CVE-2014-3580: Apache Subversion
Medium severity, CVSS 5.0. EPSS: 11.1% chance of exploitation in the next 30 days.
The mod_dav_svn Apache HTTPD server module in Apache Subversion 1.x before 1.7.19 and 1.8.x before 1.8.11 allows remote attackers to cause a denial of service (NULL pointer dereference and server crash) via a REPORT request for a resource that does not exist.
Affected products
- Apache Subversion: version 1.0.0 only; version 1.0.1 only; version 1.0.2 only; version 1.0.3 only; version 1.0.4 only; version 1.0.5 only; …
- Apple Xcode: version 6.1.1 only
- Debian Debian Linux: version 7.0 only
- Red Hat Enterprise Linux Desktop: version 6.0 only; version 7.0 only
- Red Hat Enterprise Linux Hpc Node: version 6.0 only; version 7.0 only
- Red Hat Enterprise Linux Server: version 6.0 only; version 7.0 only
- Red Hat Enterprise Linux Server Eus: version 6.6.z only
- Red Hat Enterprise Linux Workstation: version 6.0 only; version 7.0 only
Published 2014-12-18. Last modified 2026-06-17.