Subversion is a version-control system widely embedded across software development infrastructure, despite having a narrow, focused product portfolio. Its vulnerability disclosures have an elevated tendency toward public exploit availability and recur around path-traversal and directory-access weaknesses that reflect the complexity of repository access control and file-system interaction. Defenders should treat Subversion instances as infrastructure-tier patching priorities given the system's centrality to build and release pipelines; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Subversion over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2004-0397HIGH Stack-based buffer overflow during the apr_time_t data conversion in Subversion 1.0.2 and earlier allows remote attackers to execute arbitrary code via a (1) DAV2 REPORT query or ( | Jul 7, 2004 | 7.5 | 77 | NO | YES |
CVE-2009-2411HIGH Multiple integer overflows in the libsvn_delta library in Subversion before 1.5.7, and 1.6.x before 1.6.4, allow remote authenticated users and remote Subversion servers to execute | Aug 7, 2009 | 8.5 | 29 | NO | NO |
CVE-2004-0413HIGH libsvn_ra_svn in Subversion 1.0.4 trusts the length field of (1) svn://, (2) svn+ssh://, and (3) other svn protocol URL strings, which allows remote attackers to cause a denial of | Aug 6, 2004 | 10.0 | 27 | NO | NO |
CVE-2007-3846MEDIUM Directory traversal vulnerability in Subversion before 1.4.5, as used by TortoiseSVN before 1.4.5 and possibly other products, when run on Windows-based systems, allows remote auth | Aug 28, 2007 | 6.0 | 18 | NO | NO |
CVE-2004-0749MEDIUM The mod_authz_svn module in Subversion 1.0.7 and earlier does not properly restrict access to all metadata on unreadable paths, which could allow remote attackers to gain sensitive | Dec 23, 2004 | 5.0 | 15 | NO | NO |
The mod_authz_svn Apache module for Subversion 1.0.4-r1 and earlier allows remote authenticated users, with write access to the repository, to read unauthorized parts of the reposi | Dec 31, 2004 | 2.1 | 14 | NO | NO |
Subversion 1.4.3 and earlier does not properly implement the "partial access" privilege for users who have access to changed paths but not copied paths, which allows remote authent | Jun 14, 2007 | 2.1 | 11 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Subversion.
Media articles that mention a CVE ID that affects a product developed by Subversion — matched by CVE ID, not by vendor name.