2013 CVE Vulnerabilities

6,831 CVEs published in 2013.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2013-5697——SQL injection vulnerability in mod_accounting.c in the mod_accounting module 0.5 and earlier for Apache allows remote at...
CVE-2013-5651——The virBitmapParse function in util/virbitmap.c in libvirt before 1.1.2 allows context-dependent attackers to cause a de...
CVE-2013-4316——Apache Struts 2.0.0 through 2.3.15.1 enables Dynamic Method Invocation by default, which has unknown impact and attack v...
CVE-2013-4314——The X509Extension in pyOpenSSL before 0.13.1 does not properly handle a '\0' character in a domain name in the Subject A...
CVE-2013-4310——Apache Struts 2.0.0 through 2.3.15.1 allows remote attackers to bypass access controls via a crafted action: prefix.
CVE-2013-4297——The virFileNBDDeviceAssociate function in util/virfile.c in libvirt 1.1.2 and earlier allows remote authenticated users ...
CVE-2013-4296——The remoteDispatchDomainMemoryStats function in daemon/remote.c in libvirt 0.9.1 through 0.10.1.x, 0.10.2.x before 0.10....
CVE-2013-4292——libvirt 1.1.0 and 1.1.1 allows local users to cause a denial of service (memory consumption) via a large number of domai...
CVE-2013-4291——The virSecurityManagerSetProcessLabel function in libvirt 0.10.2.7, 1.0.5.5, and 1.1.1, when the domain has read an uid:...
CVE-2013-4239——The xenDaemonListDefinedDomains function in xen/xend_internal.c in libvirt 1.1.1 allows remote authenticated users to ca...
CVE-2013-4154——The qemuAgentCommand function in libvirt before 1.1.1, when a guest agent is not configured, allows remote attackers to ...
CVE-2013-4153——Double free vulnerability in the qemuAgentGetVCPUs function in qemu/qemu_agent.c in libvirt 1.0.6 through 1.1.0 allows r...
CVE-2013-2230——The qemu driver (qemu/qemu_driver.c) in libvirt before 1.1.1 allows remote authenticated users to cause a denial of serv...
CVE-2013-2218——Double free vulnerability in the virConnectListAllInterfaces method in interface/interface_backend_netcf.c in libvirt 1....
CVE-2013-5965——The Node View Permissions module 7.x-1.x before 7.x-1.2 for Drupal does not properly implement the hook_query_alter func...
CVE-2013-5964——Cross-site scripting (XSS) vulnerability in the administration page in the Flag module 7.x-3.x before 7.x-3.1 for Drupal...
CVE-2013-4372——Multiple cross-site scripting (XSS) vulnerabilities in Fuse Management Console in Red Hat JBoss Fuse 6.0.0 before patch ...
CVE-2013-4359——Integer overflow in kbdint.c in mod_sftp in ProFTPD 1.3.4d and 1.3.5r3 allows remote attackers to cause a denial of serv...
CVE-2013-4136——ext/common/ServerInstanceDir.h in Phusion Passenger gem before 4.0.6 for Ruby allows local users to gain privileges or p...
CVE-2013-1442——Xen 4.0 through 4.3.x, when using AVX or LWP capable CPUs, does not properly clear previous data from registers when usi...
CVE-2013-5960——The authenticated-encryption feature in the symmetric-encryption implementation in the OWASP Enterprise Security API (ES...
CVE-2013-5679——The authenticated-encryption feature in the symmetric-encryption implementation in the OWASP Enterprise Security API (ES...
CVE-2013-5505——Cross-site scripting (XSS) vulnerability in an administration page in Cisco Identity Services Engine (ISE) allows remote...
CVE-2013-5504——Cross-site scripting (XSS) vulnerability in the Mobile Device Management (MDM) portal in Cisco Identity Services Engine ...
CVE-2013-3417——The administrative web interface in Cisco Video Surveillance Operations Manager does not properly perform authentication...

Check if your code is affected by 2013 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now