Subversion

Vendor:

First CVE: Jun 1, 2004 · Active for 22 years

48
Total CVEs
More Total CVEs than 97% of tracked products
4.0
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
5.4
Avg CVSS
Higher Avg CVSS than 14% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Subversion over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 1, 2004
22 years ago
Most Recent CVE
Dec 9, 2024
592 days ago

CVE Severity & Scoring

Subversion48 CVEs
All CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local1 (2.1%)
Network14 (29.2%)
Unknown33 (68.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (29.2%)
High1 (2.1%)
Unknown33 (68.8%)
User Interaction
None15 (31.3%)
Unknown33 (68.8%)
Required0 (0.0%)
Privileges Required
Low9 (18.8%)
High0 (0.0%)
None6 (12.5%)
Unknown33 (68.8%)

Top CVEs

Signals from CVEs in this product scope (48 CVEs).

48 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Subversion's mod_dav_svn Apache HTTPD module versions 1.11.0 and 1.10.0 to 1.10.3 will crash after dereferencing an uninitialized pointer if the client omits the root path in a rec
Feb 5, 20197.558NONO
The mod_dav_svn Apache HTTPD server module in Subversion 1.7.0 through 1.7.8 allows remote attackers to cause a denial of service (segmentation fault and crash) via a log REPORT re
May 2, 20135.056NOYES
Integer overflow in the read_string function in libsvn_ra_svn/marshal.c in Apache Subversion 1.9.x before 1.9.3 allows remote attackers to execute arbitrary code via an svn:// prot
Jan 8, 20168.651NONO
The mod_dav_svn Apache HTTPD server module in Subversion 1.6.0 through 1.6.20 and 1.7.0 through 1.7.8 allows remote attackers to cause a denial of service (NULL pointer dereference
May 2, 20135.049NOYES
contrib/hook-scripts/svn-keyword-check.pl in Subversion before 1.6.23 allows remote authenticated users with commit permissions to execute arbitrary commands via shell metacharacte
Jul 31, 20137.143NOYES
A maliciously constructed svn+ssh:// URL would cause Subversion clients before 1.8.19, 1.9.x before 1.9.7, and 1.10.0.x through 1.10.0-alpha3 to run an arbitrary shell command. Suc
Aug 11, 20179.841NONO
Subversion's mod_authz_svn module will crash if the server is using in-repository authz rules with the AuthzSVNReposRelativeAccessFile option and a client sends a request for a non
Mar 17, 20217.538NONO
Multiple format string vulnerabilities in (1) neon 0.24.4 and earlier, and other products that use neon including (2) Cadaver, (3) Subversion, and (4) OpenOffice, allow remote mali
Jun 1, 20046.834NOYES
Integer overflow in util.c in mod_dav_svn in Apache Subversion 1.7.x, 1.8.x before 1.8.15, and 1.9.x before 1.9.3 allows remote authenticated users to cause a denial of service (su
Apr 14, 20167.633NONO
The req_check_access function in the mod_authz_svn module in the httpd server in Apache Subversion before 1.8.16 and 1.9.x before 1.9.4 allows remote authenticated users to cause a
May 5, 20166.531NONO

Exploit Exposure

Signals from CVEs in this product scope (48 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
8.3% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (48 CVEs).

Media Mentions

Signals from CVEs in this product scope (48 CVEs).

Top CNAs Publishing CVEs For Subversion

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
m4\/m534.95.3%00
m334.95.3%00
m234.95.3%00
m134.95.3%00
1.9.619.818.9%00
1.9.519.818.9%00
1.9.428.212.6%00
1.9.347.412.9%00
1.9.257.621.8%00
1.9.157.621.8%00
1.9.057.621.8%00
1.8.9104.97.9%00
1.8.8114.98.0%00
1.8.7114.98.0%00
1.8.6114.98.0%00
1.8.5124.98.3%00
1.8.4134.88.1%00
1.8.3134.88.1%00
1.8.2144.67.6%00
1.8.1616.56.4%00