2013 CVE Vulnerabilities
6,830 CVEs published in 2013.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2013-5525 | — | — | 1.3% | Oct 10, 2013 | SQL injection vulnerability in the web framework in Cisco Identity Services Engine (ISE) 1.2 and earlier allows remote a... |
| CVE-2013-5524 | — | — | 1.5% | Oct 10, 2013 | Cross-site scripting (XSS) vulnerability in the troubleshooting page in Cisco Identity Services Engine (ISE) 1.2 and ear... |
| CVE-2013-5523 | — | — | 1.2% | Oct 10, 2013 | The Sponsor Portal in Cisco Identity Services Engine (ISE) 1.2 and earlier does not properly restrict use of IFRAME elem... |
| CVE-2013-5499 | — | — | 0.5% | Oct 10, 2013 | The remember feature in the DHCP server in Cisco IOS allows remote attackers to cause a denial of service (device reload... |
| CVE-2013-5008 | — | — | 0.2% | Oct 10, 2013 | The agent and task-agent components in Symantec Management Platform 7.0 and 7.1 before 7.1 SP2 Mp1.1v7 rollup, as used i... |
| CVE-2013-4396 | — | — | 4.1% | Oct 10, 2013 | Use-after-free vulnerability in the doImageText function in dix/dixfonts.c in the xorg-server module before 1.14.4 in X.... |
| CVE-2013-4387 | — | — | 2.6% | Oct 10, 2013 | net/ipv6/ip6_output.c in the Linux kernel through 3.11.4 does not properly determine the need for UDP Fragmentation Offl... |
| CVE-2013-4345 | — | — | 3.2% | Oct 10, 2013 | Off-by-one error in the get_prng_bytes function in crypto/ansi_cprng.c in the Linux kernel through 3.11.4 makes it easie... |
| CVE-2013-3409 | — | — | 0.3% | Oct 10, 2013 | The portal in Cisco Prime Central for Hosted Collaboration Solution (HCS) places cleartext credentials in temporary file... |
| CVE-2013-0580 | — | — | 0.3% | Oct 10, 2013 | Cross-site request forgery (CSRF) vulnerability in the Optim E-Business Console in IBM Data Growth Solution for Oracle E... |
| CVE-2013-0579 | — | — | 0.6% | Oct 10, 2013 | The Optim E-Business Console in IBM Data Growth Solution for Oracle E-business Suite 6.0 through 9.1 allows remote attac... |
| CVE-2013-0577 | — | — | 0.6% | Oct 10, 2013 | The Optim E-Business Console in IBM Data Growth Solution for Oracle E-business Suite 6.0 through 9.1 allows remote authe... |
| CVE-2013-4767 | — | — | 1.5% | Oct 10, 2013 | Unspecified vulnerability in Eucalyptus before 3.3.2 has unknown impact and attack vectors. |
| CVE-2013-4351 | — | — | 2.5% | Oct 10, 2013 | GnuPG 1.4.x, 2.0.x, and 2.1.x treats a key flags subpacket with all bits cleared (no usage permitted) as if it has all b... |
| CVE-2013-4342 | — | — | 6.4% | Oct 10, 2013 | xinetd does not enforce the user and group configuration directives for TCPMUX services, which causes these services to ... |
| CVE-2013-4271 | — | — | 2.8% | Oct 10, 2013 | The default configuration of the ObjectRepresentation class in Restlet before 2.1.4 deserializes objects from untrusted ... |
| CVE-2013-4221 | — | — | 2.9% | Oct 10, 2013 | The default configuration of the ObjectRepresentation class in Restlet before 2.1.4 deserializes objects from untrusted ... |
| CVE-2013-2241 | — | — | 1.6% | Oct 10, 2013 | modules/gallery/helpers/data_rest.php in Gallery 3 before 3.0.9 allows remote attackers to bypass intended access restri... |
| CVE-2013-2240 | — | — | 1.7% | Oct 10, 2013 | lib/flowplayer.swf.php in Gallery 3 before 3.0.9 does not properly remove query fragments, which allows remote attackers... |
| CVE-2013-2138 | — | — | 2.7% | Oct 10, 2013 | The (1) uploadify and (2) flowplayer SWF files in Gallery 3 before 3.0.8 do not properly remove query parameters and fra... |
| CVE-2013-1881 | — | — | 3.2% | Oct 10, 2013 | GNOME libsvg before 2.39.0 allows remote attackers to read arbitrary files via an XML document containing an external en... |
| CVE-2013-4356 | — | — | 0.6% | Oct 9, 2013 | Xen 4.3.x writes hypervisor mappings to certain shadow pagetables when live migration is performed on hosts with more th... |
| CVE-2013-4332 | — | — | 2.6% | Oct 9, 2013 | Multiple integer overflows in malloc/malloc.c in the GNU C Library (aka glibc or libc6) 2.18 and earlier allow context-d... |
| CVE-2013-4237 | — | — | 3.8% | Oct 9, 2013 | sysdeps/posix/readdir_r.c in the GNU C Library (aka glibc or libc6) 2.18 and earlier allows context-dependent attackers ... |
| CVE-2013-2207 | — | — | 0.4% | Oct 9, 2013 | pt_chown in GNU C Library (aka glibc or libc6) before 2.18 does not properly check permissions for tty files, which allo... |
Check if your code is affected by 2013 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now