subversion records
7 published records for vendor subversion.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 14.3%
- Pre-auth RCE
- 2
- With a fix record
- 85.7%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-189 Numeric Errors1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
53Plan | CVE-2004-0397Weaponized | Stack-based buffer overflow during the apr_time_t data conversion in Subversion 1.0.2 and earlier allows remote attackers to execute arbitrasubversion · subversion | High7.5 | — | 75.3% | Jul 7, 2004 |
42Plan | CVE-2004-0413No exploit | libsvn_ra_svn in Subversion 1.0.4 trusts the length field of (1) svn://, (2) svn+ssh://, and (3) other svn protocol URL strings, which allowsubversion · subversion | Critical10.0 | — | 5.9% | Aug 6, 2004 |
36Monitor | CVE-2009-2411No exploit | Multiple integer overflows in the libsvn_delta library in Subversion before 1.5.7, and 1.6.x before 1.6.4, allow remote authenticated users subversion · subversion · CWE-189 | High8.5 | — | 5.1% | Aug 7, 2009 |
24Monitor | CVE-2007-3846No exploit | Directory traversal vulnerability in Subversion before 1.4.5, as used by TortoiseSVN before 1.4.5 and possibly other products, when run on Wsubversion · subversion · CWE-22 | Medium6.0 | — | 1.6% | Aug 28, 2007 |
20Monitor | CVE-2004-0749No exploit | The mod_authz_svn module in Subversion 1.0.7 and earlier does not properly restrict access to all metadata on unreadable paths, which could subversion · subversion | Medium5.0 | — | 1.5% | Dec 23, 2004 |
8Monitor | CVE-2007-2448No exploit | Subversion 1.4.3 and earlier does not properly implement the "partial access" privilege for users who have access to changed paths but not csubversion · subversion | Low2.1 | — | 1.5% | Jun 14, 2007 |
8Monitor | CVE-2004-1438No exploit | The mod_authz_svn Apache module for Subversion 1.0.4-r1 and earlier allows remote authenticated users, with write access to the repository, subversion · subversion | Low2.1 | — | 0.7% | Dec 31, 2004 |
- CVE-2004-039753Plan
Stack-based buffer overflow during the apr_time_t data conversion in Subversion 1.0.2 and earlier allows remote attackers to execute arbitra
HighCVSS 7.5WeaponizedEPSS 75%subversion · subversionJul 7, 2004
- CVE-2004-041342Plan
libsvn_ra_svn in Subversion 1.0.4 trusts the length field of (1) svn://, (2) svn+ssh://, and (3) other svn protocol URL strings, which allow
CriticalCVSS 10.0No exploitEPSS 6%subversion · subversionAug 6, 2004
- CVE-2009-241136Monitor
Multiple integer overflows in the libsvn_delta library in Subversion before 1.5.7, and 1.6.x before 1.6.4, allow remote authenticated users
HighCVSS 8.5No exploitEPSS 5%subversion · subversionAug 7, 2009
- CVE-2007-384624Monitor
Directory traversal vulnerability in Subversion before 1.4.5, as used by TortoiseSVN before 1.4.5 and possibly other products, when run on W
MediumCVSS 6.0No exploitEPSS 2%subversion · subversionAug 28, 2007
- CVE-2004-074920Monitor
The mod_authz_svn module in Subversion 1.0.7 and earlier does not properly restrict access to all metadata on unreadable paths, which could
MediumCVSS 5.0No exploitEPSS 1%subversion · subversionDec 23, 2004
- CVE-2007-24488Monitor
Subversion 1.4.3 and earlier does not properly implement the "partial access" privilege for users who have access to changed paths but not c
LowCVSS 2.1No exploitEPSS 2%subversion · subversionJun 14, 2007
- CVE-2004-14388Monitor
The mod_authz_svn Apache module for Subversion 1.0.4-r1 and earlier allows remote authenticated users, with write access to the repository,
LowCVSS 2.1No exploitEPSS 1%subversion · subversionDec 31, 2004