2013 CVE Vulnerabilities
6,830 CVEs published in 2013.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2013-5172 | — | — | 1.1% | Oct 24, 2013 | The kernel in Apple Mac OS X before 10.9 does not properly determine the output length for SHA-2 digest function calls, ... |
| CVE-2013-5171 | — | — | 0.3% | Oct 24, 2013 | CoreGraphics in Apple Mac OS X before 10.9 allows local users to bypass secure input mode and log an arbitrary applicati... |
| CVE-2013-5170 | — | — | 2.4% | Oct 24, 2013 | Buffer underflow in CoreGraphics in Apple Mac OS X before 10.9 allows remote attackers to execute arbitrary code or caus... |
| CVE-2013-5169 | — | — | 0.3% | Oct 24, 2013 | CoreGraphics in Apple Mac OS X before 10.9, when display-sleep mode is used, does not ensure that screen locking blocks ... |
| CVE-2013-5168 | — | — | 1.6% | Oct 24, 2013 | Console in Apple Mac OS X before 10.9 allows user-assisted remote attackers to execute arbitrary applications by trigger... |
| CVE-2013-5167 | — | — | 1.1% | Oct 24, 2013 | CFNetwork in Apple Mac OS X before 10.9 does not properly support Safari's deletion of session cookies in response to a ... |
| CVE-2013-5166 | — | — | 0.3% | Oct 24, 2013 | The Bluetooth USB host controller in Apple Mac OS X before 10.9 prematurely deletes interfaces, which allows local users... |
| CVE-2013-5165 | — | — | 1.6% | Oct 24, 2013 | socketfilterfw in Application Firewall in Apple Mac OS X before 10.9 does not properly implement the --blockApp option, ... |
| CVE-2013-5164 | — | — | 0.2% | Oct 24, 2013 | Multiple race conditions in the Phone app in Apple iOS before 7.0.3 allow physically proximate attackers to bypass the l... |
| CVE-2013-5162 | — | — | 0.4% | Oct 24, 2013 | Passcode Lock in Apple iOS before 7.0.3 on iPhone devices allows physically proximate attackers to bypass the passcode-f... |
| CVE-2013-5144 | — | — | 0.3% | Oct 24, 2013 | Passcode Lock in Apple iOS before 7.0.3 on iPhone devices allows physically proximate attackers to bypass an intended pa... |
| CVE-2013-5136 | — | — | 1.1% | Oct 24, 2013 | Apple Remote Desktop before 3.7 does not properly use server authentication-type information during decisions about whet... |
| CVE-2013-5135 | — | — | 10.8% | Oct 24, 2013 | Format string vulnerability in Screen Sharing Server in Apple Mac OS X before 10.9 and Apple Remote Desktop before 3.5.4... |
| CVE-2013-4390 | — | — | 3.1% | Oct 24, 2013 | Open redirect vulnerability in the AbstractAuthenticationFormServlet in the Auth Core (org.apache.sling.auth.core) bundl... |
| CVE-2013-4373 | — | — | 0.3% | Oct 24, 2013 | The storeFiles method in JPADriftServerBean in Red Hat JBoss Operations Network (JON) 3.1.2 allows local users to load a... |
| CVE-2013-4295 | — | — | 12.2% | Oct 24, 2013 | The gadget renderer in Apache Shindig 2.5.0 for PHP allows remote attackers to obtain sensitive information via an XML d... |
| CVE-2013-4293 | — | — | 0.3% | Oct 24, 2013 | The server in Red Hat JBoss Operations Network (JON) 3.1.2 logs passwords in plaintext, which allows local users to obta... |
| CVE-2013-2236 | — | — | 2.1% | Oct 24, 2013 | Stack-based buffer overflow in the new_msg_lsa_change_notify function in the OSPFD API (ospf_api.c) in Quagga before 0.9... |
| CVE-2013-6245 | — | — | 4.7% | Oct 24, 2013 | Unspecified vulnerability in SAP Sybase Adaptive Server Enterprise (ASE) before 15.0.3 ESD#4.3. 15.5 before 15.5 ESD#5.3... |
| CVE-2013-6244 | — | — | 1.6% | Oct 24, 2013 | The Live Update webdynpro application (webdynpro/dispatcher/sap.com/tc~slm~ui_lup/LUP) in SAP NetWeaver 7.31 and earlier... |
| CVE-2013-3244 | — | — | 1.7% | Oct 24, 2013 | Multiple unspecified vulnerabilities in the CJDB_FILL_MEMORY_FROM_PPB function in the Project System (PS-IS) module for ... |
| CVE-2013-6243 | — | — | 2.5% | Oct 23, 2013 | SQL injection vulnerability in the Landing Pages plugin 1.2.3, before 20131009, and earlier for WordPress allows remote ... |
| CVE-2013-4422 | — | — | 2.1% | Oct 23, 2013 | SQL injection vulnerability in Quassel IRC before 0.9.1, when Qt 4.8.5 or later and PostgreSQL 8.2 or later are used, al... |
| CVE-2013-2651 | — | — | 2.1% | Oct 23, 2013 | Multiple cross-site scripting (XSS) vulnerabilities in BoltWire 3.5 and earlier allow remote attackers to inject arbitra... |
| CVE-2013-5703 | — | — | 1.3% | Oct 22, 2013 | The DrayTek Vigor 2700 router 2.8.3 allows remote attackers to execute arbitrary JavaScript code, and modify settings or... |
Check if your code is affected by 2013 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now