2013 CVE Vulnerabilities

6,830 CVEs published in 2013.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2013-4965Puppet Enterprise before 3.1.0 does not properly restrict the number of authentication attempts by a console account, wh...
CVE-2013-4957The dashboard report in Puppet Enterprise before 3.0.1 allows attackers to execute arbitrary YAML code via a crafted rep...
CVE-2013-4465Unrestricted file upload vulnerability in the avatar upload functionality in Simple Machines Forum before 2.0.6 and 2.1 ...
CVE-2013-4434Dropbear SSH Server before 2013.59 generates error messages for a failed logon attempt with different time delays depend...
CVE-2013-4421The buf_decompress function in packet.c in Dropbear SSH Server before 2013.59 allows remote attackers to cause a denial ...
CVE-2013-1067Apport 2.12.5 and earlier uses weak permissions for core dump files created by setuid binaries, which allows local users...
CVE-2013-6128The KCHARTXYLib.KChartXY ActiveX control in KChartXY.ocx before 65.30.30000.10002 in WellinTech KingView before 6.53 doe...
CVE-2013-6127The SUPERGRIDLib.SuperGrid ActiveX control in SuperGrid.ocx before 65.30.30000.10002 in WellinTech KingView before 6.53 ...
CVE-2013-5424IBM Flex System Manager (FSM) 1.3.0 allows remote attackers to bypass intended access restrictions, and create new user ...
CVE-2013-3989IBM Security AppScan Enterprise 8.x before 8.8 sends a cleartext AppScan Source database password in a response, which a...
CVE-2013-6281Cross-site scripting (XSS) vulnerability in codebase/spreadsheet.php in the Spreadsheet (dhtmlxSpreadsheet) plugin 2.0 f...
CVE-2013-6280Cross-site scripting (XSS) vulnerability in Social Sharing Toolkit plugin before 2.1.2 for WordPress allows remote attac...
CVE-2013-5549Cisco IOS XR 3.8.1 through 4.2.0 does not properly process fragmented packets within the RP-A, RP-B, PRP, and DRP-B rout...
CVE-2013-5531Cisco Identity Services Engine (ISE) 1.x before 1.1.1 allows remote attackers to bypass authentication, and read support...
CVE-2013-5530The web framework in Cisco Identity Services Engine (ISE) 1.0 and 1.1.0 before 1.1.0.665-5, 1.1.1 before 1.1.1.268-7, 1....
CVE-2013-5522Cisco IOS on Catalyst 3750X switches has default Service Module credentials, which makes it easier for local users to ga...
CVE-2013-5521Cisco Identity Services Engine does not properly restrict the creation of guest accounts, which allows remote attackers ...
CVE-2013-3280EMC RSA Authentication Agent 7.1.x before 7.1.2 for Web for Internet Information Services has a fail-open design, which ...
CVE-2013-5537The web framework on Cisco Web Security Appliance (WSA), Email Security Appliance (ESA), and Content Security Management...
CVE-2013-5536Cisco Secure Access Control System (ACS) does not properly implement an incoming-packet firewall rule, which allows remo...
CVE-2013-5148Apple Keynote before 6.0 does not properly handle the interaction between Keynote presentation mode and the Screen Lock ...
CVE-2013-5143The RADIUS service in Server App in Apple OS X Server before 3.0 selects a fallback X.509 certificate in unspecified cir...
CVE-2013-5130WebKit in Apple Safari before 6.1 disables the Private Browsing feature upon a launch of the Web Inspector, which makes ...
CVE-2013-4443Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2013-4299Interpretation conflict in drivers/md/dm-snap-persistent.c in the Linux kernel through 3.11.6 allows remote authenticate...

Check if your code is affected by 2013 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now