2013 CVE Vulnerabilities

6,831 CVEs published in 2013.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2013-5526——Cisco 9900 fourth-generation IP phones do not properly perform SDP negotiation, which allows remote attackers to cause a...
CVE-2013-5525——SQL injection vulnerability in the web framework in Cisco Identity Services Engine (ISE) 1.2 and earlier allows remote a...
CVE-2013-5524——Cross-site scripting (XSS) vulnerability in the troubleshooting page in Cisco Identity Services Engine (ISE) 1.2 and ear...
CVE-2013-5523——The Sponsor Portal in Cisco Identity Services Engine (ISE) 1.2 and earlier does not properly restrict use of IFRAME elem...
CVE-2013-5499——The remember feature in the DHCP server in Cisco IOS allows remote attackers to cause a denial of service (device reload...
CVE-2013-5008——The agent and task-agent components in Symantec Management Platform 7.0 and 7.1 before 7.1 SP2 Mp1.1v7 rollup, as used i...
CVE-2013-4396——Use-after-free vulnerability in the doImageText function in dix/dixfonts.c in the xorg-server module before 1.14.4 in X....
CVE-2013-4387——net/ipv6/ip6_output.c in the Linux kernel through 3.11.4 does not properly determine the need for UDP Fragmentation Offl...
CVE-2013-4345——Off-by-one error in the get_prng_bytes function in crypto/ansi_cprng.c in the Linux kernel through 3.11.4 makes it easie...
CVE-2013-3409——The portal in Cisco Prime Central for Hosted Collaboration Solution (HCS) places cleartext credentials in temporary file...
CVE-2013-0580——Cross-site request forgery (CSRF) vulnerability in the Optim E-Business Console in IBM Data Growth Solution for Oracle E...
CVE-2013-0579——The Optim E-Business Console in IBM Data Growth Solution for Oracle E-business Suite 6.0 through 9.1 allows remote attac...
CVE-2013-0577——The Optim E-Business Console in IBM Data Growth Solution for Oracle E-business Suite 6.0 through 9.1 allows remote authe...
CVE-2013-4767——Unspecified vulnerability in Eucalyptus before 3.3.2 has unknown impact and attack vectors.
CVE-2013-4351——GnuPG 1.4.x, 2.0.x, and 2.1.x treats a key flags subpacket with all bits cleared (no usage permitted) as if it has all b...
CVE-2013-4342——xinetd does not enforce the user and group configuration directives for TCPMUX services, which causes these services to ...
CVE-2013-4271——The default configuration of the ObjectRepresentation class in Restlet before 2.1.4 deserializes objects from untrusted ...
CVE-2013-4221——The default configuration of the ObjectRepresentation class in Restlet before 2.1.4 deserializes objects from untrusted ...
CVE-2013-2241——modules/gallery/helpers/data_rest.php in Gallery 3 before 3.0.9 allows remote attackers to bypass intended access restri...
CVE-2013-2240——lib/flowplayer.swf.php in Gallery 3 before 3.0.9 does not properly remove query fragments, which allows remote attackers...
CVE-2013-2138——The (1) uploadify and (2) flowplayer SWF files in Gallery 3 before 3.0.8 do not properly remove query parameters and fra...
CVE-2013-1881——GNOME libsvg before 2.39.0 allows remote attackers to read arbitrary files via an XML document containing an external en...
CVE-2013-4356——Xen 4.3.x writes hypervisor mappings to certain shadow pagetables when live migration is performed on hosts with more th...
CVE-2013-4332——Multiple integer overflows in malloc/malloc.c in the GNU C Library (aka glibc or libc6) 2.18 and earlier allow context-d...
CVE-2013-4237——sysdeps/posix/readdir_r.c in the GNU C Library (aka glibc or libc6) 2.18 and earlier allows context-dependent attackers ...

Check if your code is affected by 2013 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now