Search CVE reports


Toggle filters

11 – 20 of 52 results


CVE-2016-2168

Medium priority

Some fixes available 2 of 4

The req_check_access function in the mod_authz_svn module in the httpd server in Apache Subversion before 1.8.16 and 1.9.x before 1.9.4 allows remote authenticated users to cause a denial of service (NULL pointer dereference and...

1 affected package

subversion

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
subversion Fixed
Show less packages

CVE-2016-2167

Low priority

Some fixes available 2 of 4

The canonicalize_username function in svnserve/cyrus_auth.c in Apache Subversion before 1.8.16 and 1.9.x before 1.9.4, when Cyrus SASL authentication is used, allows remote attackers to authenticate and bypass intended access...

1 affected package

subversion

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
subversion Fixed
Show less packages

CVE-2015-5343

Medium priority

Some fixes available 1 of 3

Integer overflow in util.c in mod_dav_svn in Apache Subversion 1.7.x, 1.8.x before 1.8.15, and 1.9.x before 1.9.3 allows remote authenticated users to cause a denial of service (subversion server crash or memory consumption) and...

1 affected package

subversion

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
subversion Not affected
Show less packages

CVE-2015-5259

Medium priority
Not affected

Integer overflow in the read_string function in libsvn_ra_svn/marshal.c in Apache Subversion 1.9.x before 1.9.3 allows remote attackers to execute arbitrary code via an svn:// protocol string, which triggers a heap-based buffer...

1 affected package

subversion

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
subversion
Show less packages

CVE-2015-3187

Medium priority
Fixed

The svn_repos_trace_node_locations function in Apache Subversion before 1.7.21 and 1.8.x before 1.8.14, when path-based authorization is used, allows remote authenticated users to obtain sensitive path information by reading the...

1 affected package

subversion

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
subversion
Show less packages

CVE-2015-3184

Medium priority
Fixed

mod_authz_svn in Apache Subversion 1.7.x before 1.7.21 and 1.8.x before 1.8.14, when using Apache httpd 2.4.x, does not properly restrict anonymous access, which allows remote anonymous users to read hidden files via the path name.

1 affected package

subversion

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
subversion
Show less packages

CVE-2015-0251

Low priority

Some fixes available 3 of 5

The mod_dav_svn server in Subversion 1.5.0 through 1.7.19 and 1.8.0 through 1.8.11 allows remote authenticated users to spoof the svn:author property via a crafted v1 HTTP protocol request sequences.

1 affected package

subversion

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
subversion
Show less packages

CVE-2015-0248

Medium priority

Some fixes available 3 of 5

The (1) mod_dav_svn and (2) svnserve servers in Subversion 1.6.0 through 1.7.19 and 1.8.0 through 1.8.11 allow remote attackers to cause a denial of service (assertion failure and abort) via crafted parameter combinations related...

1 affected package

subversion

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
subversion
Show less packages

CVE-2015-0202

Medium priority

Some fixes available 2 of 4

The mod_dav_svn server in Subversion 1.8.0 through 1.8.11 allows remote attackers to cause a denial of service (memory consumption) via a large number of REPORT requests, which trigger the traversal of FSFS repository nodes.

1 affected package

subversion

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
subversion
Show less packages

CVE-2014-8108

Medium priority

Some fixes available 2 of 4

The mod_dav_svn Apache HTTPD server module in Apache Subversion 1.7.x before 1.7.19 and 1.8.x before 1.8.11 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a request for a URI that...

1 affected package

subversion

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
subversion
Show less packages