Show filters
71 Total Results
Displaying 61-70 of 71
Sort by:
Attacker Value
Unknown
CVE-2011-0715
Disclosure Date: March 11, 2011 (last updated October 04, 2023)
The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.16, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a request that contains a lock token.
0
Attacker Value
Unknown
CVE-2010-4539
Disclosure Date: January 07, 2011 (last updated October 04, 2023)
The walk function in repos.c in the mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.15, allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) via vectors that trigger the walking of SVNParentPath collections.
0
Attacker Value
Unknown
CVE-2010-4644
Disclosure Date: January 07, 2011 (last updated October 04, 2023)
Multiple memory leaks in rev_hunt.c in Apache Subversion before 1.6.15 allow remote authenticated users to cause a denial of service (memory consumption and daemon crash) via the -g option to the blame command.
0
Attacker Value
Unknown
CVE-2010-3315
Disclosure Date: October 04, 2010 (last updated October 04, 2023)
authz.c in the mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x before 1.5.8 and 1.6.x before 1.6.13, when SVNPathAuthz short_circuit is enabled, does not properly handle a named repository as a rule scope, which allows remote authenticated users to bypass intended access restrictions via svn commands.
0
Attacker Value
Unknown
CVE-2009-2411
Disclosure Date: August 07, 2009 (last updated October 04, 2023)
Multiple integer overflows in the libsvn_delta library in Subversion before 1.5.7, and 1.6.x before 1.6.4, allow remote authenticated users and remote Subversion servers to execute arbitrary code via an svndiff stream with large windows that trigger a heap-based buffer overflow, a related issue to CVE-2009-2412.
0
Attacker Value
Unknown
CVE-2007-3846
Disclosure Date: August 28, 2007 (last updated October 04, 2023)
Directory traversal vulnerability in Subversion before 1.4.5, as used by TortoiseSVN before 1.4.5 and possibly other products, when run on Windows-based systems, allows remote authenticated users to overwrite and create arbitrary files via a ..\ (dot dot backslash) sequence in the filename, as stored in the file repository.
0
Attacker Value
Unknown
CVE-2007-2448
Disclosure Date: June 14, 2007 (last updated October 04, 2023)
Subversion 1.4.3 and earlier does not properly implement the "partial access" privilege for users who have access to changed paths but not copied paths, which allows remote authenticated users to obtain sensitive information (revision properties) via svn (1) propget, (2) proplist, or (3) propedit.
0
Attacker Value
Unknown
CVE-2004-1438
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
The mod_authz_svn Apache module for Subversion 1.0.4-r1 and earlier allows remote authenticated users, with write access to the repository, to read unauthorized parts of the repository via the svn copy command.
0
Attacker Value
Unknown
CVE-2004-0749
Disclosure Date: December 23, 2004 (last updated February 22, 2025)
The mod_authz_svn module in Subversion 1.0.7 and earlier does not properly restrict access to all metadata on unreadable paths, which could allow remote attackers to gain sensitive information via (1) svn log -v, (2) svn propget, or (3) svn blame, and other commands that follow renames.
0
Attacker Value
Unknown
CVE-2004-0413
Disclosure Date: August 06, 2004 (last updated February 22, 2025)
libsvn_ra_svn in Subversion 1.0.4 trusts the length field of (1) svn://, (2) svn+ssh://, and (3) other svn protocol URL strings, which allows remote attackers to cause a denial of service (memory consumption) and possibly execute arbitrary code via an integer overflow that leads to a heap-based buffer overflow.
0