← Vulnerability feed

Vulnerability record · CVE-2014-0032 · published 14 February 2014

CVE-2014-0032: Apache subversion improper input validation vulnerability

Apache · Subversion

The get_resource function in repos.c in the mod_dav_svn module in Apache Subversion before 1.7.15 and 1.8.x before 1.8.6, when SVNListParentPath is enabled, allows remote attackers to cause a denial of service (crash) via vectors related to the server root and request methods other than GET, as demonstrated by the "svn ls http://svn.example.com" command.

4.3 CVSS 2.0 Medium EPSS 11% · top 4.2% CWE-20 · Improper input validation
4.3CVSS 2.0 base score
11%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
38References
17 Jun 2026Last modified by NVD

Description

The get_resource function in repos.c in the mod_dav_svn module in Apache Subversion before 1.7.15 and 1.8.x before 1.8.6, when SVNListParentPath is enabled, allows remote attackers to cause a denial of service (crash) via vectors related to the server root and request methods other than GET, as demonstrated by the "svn ls http://svn.example.com" command.

AV:N/AC:M/Au:N/C:N/I:N/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://lists.opensuse.org/opensuse-updates/2014-02/msg00086.html
http://lists.opensuse.org/opensuse-updates/2014-03/msg00011.html
http://mail-archives.apache.org/mod_mbox/subversion-dev/201401.mbox/%3C52D328AB.8090502%40reser.org%3E
http://mail-archives.apache.org/mod_mbox/subversion-dev/201401.mbox/%3C871u0gqb0d.fsf%40ntlworld.com%3E
http://mail-archives.apache.org/mod_mbox/subversion-dev/201401.mbox/%3CCANvU9scLHr2yOLABW8q6_wNzhEf7pWM=NiavGcobqvUuyhKy
http://rhn.redhat.com/errata/RHSA-2014-0255.html
http://secunia.com/advisories/56822 Vendor Advisory
http://secunia.com/advisories/60722
http://secunia.com/advisories/61321
http://support.apple.com/kb/HT6444
http://svn.apache.org/repos/asf/subversion/tags/1.7.15/CHANGES
http://svn.apache.org/repos/asf/subversion/tags/1.8.6/CHANGES
http://svn.apache.org/viewvc?view=revision&revision=1557320 Patch
http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.html
http://www.osvdb.org/102927
http://www.securityfocus.com/bid/65434
http://www.ubuntu.com/usn/USN-2316-1
https://exchange.xforce.ibmcloud.com/vulnerabilities/90986
https://security.gentoo.org/glsa/201610-05
http://lists.opensuse.org/opensuse-updates/2014-02/msg00086.html
http://lists.opensuse.org/opensuse-updates/2014-03/msg00011.html
http://mail-archives.apache.org/mod_mbox/subversion-dev/201401.mbox/%3C52D328AB.8090502%40reser.org%3E
http://mail-archives.apache.org/mod_mbox/subversion-dev/201401.mbox/%3C871u0gqb0d.fsf%40ntlworld.com%3E
http://mail-archives.apache.org/mod_mbox/subversion-dev/201401.mbox/%3CCANvU9scLHr2yOLABW8q6_wNzhEf7pWM=NiavGcobqvUuyhKy
http://rhn.redhat.com/errata/RHSA-2014-0255.html
http://secunia.com/advisories/56822 Vendor Advisory
http://secunia.com/advisories/60722
http://secunia.com/advisories/61321
http://support.apple.com/kb/HT6444
http://svn.apache.org/repos/asf/subversion/tags/1.7.15/CHANGES
http://svn.apache.org/repos/asf/subversion/tags/1.8.6/CHANGES
http://svn.apache.org/viewvc?view=revision&revision=1557320 Patch
http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.html
http://www.osvdb.org/102927
http://www.securityfocus.com/bid/65434
http://www.ubuntu.com/usn/USN-2316-1
https://exchange.xforce.ibmcloud.com/vulnerabilities/90986
https://security.gentoo.org/glsa/201610-05

Track CVE-2014-0032 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2017-9800Apache subversion improper input validation vulnerabilityA maliciously constructed svn+ssh:// URL would cause Subversion clients before 1.8.19, 1.9.x before 1.9.7, and 1.10.0.x through 1.10.0-alpha3 to run …EPSS 19%8.8CVE-2013-4246Apache subversion improper access control vulnerabilitylibsvn_fs_fs/fs_fs.c in Apache Subversion 1.8.x before 1.8.2 might allow remote authenticated users with commit access to corrupt FSFS repositories a…EPSS 2.8%8.6CVE-2015-5259Apache Subversion svn:// protocol integer overflow enables remote code executionApache Subversion 1.9.x before 1.9.3 has an integer overflow in the read_string function in libsvn_ra_svn/marshal.c. A crafted svn:// protocol string…EPSS 57%analysed7.8CVE-2024-45720Apache subversion os command injection vulnerabilityOn Windows platforms, a "best fit" character encoding conversion of command line arguments to Subversion's executables (e.g., svn.exe, etc.) may lead…EPSS 0.61%7.8CVE-2015-0202Apache subversion vulnerabilityThe mod_dav_svn server in Subversion 1.8.0 through 1.8.11 allows remote attackers to cause a denial of service (memory consumption) via a large numbe…EPSS 8.0%7.8CVE-2013-2112Apache subversion vulnerabilityThe svnserve server in Subversion before 1.6.23 and 1.7.x before 1.7.10 allows remote attackers to cause a denial of service (exit) by aborting a con…EPSS 3.9%7.6CVE-2015-5343Apache subversion memory buffer overflow vulnerabilityInteger overflow in util.c in mod_dav_svn in Apache Subversion 1.7.x, 1.8.x before 1.8.15, and 1.9.x before 1.9.3 allows remote authenticated users t…EPSS 30%7.5CVE-2022-24070Apache subversion use after free vulnerabilitySubversion's mod_dav_svn is vulnerable to memory corruption. While looking up path-based authorization rules, mod_dav_svn servers may attempt to use …EPSS 9.5%

Source: NIST National Vulnerability Database (record CVE-2014-0032), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.