Vulnerability index

Browse CVEs

11 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Viewvc HIGH 7.5
CVE-2025-54141

ViewVC is a browser interface for CVS and Subversion version control repositories. In versions 1.1.0 through 1.1.31 and 1.2.0 through 1.2.3, the stan…

Fix: 1.1.31 / 1.2.4+
Fix from $1,950 2025-07-22
Viewvc MEDIUM 5.4
CVE-2023-22464

ViewVC is a browser interface for CVS and Subversion version control repositories. Versions prior to 1.2.3 and 1.1.30 are vulnerable to cross-site sc…

Fix: 1.1.30 / 1.2.3+
Fix from $1,600 2023-01-04
Viewvc MEDIUM 6.1
CVE-2023-22456

ViewVC, a browser interface for CVS and Subversion version control repositories, as a cross-site scripting vulnerability that affects versions prior …

Fix: 1.1.29 / 1.2.2+
Fix from $1,600 2023-01-03
Viewvc MEDIUM 5.0
CVE-2012-3356

The remote SVN views functionality (lib/vclib/svn/svn_ra.py) in ViewVC before 1.1.15 does not properly perform authorization, which allows remote att…

Fix: after 1.1.14
Fix from $1,600 2012-07-22
Viewvc MEDIUM 5.0
CVE-2012-3357

The SVN revision view (lib/vclib/svn/svn_repos.py) in ViewVC before 1.1.15 does not properly handle log messages when a readable path is copied from …

Fix: after 1.1.14
Fix from $1,600 2012-07-22
Viewvc MEDIUM 5.0
CVE-2009-5024

ViewVC before 1.1.11 allows remote attackers to bypass the cvsdb row_limit configuration setting, and consequently conduct resource-consumption attac…

Fix: after 1.1.10
Fix from $1,600 2011-05-23
Viewvc HIGH 7.5
CVE-2010-0005

query.py in the query interface in ViewVC before 1.1.3 does not reject configurations that specify an unsupported authorizer for a root, which might …

Fix: after 1.1.2
Fix from $1,950 2010-01-29
Viewvc MEDIUM 5.0
CVE-2010-0004

ViewVC before 1.1.3 composes the root listing view without using the authorizer for each root, which might allow remote attackers to discover private…

Mitigation only
Fix from $1,600 2010-01-29
Viewvc MEDIUM 5.0
CVE-2009-3619

Unspecified vulnerability in ViewVC 1.0 before 1.0.9 and 1.1 before 1.1.2 has unknown impact and remote attack vectors related to "printing illegal p…

Patch available
Fix from $1,600 2009-11-10
Viewvc MEDIUM 5.8
CVE-2008-4325

lib/viewvc.py in ViewVC 1.0.5 uses the content-type parameter in the HTTP request for the Content-Type header in the HTTP response, which allows remo…

Patch available
Fix from $1,600 2008-09-30
Viewvc MEDIUM 6.8
CVE-2006-5442

ViewVC 1.0.2 and earlier does not specify a charset in its HTTP headers or HTML documents, which allows remote attackers to conduct cross-site script…

Fix: after 1.0.2
Fix from $1,600 2006-10-21