CVE-2024-46901
- EPSS 16.72%
- Veröffentlicht 09.12.2024 10:15:05
- Zuletzt bearbeitet 15.07.2025 16:35:39
Insufficient validation of filenames against control characters in Apache Subversion repositories served via mod_dav_svn allows authenticated users with commit access to commit a corrupted revision, leading to disruption for users of the repository. ...
CVE-2024-45720
- EPSS 0.09%
- Veröffentlicht 09.10.2024 13:15:11
- Zuletzt bearbeitet 11.02.2025 17:22:19
On Windows platforms, a "best fit" character encoding conversion of command line arguments to Subversion's executables (e.g., svn.exe, etc.) may lead to unexpected command line argument interpretation, including argument injection and execution of ot...
CVE-2022-24070
- EPSS 0.56%
- Veröffentlicht 12.04.2022 18:15:09
- Zuletzt bearbeitet 21.11.2024 06:49:45
Subversion's mod_dav_svn is vulnerable to memory corruption. While looking up path-based authorization rules, mod_dav_svn servers may attempt to use memory which has already been freed. Affected Subversion mod_dav_svn servers 1.10.0 through 1.14.1 (i...
CVE-2021-28544
- EPSS 0.29%
- Veröffentlicht 12.04.2022 18:15:08
- Zuletzt bearbeitet 21.11.2024 05:59:49
Apache Subversion SVN authz protected copyfrom paths regression Subversion servers reveal 'copyfrom' paths that should be hidden according to configured path-based authorization (authz) rules. When a node has been copied from a protected location, us...
CVE-2020-17525
- EPSS 14.62%
- Veröffentlicht 17.03.2021 10:15:11
- Zuletzt bearbeitet 21.11.2024 05:08:17
Subversion's mod_authz_svn module will crash if the server is using in-repository authz rules with the AuthzSVNReposRelativeAccessFile option and a client sends a request for a non-existing repository URL. This can lead to disruption for users of the...
CVE-2019-0203
- EPSS 5.79%
- Veröffentlicht 26.09.2019 16:15:10
- Zuletzt bearbeitet 21.11.2024 04:16:28
In Apache Subversion versions up to and including 1.9.10, 1.10.4, 1.12.0, Subversion's svnserve server process may exit when a client sends certain sequences of protocol commands. This can lead to disruption for users of the server.
CVE-2018-11782
- EPSS 1.1%
- Veröffentlicht 26.09.2019 16:15:10
- Zuletzt bearbeitet 21.11.2024 03:44:01
In Apache Subversion versions up to and including 1.9.10, 1.10.4, 1.12.0, Subversion's svnserve server process may exit when a well-formed read-only request produces a particular answer. This can lead to disruption for users of the server.
CVE-2018-11803
- EPSS 0.83%
- Veröffentlicht 05.02.2019 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:44:03
Subversion's mod_dav_svn Apache HTTPD module versions 1.11.0 and 1.10.0 to 1.10.3 will crash after dereferencing an uninitialized pointer if the client omits the root path in a recursive directory listing operation.
CVE-2013-4246
- EPSS 0.39%
- Veröffentlicht 30.10.2017 14:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
libsvn_fs_fs/fs_fs.c in Apache Subversion 1.8.x before 1.8.2 might allow remote authenticated users with commit access to corrupt FSFS repositories and cause a denial of service or obtain sensitive information by editing packed revision properties.
CVE-2016-8734
- EPSS 12.88%
- Veröffentlicht 16.10.2017 13:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Apache Subversion's mod_dontdothat module and HTTP clients 1.4.0 through 1.8.16, and 1.9.0 through 1.9.4 are vulnerable to a denial-of-service attack caused by exponential XML entity expansion. The attack can cause the targeted process to consume an ...