2013 CVE Vulnerabilities

6,830 CVEs published in 2013.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2013-5525SQL injection vulnerability in the web framework in Cisco Identity Services Engine (ISE) 1.2 and earlier allows remote a...
CVE-2013-5524Cross-site scripting (XSS) vulnerability in the troubleshooting page in Cisco Identity Services Engine (ISE) 1.2 and ear...
CVE-2013-5523The Sponsor Portal in Cisco Identity Services Engine (ISE) 1.2 and earlier does not properly restrict use of IFRAME elem...
CVE-2013-5499The remember feature in the DHCP server in Cisco IOS allows remote attackers to cause a denial of service (device reload...
CVE-2013-5008The agent and task-agent components in Symantec Management Platform 7.0 and 7.1 before 7.1 SP2 Mp1.1v7 rollup, as used i...
CVE-2013-4396Use-after-free vulnerability in the doImageText function in dix/dixfonts.c in the xorg-server module before 1.14.4 in X....
CVE-2013-4387net/ipv6/ip6_output.c in the Linux kernel through 3.11.4 does not properly determine the need for UDP Fragmentation Offl...
CVE-2013-4345Off-by-one error in the get_prng_bytes function in crypto/ansi_cprng.c in the Linux kernel through 3.11.4 makes it easie...
CVE-2013-3409The portal in Cisco Prime Central for Hosted Collaboration Solution (HCS) places cleartext credentials in temporary file...
CVE-2013-0580Cross-site request forgery (CSRF) vulnerability in the Optim E-Business Console in IBM Data Growth Solution for Oracle E...
CVE-2013-0579The Optim E-Business Console in IBM Data Growth Solution for Oracle E-business Suite 6.0 through 9.1 allows remote attac...
CVE-2013-0577The Optim E-Business Console in IBM Data Growth Solution for Oracle E-business Suite 6.0 through 9.1 allows remote authe...
CVE-2013-4767Unspecified vulnerability in Eucalyptus before 3.3.2 has unknown impact and attack vectors.
CVE-2013-4351GnuPG 1.4.x, 2.0.x, and 2.1.x treats a key flags subpacket with all bits cleared (no usage permitted) as if it has all b...
CVE-2013-4342xinetd does not enforce the user and group configuration directives for TCPMUX services, which causes these services to ...
CVE-2013-4271The default configuration of the ObjectRepresentation class in Restlet before 2.1.4 deserializes objects from untrusted ...
CVE-2013-4221The default configuration of the ObjectRepresentation class in Restlet before 2.1.4 deserializes objects from untrusted ...
CVE-2013-2241modules/gallery/helpers/data_rest.php in Gallery 3 before 3.0.9 allows remote attackers to bypass intended access restri...
CVE-2013-2240lib/flowplayer.swf.php in Gallery 3 before 3.0.9 does not properly remove query fragments, which allows remote attackers...
CVE-2013-2138The (1) uploadify and (2) flowplayer SWF files in Gallery 3 before 3.0.8 do not properly remove query parameters and fra...
CVE-2013-1881GNOME libsvg before 2.39.0 allows remote attackers to read arbitrary files via an XML document containing an external en...
CVE-2013-4356Xen 4.3.x writes hypervisor mappings to certain shadow pagetables when live migration is performed on hosts with more th...
CVE-2013-4332Multiple integer overflows in malloc/malloc.c in the GNU C Library (aka glibc or libc6) 2.18 and earlier allow context-d...
CVE-2013-4237sysdeps/posix/readdir_r.c in the GNU C Library (aka glibc or libc6) 2.18 and earlier allows context-dependent attackers ...
CVE-2013-2207pt_chown in GNU C Library (aka glibc or libc6) before 2.18 does not properly check permissions for tty files, which allo...

Check if your code is affected by 2013 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now