CVE Tools

Tigris

5 CVEs tracked since 2009. Since Jan 2009, none of them reached CISA KEV.

Tigris CVEs per month

Jan 2009 to Sep 2010. Point at a month, or focus the strip and use the arrow keys.
Tigris CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2009-0140
2009-02null or fewer
2009-03null or fewer
2009-04null or fewer
2009-05null or fewer
2009-06null or fewer
2009-07null or fewer
2009-08null or fewer
2009-09null or fewer
2009-10null or fewer
2009-11null or fewer
2009-12null or fewer
2010-01null or fewer
2010-02null or fewer
2010-03null or fewer
2010-04null or fewer
2010-05null or fewer
2010-06null or fewer
2010-07null or fewer
2010-08null or fewer
2010-0910

Products

The products that kept showing up in Tigris's monthly top three, with their CVEs summed over those months.

  1. Websvn41 month
  2. Tortoisesvn11 month

Latest CVEs

The 6 most recently published vulnerabilities affecting Tigris.

  1. CVE-2024-31497In PuTTY 0.68 through 0.80 before 0.81, biased ECDSA nonce generation allows an attacker to recover a user's NIST P-521 secret key via a quick attack in approximately 60 signatures. This is especia...5.9
  2. CVE-2010-3199Untrusted search path vulnerability in TortoiseSVN 1.6.10, Build 19898 and earlier allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via...9.3
  3. CVE-2009-0240listing.php in WebSVN 2.0 and possibly 1.7 beta, when using an SVN authz file, allows remote authenticated users to read changelogs or diffs for restricted projects via a modified repname parameter.3.5
  4. CVE-2008-5918Cross-site scripting (XSS) vulnerability in the getParameterisedSelfUrl function in index.php in WebSVN 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the PATH_I...4.3
  5. CVE-2008-5920The create_anchors function in utils.inc in WebSVN 1.x allows remote attackers to execute arbitrary PHP code via a crafted username that is processed by the preg_replace function with the eval switch.7.5
  6. CVE-2008-5919Directory traversal vulnerability in rss.php in WebSVN 2.0 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to overwrite arbitrary files via directory traversal sequences in ...6.8

The record

Peak rank
#23 in Jan 2009
Busiest month shown
Jan 2009, 4 CVEs
Months with a KEV entry
0 since Jan 2009
Monthly snapshots
2 since 2009
Tigris's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store