<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Apache Subversion (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/apache-subversion.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/apache-subversion-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Apache Subversion (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:52 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-29169 – A NULL pointer dereference in mod_dav_lock in Apache HTTP Server 2.4.66 and earl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-29169</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-29169</guid>
    <pubDate>Mon, 04 May 2026 15:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-29169</strong></p>
  <p>A NULL pointer dereference in mod_dav_lock in Apache HTTP Server 2.4.66 and earlier may allow an attacker to crash the server with a malicious request.mod_dav_lock is not used internally by mod_dav or mod_dav_fs.  The only known use-case for mod_dav_lock was mod_dav_svn from Apache Subversion earlier than version 1.2.0.  Users are recommended to upgrade to version 2.4.66, which fixes this issue,…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-29169">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-0203 – In Apache Subversion versions up to and including 1.9.10, 1.10.4, 1.12.0, Subver...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-0203</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-0203</guid>
    <pubDate>Thu, 26 Sep 2019 16:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-0203</strong></p>
  <p>In Apache Subversion versions up to and including 1.9.10, 1.10.4, 1.12.0, Subversion's svnserve server process may exit when a client sends certain sequences of protocol commands. This can lead to disruption for users of the server.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-0203">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2013-4246 – libsvn_fs_fs/fs_fs.c in Apache Subversion 1.8.x before 1.8.2 might allow remote ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-4246</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-4246</guid>
    <pubDate>Mon, 30 Oct 2017 14:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2013-4246</strong></p>
  <p>libsvn_fs_fs/fs_fs.c in Apache Subversion 1.8.x before 1.8.2 might allow remote authenticated users with commit access to corrupt FSFS repositories and cause a denial of service or obtain sensitive information by editing packed revision properties.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-4246">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-5343 – Integer overflow in util.c in mod_dav_svn in Apache Subversion 1.7.x, 1.8.x befo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-5343</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-5343</guid>
    <pubDate>Thu, 14 Apr 2016 14:59:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-5343</strong></p>
  <p>Integer overflow in util.c in mod_dav_svn in Apache Subversion 1.7.x, 1.8.x before 1.8.15, and 1.9.x before 1.9.3 allows remote authenticated users to cause a denial of service (subversion server crash or memory consumption) and possibly execute arbitrary code via a skel-encoded request body, which triggers an out-of-bounds read and heap-based buffer overflow.</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-5343">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-5259 – Integer overflow in the read_string function in libsvn_ra_svn/marshal.c in Apach...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-5259</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-5259</guid>
    <pubDate>Fri, 08 Jan 2016 19:59:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-5259</strong></p>
  <p>Integer overflow in the read_string function in libsvn_ra_svn/marshal.c in Apache Subversion 1.9.x before 1.9.3 allows remote attackers to execute arbitrary code via an svn:// protocol string, which triggers a heap-based buffer overflow and an out-of-bounds read.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-5259">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
