2013 CVE Vulnerabilities

6,831 CVEs published in 2013.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2013-6283——VideoLAN VLC Media Player 2.0.8 and earlier allows remote attackers to cause a denial of service (crash) and possibly ex...
CVE-2013-4965——Puppet Enterprise before 3.1.0 does not properly restrict the number of authentication attempts by a console account, wh...
CVE-2013-4957——The dashboard report in Puppet Enterprise before 3.0.1 allows attackers to execute arbitrary YAML code via a crafted rep...
CVE-2013-4465——Unrestricted file upload vulnerability in the avatar upload functionality in Simple Machines Forum before 2.0.6 and 2.1 ...
CVE-2013-4434——Dropbear SSH Server before 2013.59 generates error messages for a failed logon attempt with different time delays depend...
CVE-2013-4421——The buf_decompress function in packet.c in Dropbear SSH Server before 2013.59 allows remote attackers to cause a denial ...
CVE-2013-1067——Apport 2.12.5 and earlier uses weak permissions for core dump files created by setuid binaries, which allows local users...
CVE-2013-6128——The KCHARTXYLib.KChartXY ActiveX control in KChartXY.ocx before 65.30.30000.10002 in WellinTech KingView before 6.53 doe...
CVE-2013-6127——The SUPERGRIDLib.SuperGrid ActiveX control in SuperGrid.ocx before 65.30.30000.10002 in WellinTech KingView before 6.53 ...
CVE-2013-5424——IBM Flex System Manager (FSM) 1.3.0 allows remote attackers to bypass intended access restrictions, and create new user ...
CVE-2013-3989——IBM Security AppScan Enterprise 8.x before 8.8 sends a cleartext AppScan Source database password in a response, which a...
CVE-2013-6281——Cross-site scripting (XSS) vulnerability in codebase/spreadsheet.php in the Spreadsheet (dhtmlxSpreadsheet) plugin 2.0 f...
CVE-2013-6280——Cross-site scripting (XSS) vulnerability in Social Sharing Toolkit plugin before 2.1.2 for WordPress allows remote attac...
CVE-2013-5549——Cisco IOS XR 3.8.1 through 4.2.0 does not properly process fragmented packets within the RP-A, RP-B, PRP, and DRP-B rout...
CVE-2013-5531——Cisco Identity Services Engine (ISE) 1.x before 1.1.1 allows remote attackers to bypass authentication, and read support...
CVE-2013-5530——The web framework in Cisco Identity Services Engine (ISE) 1.0 and 1.1.0 before 1.1.0.665-5, 1.1.1 before 1.1.1.268-7, 1....
CVE-2013-5522——Cisco IOS on Catalyst 3750X switches has default Service Module credentials, which makes it easier for local users to ga...
CVE-2013-5521——Cisco Identity Services Engine does not properly restrict the creation of guest accounts, which allows remote attackers ...
CVE-2013-3280——EMC RSA Authentication Agent 7.1.x before 7.1.2 for Web for Internet Information Services has a fail-open design, which ...
CVE-2013-5537——The web framework on Cisco Web Security Appliance (WSA), Email Security Appliance (ESA), and Content Security Management...
CVE-2013-5536——Cisco Secure Access Control System (ACS) does not properly implement an incoming-packet firewall rule, which allows remo...
CVE-2013-5148——Apple Keynote before 6.0 does not properly handle the interaction between Keynote presentation mode and the Screen Lock ...
CVE-2013-5143——The RADIUS service in Server App in Apple OS X Server before 3.0 selects a fallback X.509 certificate in unspecified cir...
CVE-2013-5130——WebKit in Apple Safari before 6.1 disables the Private Browsing feature upon a launch of the Web Inspector, which makes ...
CVE-2013-4443——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...

Check if your code is affected by 2013 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now