Subversion
Vendor:
First CVE: Jun 1, 2004 · Active for 22 years
48
Total CVEs
More Total CVEs than 97% of tracked products
4.0
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
5.4
Avg CVSS
Higher Avg CVSS than 14% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Subversion over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 1, 2004
22 years ago
Most Recent CVE
Dec 9, 2024
592 days ago
CVE Severity & Scoring
Subversion48 CVEs
15%
60%
23%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (2.1%)
Network14 (29.2%)
Unknown33 (68.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (29.2%)
High1 (2.1%)
Unknown33 (68.8%)
User Interaction
None15 (31.3%)
Unknown33 (68.8%)
Required0 (0.0%)
Privileges Required
Low9 (18.8%)
High0 (0.0%)
None6 (12.5%)
Unknown33 (68.8%)
Top CVEs
Signals from CVEs in this product scope (48 CVEs).
48 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-11803HIGH Subversion's mod_dav_svn Apache HTTPD module versions 1.11.0 and 1.10.0 to 1.10.3 will crash after dereferencing an uninitialized pointer if the client omits the root path in a rec | Feb 5, 2019 | 7.5 | 58 | NO | NO |
CVE-2013-1884MEDIUM The mod_dav_svn Apache HTTPD server module in Subversion 1.7.0 through 1.7.8 allows remote attackers to cause a denial of service (segmentation fault and crash) via a log REPORT re | May 2, 2013 | 5.0 | 56 | NO | YES |
CVE-2015-5259HIGH Integer overflow in the read_string function in libsvn_ra_svn/marshal.c in Apache Subversion 1.9.x before 1.9.3 allows remote attackers to execute arbitrary code via an svn:// prot | Jan 8, 2016 | 8.6 | 51 | NO | NO |
CVE-2013-1847MEDIUM The mod_dav_svn Apache HTTPD server module in Subversion 1.6.0 through 1.6.20 and 1.7.0 through 1.7.8 allows remote attackers to cause a denial of service (NULL pointer dereference | May 2, 2013 | 5.0 | 49 | NO | YES |
CVE-2013-2088HIGH contrib/hook-scripts/svn-keyword-check.pl in Subversion before 1.6.23 allows remote authenticated users with commit permissions to execute arbitrary commands via shell metacharacte | Jul 31, 2013 | 7.1 | 43 | NO | YES |
CVE-2017-9800CRITICAL A maliciously constructed svn+ssh:// URL would cause Subversion clients before 1.8.19, 1.9.x before 1.9.7, and 1.10.0.x through 1.10.0-alpha3 to run an arbitrary shell command. Suc | Aug 11, 2017 | 9.8 | 41 | NO | NO |
CVE-2020-17525HIGH Subversion's mod_authz_svn module will crash if the server is using in-repository authz rules with the AuthzSVNReposRelativeAccessFile option and a client sends a request for a non | Mar 17, 2021 | 7.5 | 38 | NO | NO |
CVE-2004-0179MEDIUM Multiple format string vulnerabilities in (1) neon 0.24.4 and earlier, and other products that use neon including (2) Cadaver, (3) Subversion, and (4) OpenOffice, allow remote mali | Jun 1, 2004 | 6.8 | 34 | NO | YES |
CVE-2015-5343HIGH Integer overflow in util.c in mod_dav_svn in Apache Subversion 1.7.x, 1.8.x before 1.8.15, and 1.9.x before 1.9.3 allows remote authenticated users to cause a denial of service (su | Apr 14, 2016 | 7.6 | 33 | NO | NO |
CVE-2016-2168MEDIUM The req_check_access function in the mod_authz_svn module in the httpd server in Apache Subversion before 1.8.16 and 1.9.x before 1.9.4 allows remote authenticated users to cause a | May 5, 2016 | 6.5 | 31 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (48 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
8.3% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (48 CVEs).
Media Mentions
Signals from CVEs in this product scope (48 CVEs).
Top CNAs Publishing CVEs For Subversion
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| m4\/m5 | 3 | 4.9 | 5.3% | 0 | 0 |
| m3 | 3 | 4.9 | 5.3% | 0 | 0 |
| m2 | 3 | 4.9 | 5.3% | 0 | 0 |
| m1 | 3 | 4.9 | 5.3% | 0 | 0 |
| 1.9.6 | 1 | 9.8 | 18.9% | 0 | 0 |
| 1.9.5 | 1 | 9.8 | 18.9% | 0 | 0 |
| 1.9.4 | 2 | 8.2 | 12.6% | 0 | 0 |
| 1.9.3 | 4 | 7.4 | 12.9% | 0 | 0 |
| 1.9.2 | 5 | 7.6 | 21.8% | 0 | 0 |
| 1.9.1 | 5 | 7.6 | 21.8% | 0 | 0 |
| 1.9.0 | 5 | 7.6 | 21.8% | 0 | 0 |
| 1.8.9 | 10 | 4.9 | 7.9% | 0 | 0 |
| 1.8.8 | 11 | 4.9 | 8.0% | 0 | 0 |
| 1.8.7 | 11 | 4.9 | 8.0% | 0 | 0 |
| 1.8.6 | 11 | 4.9 | 8.0% | 0 | 0 |
| 1.8.5 | 12 | 4.9 | 8.3% | 0 | 0 |
| 1.8.4 | 13 | 4.8 | 8.1% | 0 | 0 |
| 1.8.3 | 13 | 4.8 | 8.1% | 0 | 0 |
| 1.8.2 | 14 | 4.6 | 7.6% | 0 | 0 |
| 1.8.16 | 1 | 6.5 | 6.4% | 0 | 0 |