2013 CVE Vulnerabilities
6,830 CVEs published in 2013.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2013-4134 | — | — | 0.8% | Nov 5, 2013 | OpenAFS before 1.4.15, 1.6.x before 1.6.5, and 1.7.x before 1.7.26 uses weak encryption (DES) for Kerberos keys, which m... |
| CVE-2013-6618 | — | — | 10.6% | Nov 5, 2013 | jsdm/ajax/port.php in J-Web in Juniper Junos before 10.4R13, 11.4 before 11.4R7, 12.1 before 12.1R5, 12.2 before 12.2R3,... |
| CVE-2013-5695 | — | — | 1.0% | Nov 5, 2013 | Multiple cross-site scripting (XSS) vulnerabilities in Opsview before 4.4.1 allow remote attackers to inject arbitrary w... |
| CVE-2013-5694 | — | — | 2.6% | Nov 5, 2013 | SQL injection vulnerability in status/service/acknowledge in Opsview before 4.4.1 allows remote attackers to execute arb... |
| CVE-2013-4497 | — | — | 1.8% | Nov 5, 2013 | The XenAPI backend in OpenStack Compute (Nova) Folsom, Grizzly, and Havana before 2013.2 does not properly apply securit... |
| CVE-2013-4453 | — | — | 1.4% | Nov 5, 2013 | Cross-site scripting (XSS) vulnerability in templates/login.php in LDAP Account Manager (LAM) 4.3 and 4.2.1 allows remot... |
| CVE-2013-4419 | — | — | 0.8% | Nov 5, 2013 | The guestfish command in libguestfs 1.20.12, 1.22.7, and earlier, when using the --remote or --listen option, does not p... |
| CVE-2013-3264 | — | — | 2.1% | Nov 5, 2013 | The WP Ultimate Email Marketer plugin 1.1.0 and possibly earlier for Wordpress does not properly restrict access to (1) ... |
| CVE-2013-3263 | — | — | 1.6% | Nov 5, 2013 | Multiple cross-site scripting (XSS) vulnerabilities in the WP Ultimate Email Marketer plugin 1.1.0 and possibly earlier ... |
| CVE-2013-6617 | — | — | 3.0% | Nov 5, 2013 | The salt master in Salt (aka SaltStack) 0.11.0 through 0.17.0 does not properly drop group privileges, which makes it ea... |
| CVE-2013-6172 | — | — | 2.9% | Nov 5, 2013 | steps/utils/save_pref.inc in Roundcube webmail before 0.8.7 and 0.9.x before 0.9.5 allows remote attackers to modify con... |
| CVE-2013-6077 | — | — | 1.7% | Nov 5, 2013 | Citrix XenDesktop 7.0, when upgraded from XenDesktop 5.x, does not properly enforce policy rule permissions, which allow... |
| CVE-2013-5670 | — | — | 1.2% | Nov 5, 2013 | Cross-site scripting (XSS) vulnerability in spell-check-savedicts.php in the htmlarea SpellChecker module, as used in Se... |
| CVE-2013-4439 | — | — | 1.5% | Nov 5, 2013 | Salt (aka SaltStack) before 0.15.0 through 0.17.0 allows remote authenticated minions to impersonate arbitrary minions v... |
| CVE-2013-4438 | — | — | 2.1% | Nov 5, 2013 | Salt (aka SaltStack) before 0.17.1 allows remote attackers to execute arbitrary YAML code via unspecified vectors. NOTE... |
| CVE-2013-4437 | — | — | 1.5% | Nov 5, 2013 | Unspecified vulnerability in salt-ssh in Salt (aka SaltStack) 0.17.0 has unspecified impact and vectors related to "inse... |
| CVE-2013-4436 | — | — | 1.8% | Nov 5, 2013 | The default configuration for salt-ssh in Salt (aka SaltStack) 0.17.0 does not validate the SSH host key of requests, wh... |
| CVE-2013-4435 | — | — | 1.5% | Nov 5, 2013 | Salt (aka SaltStack) 0.15.0 through 0.17.0 allows remote authenticated users who are using external authentication or cl... |
| CVE-2013-6366 | — | — | 7.0% | Nov 4, 2013 | The Groovy script console in VMware Hyperic HQ 4.6.6 allows remote authenticated administrators to execute arbitrary cod... |
| CVE-2013-6340 | — | — | 1.7% | Nov 4, 2013 | epan/dissectors/packet-tcp.c in the TCP dissector in Wireshark 1.8.x before 1.8.11 and 1.10.x before 1.10.3 does not pro... |
| CVE-2013-6339 | — | — | 2.0% | Nov 4, 2013 | The dissect_openwire_type function in epan/dissectors/packet-openwire.c in the OpenWire dissector in Wireshark 1.8.x bef... |
| CVE-2013-6338 | — | — | 1.7% | Nov 4, 2013 | The dissect_sip_common function in epan/dissectors/packet-sip.c in the SIP dissector in Wireshark 1.8.x before 1.8.11 an... |
| CVE-2013-6337 | — | — | 1.5% | Nov 4, 2013 | Unspecified vulnerability in the NBAP dissector in Wireshark 1.8.x before 1.8.11 and 1.10.x before 1.10.3 allows remote ... |
| CVE-2013-6336 | — | — | 1.9% | Nov 4, 2013 | The ieee802154_map_rec function in epan/dissectors/packet-ieee802154.c in the IEEE 802.15.4 dissector in Wireshark 1.8.x... |
| CVE-2013-5564 | — | — | 1.8% | Nov 4, 2013 | The Java process in the Impact server in Cisco Prime Central for Hosted Collaboration Solution (HCS) allows remote attac... |
Check if your code is affected by 2013 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now