2013 CVE Vulnerabilities
6,830 CVEs published in 2013.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2013-0348 | — | — | 0.5% | Dec 13, 2013 | thttpd.c in sthttpd before 2.26.4-r2 and thttpd 2.25b use world-readable permissions for /var/log/thttpd.log, which allo... |
| CVE-2013-6839 | — | — | 1.3% | Dec 13, 2013 | SQL injection vulnerability in InstantSoft InstantCMS 1.10.3 and earlier allows remote attackers to execute arbitrary SQ... |
| CVE-2013-6005 | — | — | 1.3% | Dec 13, 2013 | Cross-site scripting (XSS) vulnerability in Cybozu Dezie before 8.1.0 allows remote attackers to inject arbitrary web sc... |
| CVE-2013-4988 | — | — | 67.0% | Dec 13, 2013 | Stack-based buffer overflow in IcoFX 2.5 and earlier allows remote attackers to execute arbitrary code via a long idCoun... |
| CVE-2013-5763 | — | — | 0.5% | Dec 12, 2013 | Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.4.0 allows context... |
| CVE-2013-6421 | — | — | 2.0% | Dec 12, 2013 | The unpack_zip function in archive_unpacker.rb in the sprout gem 0.7.246 for Ruby allows context-dependent attackers to ... |
| CVE-2013-6054 | — | — | 2.2% | Dec 12, 2013 | Heap-based buffer overflow in OpenJPEG 1.3 has unspecified impact and remote vectors, a different vulnerability than CVE... |
| CVE-2013-6052 | — | — | 2.2% | Dec 12, 2013 | OpenJPEG 1.3 and earlier allows remote attackers to obtain sensitive information via unspecified vectors that trigger a ... |
| CVE-2013-6045 | — | — | 5.5% | Dec 12, 2013 | Multiple heap-based buffer overflows in OpenJPEG 1.3 and earlier might allow remote attackers to execute arbitrary code ... |
| CVE-2013-4566 | — | — | 2.0% | Dec 12, 2013 | mod_nss 1.0.8 and earlier, when NSSVerifyClient is set to none for the server/vhost context, does not enforce the NSSVer... |
| CVE-2013-4458 | — | — | 4.2% | Dec 12, 2013 | Stack-based buffer overflow in the getaddrinfo function in sysdeps/posix/getaddrinfo.c in GNU C Library (aka glibc or li... |
| CVE-2013-2752 | — | — | 1.0% | Dec 12, 2013 | Cross-site request forgery (CSRF) vulnerability in frontview/lib/np_handler.pl in NETGEAR ReadyNAS RAIDiator before 4.1.... |
| CVE-2013-2751 | — | — | 71.6% | Dec 12, 2013 | Eval injection vulnerability in frontview/lib/np_handler.pl in the FrontView web interface in NETGEAR ReadyNAS RAIDiator... |
| CVE-2013-1978 | — | — | 4.2% | Dec 12, 2013 | Heap-based buffer overflow in the read_xwd_cols function in file-xwd.c in the X Window Dump (XWD) plug-in in GIMP 2.6.9 ... |
| CVE-2013-1913 | — | — | 4.1% | Dec 12, 2013 | Integer overflow in the load_image function in file-xwd.c in the X Window Dump (XWD) plug-in in GIMP 2.6.9 and earlier, ... |
| CVE-2013-1812 | — | — | 2.1% | Dec 12, 2013 | The ruby-openid gem before 2.2.2 for Ruby allows remote OpenID providers to cause a denial of service (CPU consumption) ... |
| CVE-2013-1447 | — | — | 2.5% | Dec 12, 2013 | OpenJPEG 1.3 and earlier allows remote attackers to cause a denial of service (memory consumption or crash) via unspecif... |
| CVE-2013-7030 | HIGH | 7.3 | 5.3% | Dec 12, 2013 | The TFTP service in Cisco Unified Communications Manager (aka CUCM or Unified CM) allows remote attackers to obtain sens... |
| CVE-2013-6986 | — | — | 0.6% | Dec 12, 2013 | The ZippyYum Subway CA Kiosk app 3.4 for iOS uses cleartext storage in SQLite cache databases, which allows attackers to... |
| CVE-2013-6810 | — | — | 17.0% | Dec 12, 2013 | The server in Brocade Network Advisor before 12.1.0, as used in EMC Connectrix Manager Converged Network Edition (CMCNE)... |
| CVE-2013-6673 | MEDIUM | 5.9 | 2.9% | Dec 11, 2013 | Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 do not rec... |
| CVE-2013-6672 | — | — | 3.3% | Dec 11, 2013 | Mozilla Firefox before 26.0 and SeaMonkey before 2.23 on Linux allow user-assisted remote attackers to read clipboard da... |
| CVE-2013-6671 | CRITICAL | 9.8 | 11.1% | Dec 11, 2013 | The nsGfxScrollFrameInner::IsLTR function in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird befo... |
| CVE-2013-5619 | — | — | 3.7% | Dec 11, 2013 | Multiple integer overflows in the binary-search implementation in SpiderMonkey in Mozilla Firefox before 26.0 and SeaMon... |
| CVE-2013-5618 | CRITICAL | 9.8 | 10.4% | Dec 11, 2013 | Use-after-free vulnerability in the nsNodeUtils::LastRelease function in the table-editing user interface in the editor ... |
Check if your code is affected by 2013 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now