8.5

CVE-2009-2411

Multiple integer overflows in the libsvn_delta library in Subversion before 1.5.7, and 1.6.x before 1.6.4, allow remote authenticated users and remote Subversion servers to execute arbitrary code via an svndiff stream with large windows that trigger a heap-based buffer overflow, a related issue to CVE-2009-2412.

Data is provided by the National Vulnerability Database (NVD)
SubversionSubversion Version <= 1.5.6
SubversionSubversion Version0.22.1
SubversionSubversion Version0.23.0
SubversionSubversion Version0.24.0
SubversionSubversion Version0.24.1
SubversionSubversion Version0.24.2
SubversionSubversion Version0.25.0
SubversionSubversion Version0.27.0
SubversionSubversion Version0.28.0
SubversionSubversion Version0.28.1
SubversionSubversion Version0.28.2
SubversionSubversion Version0.29.0
SubversionSubversion Version0.30.0
SubversionSubversion Version0.31.0
SubversionSubversion Version0.32.0
SubversionSubversion Version0.32.1
SubversionSubversion Version0.33.0
SubversionSubversion Version0.33.1
SubversionSubversion Version0.34.0
SubversionSubversion Version0.35.0
SubversionSubversion Version0.35.1
SubversionSubversion Version0.36.0
SubversionSubversion Version0.37.0
SubversionSubversion Version1.0
SubversionSubversion Version1.0.0
SubversionSubversion Version1.0.1
SubversionSubversion Version1.0.2
SubversionSubversion Version1.0.3
SubversionSubversion Version1.0.4
SubversionSubversion Version1.0.5
SubversionSubversion Version1.0.6
SubversionSubversion Version1.0.7
SubversionSubversion Version1.0.8
SubversionSubversion Version1.0.9
SubversionSubversion Version1.1.0
SubversionSubversion Version1.1.0_rc1
SubversionSubversion Version1.1.0_rc2
SubversionSubversion Version1.1.0_rc3
SubversionSubversion Version1.1.1
SubversionSubversion Version1.1.2
SubversionSubversion Version1.1.3
SubversionSubversion Version1.1.4
SubversionSubversion Version1.2.0
SubversionSubversion Version1.2.1
SubversionSubversion Version1.2.2
SubversionSubversion Version1.2.3
SubversionSubversion Version1.3.0
SubversionSubversion Version1.3.1
SubversionSubversion Version1.3.2
SubversionSubversion Version1.4.0
SubversionSubversion Version1.4.1
SubversionSubversion Version1.4.2
SubversionSubversion Version1.4.3
SubversionSubversion Version1.4.4
SubversionSubversion Version1.4.5
SubversionSubversion Version1.5.0
SubversionSubversion Version1.5.1
SubversionSubversion Version1.5.3
SubversionSubversion Version1.5.4
SubversionSubversion Version1.5.5
SubversionSubversion Version1.6.0
SubversionSubversion Version1.6.1
SubversionSubversion Version1.6.2
SubversionSubversion Version1.6.3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 6.17% 0.898
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 8.5 6.8 10
AV:N/AC:M/Au:S/C:C/I:C/A:C