Vulnerabilities > Apache > Subversion

DATE CVE VULNERABILITY TITLE RISK
2014-08-19 CVE-2014-3528 Credentials Management vulnerability in multiple products
Apache Subversion 1.0.0 through 1.7.x before 1.7.17 and 1.8.x before 1.8.10 uses an MD5 hash of the URL and authentication realm to store cached credentials, which makes it easier for remote servers to obtain the credentials via a crafted authentication realm.
network
high complexity
opensuse apache canonical apple redhat CWE-255
4.0
2014-08-19 CVE-2014-3522 Improper Validation of Certificate With Host Mismatch vulnerability in multiple products
The Serf RA layer in Apache Subversion 1.4.0 through 1.7.x before 1.7.18 and 1.8.x before 1.8.10 does not properly handle wildcards in the Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof servers via a crafted certificate.
network
high complexity
apache opensuse canonical apple CWE-297
4.0
2014-07-28 CVE-2013-7393 Link Following vulnerability in Apache Subversion 1.8.0/1.8.1
The daemonize.py module in Subversion 1.8.0 before 1.8.2 allows local users to gain privileges via a symlink attack on the pid file created for (1) svnwcsub.py or (2) irkerbridge.py when the --pidfile option is used.
local
high complexity
apache CWE-59
2.4
2014-07-28 CVE-2013-4262 Link Following vulnerability in Apache Subversion 1.8.0/1.8.1/1.8.2
svnwcsub.py in Subversion 1.8.0 before 1.8.3, when using the --pidfile option and running in foreground mode, allows local users to gain privileges via a symlink attack on the pid file.
local
high complexity
apache CWE-59
2.4
2013-12-07 CVE-2013-4505 Permissions, Privileges, and Access Controls vulnerability in Apache MOD Dontdothat and Subversion
The is_this_legal function in mod_dontdothat for Apache Subversion 1.4.0 through 1.7.13 and 1.8.0 through 1.8.4 allows remote attackers to bypass intended access restrictions and possibly cause a denial of service (resource consumption) via a relative URL in a REPORT request.
network
high complexity
apache CWE-264
2.6
2013-09-16 CVE-2013-4277 Permissions, Privileges, and Access Controls vulnerability in Apache Subversion
Svnserve in Apache Subversion 1.4.0 through 1.7.12 and 1.8.0 through 1.8.1 allows local users to overwrite arbitrary files or kill arbitrary processes via a symlink attack on the file specified by the --pid-file option.
local
apache CWE-264
3.3
2013-07-31 CVE-2013-4131 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Apache Subversion
The mod_dav_svn Apache HTTPD server module in Subversion 1.7.0 through 1.7.10 and 1.8.x before 1.8.1 allows remote authenticated users to cause a denial of service (assertion failure or out-of-bounds read) via a certain (1) COPY, (2) DELETE, or (3) MOVE request against a revision root.
network
low complexity
apache CWE-119
4.0
2013-07-31 CVE-2013-2112 Remote Denial of Service vulnerability in Apache Subversion
The svnserve server in Subversion before 1.6.23 and 1.7.x before 1.7.10 allows remote attackers to cause a denial of service (exit) by aborting a connection.
network
low complexity
apache collabnet canonical opensuse
7.8
2013-07-31 CVE-2013-2088 Improper Input Validation vulnerability in multiple products
contrib/hook-scripts/svn-keyword-check.pl in Subversion before 1.6.23 allows remote authenticated users with commit permissions to execute arbitrary commands via shell metacharacters in a filename.
network
high complexity
apache collabnet opensuse CWE-20
7.1
2013-07-31 CVE-2013-1968 Remote Denial of Service vulnerability in Apache Subversion
Subversion before 1.6.23 and 1.7.x before 1.7.10 allows remote authenticated users to cause a denial of service (FSFS repository corruption) via a newline character in a file name.
network
low complexity
apache collabnet canonical opensuse
5.5