2013 CVE Vulnerabilities

6,830 CVEs published in 2013.

CVE IDSeverityCVSSDescription
CVE-2013-4261OpenStack Compute (Nova) Folsom, Grizzly, and earlier, when using Apache Qpid for the RPC backend, does not properly han...
CVE-2013-4185Algorithmic complexity vulnerability in OpenStack Compute (Nova) before 2013.1.3 and Havana before havana-3 does not pro...
CVE-2013-5968Cross-site scripting (XSS) vulnerability in CA SiteMinder 12.0 through 12.51, and SiteMinder 6 Web Agents, allows remote...
CVE-2013-5741Triangle Research International (aka Tri) Nano-10 PLC devices with firmware r81 and earlier do not properly handle large...
CVE-2013-6289Cross-site scripting (XSS) vulnerability in the Apache Solr for TYPO3 (solr) extension before 2.8.3 for TYPO3 allows rem...
CVE-2013-6288Unspecified vulnerability in the Apache Solr for TYPO3 (solr) extension before 2.8.3 for TYPO3 has unknown impact and re...
CVE-2013-6014CRITICAL9.3Juniper Junos 10.4 before 10.4S15, 11.4 before 11.4R9, 11.4X27 before 11.4X27.44, 12.1 before 12.1R7, 12.1X44 before 12....
CVE-2013-6012Juniper Junos 12.1X44 before 12.1.X44-D20 and 12.1X45 before 12.1X45-D15, when the no-validate option is enabled, does n...
CVE-2013-5744Cross-site scripting (XSS) vulnerability in Feng Office 2.3.2-rc and earlier allows remote attackers to inject arbitrary...
CVE-2013-4402The compressed packet parser in GnuPG 1.4.x before 1.4.15 and 2.0.x before 2.0.22 allows remote attackers to cause a den...
CVE-2013-4394The SetX11Keyboard function in systemd, when PolicyKit Local Authority (PKLA) is used to change the group permissions on...
CVE-2013-4393journald in systemd, when the origin of native messages is set to file, allows local users to cause a denial of service ...
CVE-2013-4392MEDIUM5systemd, when updating file permissions, allows local users to change the permissions and SELinux security contexts for ...
CVE-2013-4391Integer overflow in the valid_user_field function in journal/journald-native.c in systemd allows remote attackers to cau...
CVE-2013-3704The RPM GPG key import and handling feature in libzypp 12.15.0 and earlier reports a different key fingerprint than the ...
CVE-2013-3243Unspecified vulnerability in OpenText/IXOS ECM for SAP NetWeaver allows remote attackers to execute arbitrary ABAP code ...
CVE-2013-2208tpp 1.3.1 allows remote attackers to execute arbitrary commands via a --exec command in a TPP template file.
CVE-2013-2186The DiskFileItem class in Apache Commons FileUpload, as used in Red Hat JBoss BRMS 5.3.1; JBoss Portal 4.3 CP07, 5.2.2, ...
CVE-2013-2102The default configuration of Red Hat JBoss Portal before 6.1.0 enables the JGroups diagnostics service with no authentic...
CVE-2013-1056X.org X server 1.13.3 and earlier, when not run as root, allows local users to cause a denial of service (crash) or poss...
CVE-2013-6285The search component in the Treasurer application in Tyler Technologies TaxWeb 3.13.3.1 allows remote attackers to obtai...
CVE-2013-6020passwordRequestPOST.jsp in Tyler Technologies TaxWeb 3.13.3.1 sends different HTTP status codes for invalid password-rec...
CVE-2013-6019Cross-site scripting (XSS) vulnerability in Tyler Technologies TaxWeb 3.13.3.1 allows remote attackers to inject arbitra...
CVE-2013-6018Cross-site request forgery (CSRF) vulnerability in login.jsp in Tyler Technologies TaxWeb 3.13.3.1 allows remote attacke...
CVE-2013-5430The Jazz Team Server component in IBM Security AppScan Enterprise 8.x before 8.8 has a default username and password, wh...

Check if your code is affected by 2013 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now