2013 CVE Vulnerabilities

6,831 CVEs published in 2013.

CVE IDSeverityCVSSDescription
CVE-2013-6411——The HandleCrashedAircraft function in aircraft_cmd.cpp in OpenTTD 0.3.6 through 1.3.2 allows remote attackers to cause a...
CVE-2013-6391——The ec2tokens API in OpenStack Identity (Keystone) before Havana 2013.2.1 and Icehouse before icehouse-2 does not return...
CVE-2013-6051——The bgp_attr_unknown function in bgp_attr.c in Quagga 0.99.21 does not properly initialize the total variable, which all...
CVE-2013-5107——Directory traversal vulnerability in RockMongo 1.1.5 and earlier allows remote attackers to read arbitrary files via a ....
CVE-2013-1364——The user.login function in Zabbix before 1.8.16 and 2.x before 2.0.5rc1 allows remote attackers to override LDAP configu...
CVE-2013-7096——Multiple SQL injection vulnerabilities in SAP EMR Unwired allow remote attackers to execute arbitrary SQL commands via u...
CVE-2013-7095——The XML parser (crm_flex_data) in SAP Customer Relationship Management (CRM) 7.02 EHP 2 has unknown impact and attack ve...
CVE-2013-7094——SQL injection vulnerability in the RSDDCVER_COUNT_TAB_COLS function in SAP NetWeaver 7.30 allows remote attackers to exe...
CVE-2013-7093——SAP Network Interface Router (SAProuter) 39.3 SP4 allows remote attackers to bypass authentication and modify the config...
CVE-2013-7039——Stack-based buffer overflow in the MHD_digest_auth_check function in libmicrohttpd before 0.9.32, when MHD_OPTION_CONNEC...
CVE-2013-7038——The MHD_http_unescape function in libmicrohttpd before 0.9.32 might allow remote attackers to obtain sensitive informati...
CVE-2013-6809——Format string vulnerability in the client in Tftpd32 before 4.50 allows remote servers to cause a denial of service (cra...
CVE-2013-6400——Xen 4.2.x and 4.3.x, when using Intel VT-d and a PCI device has been assigned, does not clear the flag that suppresses I...
CVE-2013-6359——Munin::Master::Node in Munin before 2.0.18 allows remote attackers to cause a denial of service (abort data collection f...
CVE-2013-6048——The get_group_tree function in lib/Munin/Master/HTMLConfig.pm in Munin before 2.0.18 allows remote nodes to cause a deni...
CVE-2013-5676——The Jenkins Plugin for SonarQube 3.7 and earlier allows remote authenticated users to obtain sensitive information (clea...
CVE-2013-7092——Multiple SQL injection vulnerabilities in /admin/cgi-bin/rpc/doReport/18 in McAfee Email Gateway 7.6 allow remote authen...
CVE-2013-7091——Directory traversal vulnerability in /res/I18nMsg,AjxMsg,ZMsg,ZmMsg,AjxKeys,ZmKeys,ZdMsg,Ajx%20TemplateMsg.js.zgz in Zim...
CVE-2013-7050——The get_main_source_dir function in scripts/uscan.pl in devscripts before 2.13.8, when using USCAN_EXCLUSION, allows rem...
CVE-2013-6958——Juniper NetScreen Firewall running ScreenOS 5.4, 6.2, or 6.3, when the Ping of Death screen is disabled, allows remote a...
CVE-2013-6957——Cross-site scripting (XSS) vulnerability in the web administrative component in Juniper IDP allows remote attackers to i...
CVE-2013-6956——Cross-site scripting (XSS) vulnerability in the Secure Access Service Web rewriting feature in Juniper Junos Pulse Secur...
CVE-2013-6394——Percona XtraBackup before 2.1.6 uses a constant string for the initialization vector (IV), which makes it easier for loc...
CVE-2013-4569——The CleanChanges extension for MediaWiki before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.21.3, when "Group chan...
CVE-2013-4568——Incomplete blacklist vulnerability in Sanitizer::checkCss in MediaWiki before 1.19.9, 1.20.x before 1.20.8, and 1.21.x b...

Check if your code is affected by 2013 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now