Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Subversion

First CVE: Jul 7, 2004Active for: 22 yearsTotal CVEs: 7

Subversion is a version-control system widely embedded across software development infrastructure, despite having a narrow, focused product portfolio. Its vulnerability disclosures have an elevated tendency toward public exploit availability and recur around path-traversal and directory-access weaknesses that reflect the complexity of repository access control and file-system interaction. Defenders should treat Subversion instances as infrastructure-tier patching priorities given the system's centrality to build and release pipelines; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
7
Total CVEs
More Total CVEs than 88% of tracked vendors
2.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 90% of tracked vendors
5.9
Avg CVSS Score
Higher Avg CVSS Score than 27% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Subversion over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 7, 2004
22 years ago
Most Recent CVE
Aug 7, 2009
6,195 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (7 CVEs).

7 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2004-0397HIGH
Stack-based buffer overflow during the apr_time_t data conversion in Subversion 1.0.2 and earlier allows remote attackers to execute arbitrary code via a (1) DAV2 REPORT query or (
Jul 7, 20047.577NOYES
CVE-2009-2411HIGH
Multiple integer overflows in the libsvn_delta library in Subversion before 1.5.7, and 1.6.x before 1.6.4, allow remote authenticated users and remote Subversion servers to execute
Aug 7, 20098.529NONO
CVE-2004-0413HIGH
libsvn_ra_svn in Subversion 1.0.4 trusts the length field of (1) svn://, (2) svn+ssh://, and (3) other svn protocol URL strings, which allows remote attackers to cause a denial of
Aug 6, 200410.027NONO
CVE-2007-3846MEDIUM
Directory traversal vulnerability in Subversion before 1.4.5, as used by TortoiseSVN before 1.4.5 and possibly other products, when run on Windows-based systems, allows remote auth
Aug 28, 20076.018NONO
CVE-2004-0749MEDIUM
The mod_authz_svn module in Subversion 1.0.7 and earlier does not properly restrict access to all metadata on unreadable paths, which could allow remote attackers to gain sensitive
Dec 23, 20045.015NONO
CVE-2004-1438LOW
The mod_authz_svn Apache module for Subversion 1.0.4-r1 and earlier allows remote authenticated users, with write access to the repository, to read unauthorized parts of the reposi
Dec 31, 20042.114NONO
CVE-2007-2448LOW
Subversion 1.4.3 and earlier does not properly implement the "partial access" privilege for users who have access to changed paths but not copied paths, which allows remote authent
Jun 14, 20072.111NONO
View all 7 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products7 CVEs
29%
29%
43%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown7 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown7 (100.0%)
User Interaction
None0 (0.0%)
Unknown7 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown7 (100.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (7 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
14.3% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
14.3% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Subversion.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Subversion — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Subversion's Products

View all 2 CNAs →

Top CWEs