2013 CVE Vulnerabilities

6,830 CVEs published in 2013.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2013-4394The SetX11Keyboard function in systemd, when PolicyKit Local Authority (PKLA) is used to change the group permissions on...
CVE-2013-4393journald in systemd, when the origin of native messages is set to file, allows local users to cause a denial of service ...
CVE-2013-4391Integer overflow in the valid_user_field function in journal/journald-native.c in systemd allows remote attackers to cau...
CVE-2013-3704The RPM GPG key import and handling feature in libzypp 12.15.0 and earlier reports a different key fingerprint than the ...
CVE-2013-3243Unspecified vulnerability in OpenText/IXOS ECM for SAP NetWeaver allows remote attackers to execute arbitrary ABAP code ...
CVE-2013-2208tpp 1.3.1 allows remote attackers to execute arbitrary commands via a --exec command in a TPP template file.
CVE-2013-2186The DiskFileItem class in Apache Commons FileUpload, as used in Red Hat JBoss BRMS 5.3.1; JBoss Portal 4.3 CP07, 5.2.2, ...
CVE-2013-2102The default configuration of Red Hat JBoss Portal before 6.1.0 enables the JGroups diagnostics service with no authentic...
CVE-2013-1056X.org X server 1.13.3 and earlier, when not run as root, allows local users to cause a denial of service (crash) or poss...
CVE-2013-6285The search component in the Treasurer application in Tyler Technologies TaxWeb 3.13.3.1 allows remote attackers to obtai...
CVE-2013-6020passwordRequestPOST.jsp in Tyler Technologies TaxWeb 3.13.3.1 sends different HTTP status codes for invalid password-rec...
CVE-2013-6019Cross-site scripting (XSS) vulnerability in Tyler Technologies TaxWeb 3.13.3.1 allows remote attackers to inject arbitra...
CVE-2013-6018Cross-site request forgery (CSRF) vulnerability in login.jsp in Tyler Technologies TaxWeb 3.13.3.1 allows remote attacke...
CVE-2013-5430The Jazz Team Server component in IBM Security AppScan Enterprise 8.x before 8.8 has a default username and password, wh...
CVE-2013-4428OpenStack Image Registry and Delivery Service (Glance) Folsom, Grizzly before 2013.1.4, and Havana before 2013.2, when t...
CVE-2013-4302(1) ApiBlock.php, (2) ApiCreateAccount.php, (3) ApiLogin.php, (4) ApiMain.php, (5) ApiQueryDeletedrevs.php, (6) ApiToken...
CVE-2013-4301includes/resourceloader/ResourceLoaderContext.php in MediaWiki 1.19.x before 1.19.8, 1.20.x before 1.20.7, and 1.21.x be...
CVE-2013-4122Cyrus SASL 2.1.23, 2.1.26, and earlier does not properly handle when a NULL value is returned upon an error by the crypt...
CVE-2013-0337The default configuration of nginx, possibly 1.3.13 and earlier, uses world-readable permissions for the (1) access.log ...
CVE-2013-6016The Traffic Management Microkernel (TMM) in F5 BIG-IP LTM, APM, ASM, Edge Gateway, GTM, Link Controller, and WOM 10.0.0 ...
CVE-2013-5914Buffer overflow in the ssl_read_record function in ssl_tls.c in PolarSSL before 1.1.8, when using TLS 1.1, might allow r...
CVE-2013-4885The http-domino-enum-passwords.nse script in NMap before 6.40, when domino-enum-passwords.idpath is set, allows remote s...
CVE-2013-1445The Crypto.Random.atfork function in PyCrypto before 2.6.1 does not properly reseed the pseudo-random number generator (...
CVE-2013-6284Unspecified vulnerability in the Statutory Reporting for Insurance (FS_SR) component in the Financial Services module fo...
CVE-2013-6283VideoLAN VLC Media Player 2.0.8 and earlier allows remote attackers to cause a denial of service (crash) and possibly ex...

Check if your code is affected by 2013 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now