remote authenticated users to cause a denial of service (FSFS repository corruption) via a newline character in a file name. | 5.5 |
2013-05-02 | CVE-2013-1849 | Unspecified vulnerability in Apache Subversion The mod_dav_svn Apache HTTPD server module in Subversion 1.6.x through 1.6.20 and 1.7.0 through 1.7.8 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a PROPFIND request for an activity URL. network apache | 4.3 |
2013-05-02 | CVE-2013-1847 | Unspecified vulnerability in Apache Subversion The mod_dav_svn Apache HTTPD server module in Subversion 1.6.0 through 1.6.20 and 1.7.0 through 1.7.8 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an anonymous LOCK for a URL that does not exist. | 5.0 |