CVE-2017-9800
- EPSS 53.58%
- Veröffentlicht 11.08.2017 21:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
A maliciously constructed svn+ssh:// URL would cause Subversion clients before 1.8.19, 1.9.x before 1.9.7, and 1.10.0.x through 1.10.0-alpha3 to run an arbitrary shell command. Such a URL could be generated by a malicious server, by a malicious user ...
CVE-2016-2168
- EPSS 7.04%
- Veröffentlicht 05.05.2016 18:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
The req_check_access function in the mod_authz_svn module in the httpd server in Apache Subversion before 1.8.16 and 1.9.x before 1.9.4 allows remote authenticated users to cause a denial of service (NULL pointer dereference and crash) via a crafted ...
CVE-2016-2167
- EPSS 0.76%
- Veröffentlicht 05.05.2016 18:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The canonicalize_username function in svnserve/cyrus_auth.c in Apache Subversion before 1.8.16 and 1.9.x before 1.9.4, when Cyrus SASL authentication is used, allows remote attackers to authenticate and bypass intended access restrictions via a realm...
- EPSS 19.09%
- Veröffentlicht 14.04.2016 14:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
Integer overflow in util.c in mod_dav_svn in Apache Subversion 1.7.x, 1.8.x before 1.8.15, and 1.9.x before 1.9.3 allows remote authenticated users to cause a denial of service (subversion server crash or memory consumption) and possibly execute arbi...
- EPSS 40.68%
- Veröffentlicht 08.01.2016 19:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
Integer overflow in the read_string function in libsvn_ra_svn/marshal.c in Apache Subversion 1.9.x before 1.9.3 allows remote attackers to execute arbitrary code via an svn:// protocol string, which triggers a heap-based buffer overflow and an out-of...
- EPSS 0.86%
- Veröffentlicht 12.08.2015 14:59:12
- Zuletzt bearbeitet 12.04.2025 10:46:40
The svn_repos_trace_node_locations function in Apache Subversion before 1.7.21 and 1.8.x before 1.8.14, when path-based authorization is used, allows remote authenticated users to obtain sensitive path information by reading the history of a node tha...
- EPSS 21.35%
- Veröffentlicht 12.08.2015 14:59:10
- Zuletzt bearbeitet 12.04.2025 10:46:40
mod_authz_svn in Apache Subversion 1.7.x before 1.7.21 and 1.8.x before 1.8.14, when using Apache httpd 2.4.x, does not properly restrict anonymous access, which allows remote anonymous users to read hidden files via the path name.
- EPSS 1.52%
- Veröffentlicht 08.04.2015 18:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
The mod_dav_svn server in Subversion 1.5.0 through 1.7.19 and 1.8.0 through 1.8.11 allows remote authenticated users to spoof the svn:author property via a crafted v1 HTTP protocol request sequences.
- EPSS 17.76%
- Veröffentlicht 08.04.2015 18:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
The (1) mod_dav_svn and (2) svnserve servers in Subversion 1.6.0 through 1.7.19 and 1.8.0 through 1.8.11 allow remote attackers to cause a denial of service (assertion failure and abort) via crafted parameter combinations related to dynamically evalu...
CVE-2015-0202
- EPSS 2.08%
- Veröffentlicht 08.04.2015 18:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The mod_dav_svn server in Subversion 1.8.0 through 1.8.11 allows remote attackers to cause a denial of service (memory consumption) via a large number of REPORT requests, which trigger the traversal of FSFS repository nodes.