Show filters
21 Total Results
Displaying 11-20 of 21
Sort by:
Attacker Value
Unknown

CVE-2013-4558

Disclosure Date: December 07, 2013 (last updated October 05, 2023)
The get_parent_resource function in repos.c in mod_dav_svn Apache HTTPD server module in Subversion 1.7.11 through 1.7.13 and 1.8.1 through 1.8.4, when built with assertions enabled and SVNAutoversioning is enabled, allows remote attackers to cause a denial of service (assertion failure and Apache process abort) via a non-canonical URL in a request, as demonstrated using a trailing /.
0
Attacker Value
Unknown

CVE-2013-4505

Disclosure Date: December 07, 2013 (last updated October 05, 2023)
The is_this_legal function in mod_dontdothat for Apache Subversion 1.4.0 through 1.7.13 and 1.8.0 through 1.8.4 allows remote attackers to bypass intended access restrictions and possibly cause a denial of service (resource consumption) via a relative URL in a REPORT request.
0
Attacker Value
Unknown

CVE-2013-4277

Disclosure Date: September 16, 2013 (last updated October 05, 2023)
Svnserve in Apache Subversion 1.4.0 through 1.7.12 and 1.8.0 through 1.8.1 allows local users to overwrite arbitrary files or kill arbitrary processes via a symlink attack on the file specified by the --pid-file option.
0
Attacker Value
Unknown

CVE-2013-1968

Disclosure Date: July 31, 2013 (last updated October 05, 2023)
Subversion before 1.6.23 and 1.7.x before 1.7.10 allows remote authenticated users to cause a denial of service (FSFS repository corruption) via a newline character in a file name.
0
Attacker Value
Unknown

CVE-2013-2112

Disclosure Date: July 31, 2013 (last updated October 05, 2023)
The svnserve server in Subversion before 1.6.23 and 1.7.x before 1.7.10 allows remote attackers to cause a denial of service (exit) by aborting a connection.
0
Attacker Value
Unknown

CVE-2013-4131

Disclosure Date: July 31, 2013 (last updated October 05, 2023)
The mod_dav_svn Apache HTTPD server module in Subversion 1.7.0 through 1.7.10 and 1.8.x before 1.8.1 allows remote authenticated users to cause a denial of service (assertion failure or out-of-bounds read) via a certain (1) COPY, (2) DELETE, or (3) MOVE request against a revision root.
0
Attacker Value
Unknown

CVE-2013-1849

Disclosure Date: May 02, 2013 (last updated October 05, 2023)
The mod_dav_svn Apache HTTPD server module in Subversion 1.6.x through 1.6.20 and 1.7.0 through 1.7.8 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a PROPFIND request for an activity URL.
0
Attacker Value
Unknown

CVE-2013-1845

Disclosure Date: May 02, 2013 (last updated October 05, 2023)
The mod_dav_svn Apache HTTPD server module in Subversion 1.6.x before 1.6.21 and 1.7.0 through 1.7.8 allows remote authenticated users to cause a denial of service (memory consumption) by (1) setting or (2) deleting a large number of properties for a file or directory.
0
Attacker Value
Unknown

CVE-2013-1846

Disclosure Date: May 02, 2013 (last updated October 05, 2023)
The mod_dav_svn Apache HTTPD server module in Subversion 1.6.x before 1.6.21 and 1.7.0 through 1.7.8 allows remote authenticated users to cause a denial of service (NULL pointer dereference and crash) via a LOCK on an activity URL.
0
Attacker Value
Unknown

CVE-2013-1884

Disclosure Date: May 02, 2013 (last updated October 05, 2023)
The mod_dav_svn Apache HTTPD server module in Subversion 1.7.0 through 1.7.8 allows remote attackers to cause a denial of service (segmentation fault and crash) via a log REPORT request with an invalid limit, which triggers an access of an uninitialized variable.
0