← Vulnerability feed

Vulnerability record · CVE-2007-3846 · published 28 August 2007

CVE-2007-3846: Subversion path traversal vulnerability

Subversion · Subversion

Directory traversal vulnerability in Subversion before 1.4.5, as used by TortoiseSVN before 1.4.5 and possibly other products, when run on Windows-based systems, allows remote authenticated users to overwrite and create arbitrary files via a ..\ (dot dot backslash) sequence in the filename, as stored in the file repository.

6.0 CVSS 2.0 Medium EPSS 1.6% · top 24.6% CWE-22 · Path traversal
6.0CVSS 2.0 base score
1.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
32References
16 Jun 2026Last modified by NVD

Description

Directory traversal vulnerability in Subversion before 1.4.5, as used by TortoiseSVN before 1.4.5 and possibly other products, when run on Windows-based systems, allows remote authenticated users to overwrite and create arbitrary files via a ..\ (dot dot backslash) sequence in the filename, as stored in the file repository.

AV:N/AC:M/Au:S/C:P/I:P/A:P

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://crisp.cs.du.edu/?q=node/36
http://osvdb.org/40118
http://osvdb.org/40119
http://secunia.com/advisories/26625 PatchVendor Advisory
http://secunia.com/advisories/26632 PatchVendor Advisory
http://securitytracker.com/id?1018617
http://subversion.tigris.org/servlets/NewsItemView?newsItemID=1941 Patch
http://subversion.tigris.org/servlets/ReadMsg?list=users&msgNo=69413
http://subversion.tigris.org/servlets/ReadMsg?list=users&msgNo=69413
http://subversion.tigris.org/servlets/ReadMsg?list=users&msgNo=69413
http://subversion.tigris.org/servlets/ReadMsg?list=users&msgNo=69413
http://tortoisesvn.net/node/291 Patch
http://www.securityfocus.com/bid/25468
http://www.vupen.com/english/advisories/2007/3003
http://www.vupen.com/english/advisories/2007/3004
https://exchange.xforce.ibmcloud.com/vulnerabilities/36312
http://crisp.cs.du.edu/?q=node/36
http://osvdb.org/40118
http://osvdb.org/40119
http://secunia.com/advisories/26625 PatchVendor Advisory
http://secunia.com/advisories/26632 PatchVendor Advisory
http://securitytracker.com/id?1018617
http://subversion.tigris.org/servlets/NewsItemView?newsItemID=1941 Patch
http://subversion.tigris.org/servlets/ReadMsg?list=users&msgNo=69413
http://subversion.tigris.org/servlets/ReadMsg?list=users&msgNo=69413
http://subversion.tigris.org/servlets/ReadMsg?list=users&msgNo=69413
http://subversion.tigris.org/servlets/ReadMsg?list=users&msgNo=69413
http://tortoisesvn.net/node/291 Patch
http://www.securityfocus.com/bid/25468
http://www.vupen.com/english/advisories/2007/3003
http://www.vupen.com/english/advisories/2007/3004
https://exchange.xforce.ibmcloud.com/vulnerabilities/36312

Track CVE-2007-3846 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2004-0413Openpkg vulnerabilitylibsvn_ra_svn in Subversion 1.0.4 trusts the length field of (1) svn://, (2) svn+ssh://, and (3) other svn protocol URL strings, which allows remote …EPSS 5.9%8.8CVE-2019-14422Tortoisesvn vulnerabilityAn issue was discovered in in TortoiseSVN 1.12.1. The Tsvncmd: URI handler allows a customised diff operation on Excel workbooks, which could be used…EPSS 16%8.5CVE-2009-2411Subversion vulnerabilityMultiple integer overflows in the libsvn_delta library in Subversion before 1.5.7, and 1.6.x before 1.6.4, allow remote authenticated users and remot…EPSS 5.1%7.5CVE-2004-0397Subversion apr_time_t conversion stack buffer overflowSubversion 1.0.2 and earlier contains a stack-based buffer overflow in the apr_time_t data conversion routine. A remote attacker can trigger it throu…EPSS 75%analysed5.0CVE-2004-0749Subversion vulnerabilityThe mod_authz_svn module in Subversion 1.0.7 and earlier does not properly restrict access to all metadata on unreadable paths, which could allow rem…EPSS 1.5%2.1CVE-2007-2448Subversion vulnerabilitySubversion 1.4.3 and earlier does not properly implement the "partial access" privilege for users who have access to changed paths but not copied pat…EPSS 1.5%2.1CVE-2004-1438Subversion vulnerabilityThe mod_authz_svn Apache module for Subversion 1.0.4-r1 and earlier allows remote authenticated users, with write access to the repository, to read u…EPSS 0.70%9.8CVE-2026-93616Checkpoint multi-domain security management path traversal vulnerabilityA directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Managem…KEVEPSS 20%

Source: NIST National Vulnerability Database (record CVE-2007-3846), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.