2013 CVE Vulnerabilities

6,830 CVEs published in 2013.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2013-3631NAS4Free 9.1.0.1.804 and earlier allows remote authenticated users to execute arbitrary PHP code via a request to exec.p...
CVE-2013-3617The XML API in Openbravo ERP 2.5, 3.0, and earlier allows remote authenticated users to read arbitrary files via an XML ...
CVE-2013-3287EMC Unisphere for VMAX before 1.6.1.6, when using an unspecified level of debug logging in LDAP configurations, allows l...
CVE-2013-3285The NetWorker Management Console (NMC) in EMC NetWorker 8.0.x before 8.0.2.3, when using Active Directory/LDAP for authe...
CVE-2013-2065(1) DL and (2) Fiddle in Ruby 1.9 before 1.9.3 patchlevel 426, and 2.0 before 2.0.0 patchlevel 195, do not perform taint...
CVE-2013-1084Directory traversal vulnerability in the GetFle method in the umaninv service in Novell ZENworks Configuration Managemen...
CVE-2013-6076strongSwan 5.0.2 through 5.1.0 allows remote attackers to cause a denial of service (NULL pointer dereference and charon...
CVE-2013-6075The compare_dn function in utils/identification.c in strongSwan 4.3.3 through 5.1.1 allows (1) remote attackers to cause...
CVE-2013-4494Xen before 4.1.x, 4.2.x, and 4.3.x does not take the page_alloc_lock and grant_table.lock in the same order, which allow...
CVE-2013-4469OpenStack Compute (Nova) Folsom, Grizzly, and Havana, when use_cow_images is set to False, does not verify the virtual s...
CVE-2013-4457The Cocaine gem 0.4.0 through 0.5.2 for Ruby allows context-dependent attackers to execute arbitrary commands via a craf...
CVE-2013-4401The virConnectDomainXMLToNative API function in libvirt 1.1.0 through 1.1.3 checks for the connect:read permission inste...
CVE-2013-2652CRLF injection vulnerability in help/help_language.php in WebCollab 3.30 and earlier allows remote attackers to inject a...
CVE-2013-5977Cross-site request forgery (CSRF) vulnerability in Cart66Product.php in the Cart66 Lite plugin before 1.5.1.15 for WordP...
CVE-2013-4447Cross-site scripting (XSS) vulnerability in the API in the Simplenews module 6.x-1.x before 6.x-1.5 and 7.x-1.x before 7...
CVE-2013-2701Cross-site request forgery (CSRF) vulnerability in the Social Sharing Toolkit plugin 2.1.1 for WordPress allows remote a...
CVE-2013-5555Cisco Unified Communications Manager (aka CUCM or Unified CM) allows remote attackers to cause a denial of service (serv...
CVE-2013-5551Cisco Adaptive Security Appliance (ASA) Software, when certain same-security-traffic and management-access options are e...
CVE-2013-5548The IKEv2 implementation in Cisco IOS, when AES-GCM or AES-GMAC is used, allows remote attackers to bypass certain IPsec...
CVE-2013-5431Open redirect vulnerability in IBM Tivoli Federated Identity Manager (TFIM) 6.1.1 before IF 15, 6.2.0 before IF 14, 6.2....
CVE-2013-4713Cross-site scripting (XSS) vulnerability in I-O DATA DEVICE RockDisk with firmware before 1.05e1-2.0.5 allows remote aut...
CVE-2013-4484Varnish before 3.0.5 allows remote attackers to cause a denial of service (child-process crash and temporary caching out...
CVE-2013-3630Moodle through 2.5.2 allows remote authenticated administrators to execute arbitrary programs by configuring the aspell ...
CVE-2013-5547Cisco IOS XE 3.9 before 3.9.2S on 1000 ASR devices allows remote attackers to cause a denial of service (device reload) ...
CVE-2013-5546The TCP reassembly feature in Cisco IOS XE 3.7 before 3.7.3S and 3.8 before 3.8.1S on 1000 ASR devices allows remote att...

Check if your code is affected by 2013 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now