2013 CVE Vulnerabilities
6,830 CVEs published in 2013.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2013-6023 | — | — | 10.2% | Nov 2, 2013 | Directory traversal vulnerability in the TVT TD-2308SS-B DVR with firmware 3.2.0.P-3520A-00 and earlier allows remote at... |
| CVE-2013-6347 | — | — | 1.2% | Nov 2, 2013 | Session fixation vulnerability in Novell ZENworks Configuration Management (ZCM) before 11.2.4 allows remote attackers t... |
| CVE-2013-6346 | — | — | 0.6% | Nov 2, 2013 | Cross-site request forgery (CSRF) vulnerability in the ZCC page in Novell ZENworks Configuration Management (ZCM) before... |
| CVE-2013-6345 | — | — | 1.5% | Nov 2, 2013 | Unspecified vulnerability in the ZCC page in Novell ZENworks Configuration Management (ZCM) before 11.2.4 has unknown im... |
| CVE-2013-6344 | — | — | 0.9% | Nov 2, 2013 | The ZCC page in Novell ZENworks Configuration Management (ZCM) before 11.2.4 allows attackers to conduct cross-frame scr... |
| CVE-2013-4477 | — | — | 0.4% | Nov 2, 2013 | The LDAP backend in OpenStack Identity (Keystone) Grizzly and Havana, when removing a role on a tenant for a user who do... |
| CVE-2013-4416 | — | — | 0.5% | Nov 2, 2013 | The Ocaml xenstored implementation (oxenstored) in Xen 4.1.x, 4.2.x, and 4.3.x allows local guest domains to cause a den... |
| CVE-2013-4349 | — | — | — | Nov 2, 2013 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-4540. Reason: This candidate was MERGED into C... |
| CVE-2013-4282 | — | — | 2.7% | Nov 2, 2013 | Stack-based buffer overflow in the reds_handle_ticket function in server/reds.c in SPICE 0.12.0 allows remote attackers ... |
| CVE-2013-3631 | — | — | 12.6% | Nov 2, 2013 | NAS4Free 9.1.0.1.804 and earlier allows remote authenticated users to execute arbitrary PHP code via a request to exec.p... |
| CVE-2013-3617 | — | — | 21.1% | Nov 2, 2013 | The XML API in Openbravo ERP 2.5, 3.0, and earlier allows remote authenticated users to read arbitrary files via an XML ... |
| CVE-2013-3287 | — | — | 0.3% | Nov 2, 2013 | EMC Unisphere for VMAX before 1.6.1.6, when using an unspecified level of debug logging in LDAP configurations, allows l... |
| CVE-2013-3285 | — | — | 1.0% | Nov 2, 2013 | The NetWorker Management Console (NMC) in EMC NetWorker 8.0.x before 8.0.2.3, when using Active Directory/LDAP for authe... |
| CVE-2013-2065 | — | — | 2.5% | Nov 2, 2013 | (1) DL and (2) Fiddle in Ruby 1.9 before 1.9.3 patchlevel 426, and 2.0 before 2.0.0 patchlevel 195, do not perform taint... |
| CVE-2013-1084 | — | — | 5.7% | Nov 2, 2013 | Directory traversal vulnerability in the GetFle method in the umaninv service in Novell ZENworks Configuration Managemen... |
| CVE-2013-6076 | — | — | 1.9% | Nov 2, 2013 | strongSwan 5.0.2 through 5.1.0 allows remote attackers to cause a denial of service (NULL pointer dereference and charon... |
| CVE-2013-6075 | — | — | 2.4% | Nov 2, 2013 | The compare_dn function in utils/identification.c in strongSwan 4.3.3 through 5.1.1 allows (1) remote attackers to cause... |
| CVE-2013-4494 | — | — | 0.7% | Nov 2, 2013 | Xen before 4.1.x, 4.2.x, and 4.3.x does not take the page_alloc_lock and grant_table.lock in the same order, which allow... |
| CVE-2013-4469 | — | — | 0.4% | Nov 2, 2013 | OpenStack Compute (Nova) Folsom, Grizzly, and Havana, when use_cow_images is set to False, does not verify the virtual s... |
| CVE-2013-4457 | — | — | 1.5% | Nov 2, 2013 | The Cocaine gem 0.4.0 through 0.5.2 for Ruby allows context-dependent attackers to execute arbitrary commands via a craf... |
| CVE-2013-4401 | — | — | 1.7% | Nov 2, 2013 | The virConnectDomainXMLToNative API function in libvirt 1.1.0 through 1.1.3 checks for the connect:read permission inste... |
| CVE-2013-2652 | — | — | 2.5% | Nov 2, 2013 | CRLF injection vulnerability in help/help_language.php in WebCollab 3.30 and earlier allows remote attackers to inject a... |
| CVE-2013-5977 | — | — | 3.2% | Nov 1, 2013 | Cross-site request forgery (CSRF) vulnerability in Cart66Product.php in the Cart66 Lite plugin before 1.5.1.15 for WordP... |
| CVE-2013-4447 | — | — | 2.7% | Nov 1, 2013 | Cross-site scripting (XSS) vulnerability in the API in the Simplenews module 6.x-1.x before 6.x-1.5 and 7.x-1.x before 7... |
| CVE-2013-2701 | — | — | 1.0% | Nov 1, 2013 | Cross-site request forgery (CSRF) vulnerability in the Social Sharing Toolkit plugin 2.1.1 for WordPress allows remote a... |
Check if your code is affected by 2013 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now