2013 CVE Vulnerabilities
6,830 CVEs published in 2013.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2013-5651 | — | — | 2.3% | Sep 30, 2013 | The virBitmapParse function in util/virbitmap.c in libvirt before 1.1.2 allows context-dependent attackers to cause a de... |
| CVE-2013-4316 | — | — | 8.6% | Sep 30, 2013 | Apache Struts 2.0.0 through 2.3.15.1 enables Dynamic Method Invocation by default, which has unknown impact and attack v... |
| CVE-2013-4314 | — | — | 1.2% | Sep 30, 2013 | The X509Extension in pyOpenSSL before 0.13.1 does not properly handle a '\0' character in a domain name in the Subject A... |
| CVE-2013-4310 | — | — | 7.7% | Sep 30, 2013 | Apache Struts 2.0.0 through 2.3.15.1 allows remote attackers to bypass access controls via a crafted action: prefix. |
| CVE-2013-4297 | — | — | 2.0% | Sep 30, 2013 | The virFileNBDDeviceAssociate function in util/virfile.c in libvirt 1.1.2 and earlier allows remote authenticated users ... |
| CVE-2013-4296 | — | — | 2.7% | Sep 30, 2013 | The remoteDispatchDomainMemoryStats function in daemon/remote.c in libvirt 0.9.1 through 0.10.1.x, 0.10.2.x before 0.10.... |
| CVE-2013-4292 | — | — | 0.3% | Sep 30, 2013 | libvirt 1.1.0 and 1.1.1 allows local users to cause a denial of service (memory consumption) via a large number of domai... |
| CVE-2013-4291 | — | — | 0.5% | Sep 30, 2013 | The virSecurityManagerSetProcessLabel function in libvirt 0.10.2.7, 1.0.5.5, and 1.1.1, when the domain has read an uid:... |
| CVE-2013-4239 | — | — | 2.0% | Sep 30, 2013 | The xenDaemonListDefinedDomains function in xen/xend_internal.c in libvirt 1.1.1 allows remote authenticated users to ca... |
| CVE-2013-4154 | — | — | 2.2% | Sep 30, 2013 | The qemuAgentCommand function in libvirt before 1.1.1, when a guest agent is not configured, allows remote attackers to ... |
| CVE-2013-4153 | — | — | 1.7% | Sep 30, 2013 | Double free vulnerability in the qemuAgentGetVCPUs function in qemu/qemu_agent.c in libvirt 1.0.6 through 1.1.0 allows r... |
| CVE-2013-2230 | — | — | 2.1% | Sep 30, 2013 | The qemu driver (qemu/qemu_driver.c) in libvirt before 1.1.1 allows remote authenticated users to cause a denial of serv... |
| CVE-2013-2218 | — | — | 8.3% | Sep 30, 2013 | Double free vulnerability in the virConnectListAllInterfaces method in interface/interface_backend_netcf.c in libvirt 1.... |
| CVE-2013-5965 | — | — | 1.4% | Sep 30, 2013 | The Node View Permissions module 7.x-1.x before 7.x-1.2 for Drupal does not properly implement the hook_query_alter func... |
| CVE-2013-5964 | — | — | 0.9% | Sep 30, 2013 | Cross-site scripting (XSS) vulnerability in the administration page in the Flag module 7.x-3.x before 7.x-3.1 for Drupal... |
| CVE-2013-4372 | — | — | 2.2% | Sep 30, 2013 | Multiple cross-site scripting (XSS) vulnerabilities in Fuse Management Console in Red Hat JBoss Fuse 6.0.0 before patch ... |
| CVE-2013-4359 | — | — | 3.0% | Sep 30, 2013 | Integer overflow in kbdint.c in mod_sftp in ProFTPD 1.3.4d and 1.3.5r3 allows remote attackers to cause a denial of serv... |
| CVE-2013-4136 | — | — | 0.3% | Sep 30, 2013 | ext/common/ServerInstanceDir.h in Phusion Passenger gem before 4.0.6 for Ruby allows local users to gain privileges or p... |
| CVE-2013-1442 | — | — | 0.4% | Sep 30, 2013 | Xen 4.0 through 4.3.x, when using AVX or LWP capable CPUs, does not properly clear previous data from registers when usi... |
| CVE-2013-5960 | — | — | 1.7% | Sep 30, 2013 | The authenticated-encryption feature in the symmetric-encryption implementation in the OWASP Enterprise Security API (ES... |
| CVE-2013-5679 | — | — | 2.4% | Sep 30, 2013 | The authenticated-encryption feature in the symmetric-encryption implementation in the OWASP Enterprise Security API (ES... |
| CVE-2013-5505 | — | — | 1.3% | Sep 30, 2013 | Cross-site scripting (XSS) vulnerability in an administration page in Cisco Identity Services Engine (ISE) allows remote... |
| CVE-2013-5504 | — | — | 1.5% | Sep 30, 2013 | Cross-site scripting (XSS) vulnerability in the Mobile Device Management (MDM) portal in Cisco Identity Services Engine ... |
| CVE-2013-3417 | — | — | 1.3% | Sep 30, 2013 | The administrative web interface in Cisco Video Surveillance Operations Manager does not properly perform authentication... |
| CVE-2013-5959 | — | — | 1.5% | Sep 28, 2013 | Blue Coat ProxySG before 6.2.14.1, 6.3.x, 6.4.x, and 6.5 before 6.5.2 allows remote attackers to cause a denial of servi... |
Check if your code is affected by 2013 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now