2013 CVE Vulnerabilities
6,830 CVEs published in 2013.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2013-4436 | — | — | 1.8% | Nov 5, 2013 | The default configuration for salt-ssh in Salt (aka SaltStack) 0.17.0 does not validate the SSH host key of requests, wh... |
| CVE-2013-4435 | — | — | 1.5% | Nov 5, 2013 | Salt (aka SaltStack) 0.15.0 through 0.17.0 allows remote authenticated users who are using external authentication or cl... |
| CVE-2013-6366 | — | — | 7.0% | Nov 4, 2013 | The Groovy script console in VMware Hyperic HQ 4.6.6 allows remote authenticated administrators to execute arbitrary cod... |
| CVE-2013-6340 | — | — | 1.7% | Nov 4, 2013 | epan/dissectors/packet-tcp.c in the TCP dissector in Wireshark 1.8.x before 1.8.11 and 1.10.x before 1.10.3 does not pro... |
| CVE-2013-6339 | — | — | 2.0% | Nov 4, 2013 | The dissect_openwire_type function in epan/dissectors/packet-openwire.c in the OpenWire dissector in Wireshark 1.8.x bef... |
| CVE-2013-6338 | — | — | 1.7% | Nov 4, 2013 | The dissect_sip_common function in epan/dissectors/packet-sip.c in the SIP dissector in Wireshark 1.8.x before 1.8.11 an... |
| CVE-2013-6337 | — | — | 1.5% | Nov 4, 2013 | Unspecified vulnerability in the NBAP dissector in Wireshark 1.8.x before 1.8.11 and 1.10.x before 1.10.3 allows remote ... |
| CVE-2013-6336 | — | — | 1.9% | Nov 4, 2013 | The ieee802154_map_rec function in epan/dissectors/packet-ieee802154.c in the IEEE 802.15.4 dissector in Wireshark 1.8.x... |
| CVE-2013-5564 | — | — | 1.8% | Nov 4, 2013 | The Java process in the Impact server in Cisco Prime Central for Hosted Collaboration Solution (HCS) allows remote attac... |
| CVE-2013-5561 | — | — | 1.2% | Nov 4, 2013 | The Safe Search enforcement feature in Cisco Adaptive Security Appliance (ASA) CX Context-Aware Security Software does n... |
| CVE-2013-5559 | — | — | 2.0% | Nov 4, 2013 | Buffer overflow in the Active Template Library (ATL) framework in the VPNAPI COM module in Cisco AnyConnect Secure Mobil... |
| CVE-2013-4839 | — | — | 4.0% | Nov 4, 2013 | Unspecified vulnerability in Virtual User Generator in HP LoadRunner before 11.52 allows remote attackers to obtain sens... |
| CVE-2013-4838 | — | — | 10.7% | Nov 4, 2013 | Unspecified vulnerability in Virtual User Generator in HP LoadRunner before 11.52 allows remote attackers to execute arb... |
| CVE-2013-4837 | — | — | 62.6% | Nov 4, 2013 | Unspecified vulnerability in Virtual User Generator in HP LoadRunner before 11.52 allows remote attackers to execute arb... |
| CVE-2013-4836 | — | — | 5.5% | Nov 4, 2013 | Unspecified vulnerability in the GossipService SOAP Request implementation in the Synchronizer component before 1.4.2 in... |
| CVE-2013-4835 | — | — | 71.0% | Nov 4, 2013 | The APISiteScopeImpl SOAP service in HP SiteScope 10.1x and 11.x before 11.22 allows remote attackers to bypass authenti... |
| CVE-2013-4834 | — | — | 5.5% | Nov 4, 2013 | Unspecified vulnerability in the client component in HP Application LifeCycle Management (ALM) before 11 p11 allows remo... |
| CVE-2013-6114 | — | — | 4.9% | Nov 4, 2013 | Integer overflow in the OZDocument::parseElement function in Apple Motion 5.0.7 allows remote attackers to cause a denia... |
| CVE-2013-4483 | — | — | 0.5% | Nov 4, 2013 | The ipc_rcu_putref function in ipc/util.c in the Linux kernel before 3.10 does not properly manage a reference count, wh... |
| CVE-2013-4470 | — | — | 0.6% | Nov 4, 2013 | The Linux kernel before 3.12, when UDP Fragmentation Offload (UFO) is enabled, does not properly initialize certain data... |
| CVE-2013-4348 | — | — | 9.4% | Nov 4, 2013 | The skb_flow_dissect function in net/core/flow_dissector.c in the Linux kernel through 3.12 allows remote attackers to c... |
| CVE-2013-2058 | — | — | 0.5% | Nov 4, 2013 | The host_start function in drivers/usb/chipidea/host.c in the Linux kernel before 3.7.4 does not properly support a cert... |
| CVE-2013-6349 | — | — | 2.5% | Nov 2, 2013 | McAfee Email Gateway (MEG) 7.0 before 7.0.4 and 7.5 before 7.5.1 allows remote authenticated users to execute arbitrary ... |
| CVE-2013-6348 | — | — | 6.1% | Nov 2, 2013 | Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 2.3.15.3 allow remote attackers to inject arbitrary... |
| CVE-2013-6111 | — | — | 1.2% | Nov 2, 2013 | Cross-site scripting (XSS) vulnerability in the mod_pagespeed module 0.x, 1.0.22.7, 1.1.x, 1.24.1, 1.3.25.1 through 1.3.... |
Check if your code is affected by 2013 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now