2013 CVE Vulnerabilities

6,830 CVEs published in 2013.

CVE IDSeverityCVSSDescription
CVE-2013-4428OpenStack Image Registry and Delivery Service (Glance) Folsom, Grizzly before 2013.1.4, and Havana before 2013.2, when t...
CVE-2013-4302(1) ApiBlock.php, (2) ApiCreateAccount.php, (3) ApiLogin.php, (4) ApiMain.php, (5) ApiQueryDeletedrevs.php, (6) ApiToken...
CVE-2013-4301includes/resourceloader/ResourceLoaderContext.php in MediaWiki 1.19.x before 1.19.8, 1.20.x before 1.20.7, and 1.21.x be...
CVE-2013-4122Cyrus SASL 2.1.23, 2.1.26, and earlier does not properly handle when a NULL value is returned upon an error by the crypt...
CVE-2013-0337The default configuration of nginx, possibly 1.3.13 and earlier, uses world-readable permissions for the (1) access.log ...
CVE-2013-6016The Traffic Management Microkernel (TMM) in F5 BIG-IP LTM, APM, ASM, Edge Gateway, GTM, Link Controller, and WOM 10.0.0 ...
CVE-2013-5914Buffer overflow in the ssl_read_record function in ssl_tls.c in PolarSSL before 1.1.8, when using TLS 1.1, might allow r...
CVE-2013-4885The http-domino-enum-passwords.nse script in NMap before 6.40, when domino-enum-passwords.idpath is set, allows remote s...
CVE-2013-1445The Crypto.Random.atfork function in PyCrypto before 2.6.1 does not properly reseed the pseudo-random number generator (...
CVE-2013-6284Unspecified vulnerability in the Statutory Reporting for Insurance (FS_SR) component in the Financial Services module fo...
CVE-2013-6283VideoLAN VLC Media Player 2.0.8 and earlier allows remote attackers to cause a denial of service (crash) and possibly ex...
CVE-2013-4965Puppet Enterprise before 3.1.0 does not properly restrict the number of authentication attempts by a console account, wh...
CVE-2013-4957The dashboard report in Puppet Enterprise before 3.0.1 allows attackers to execute arbitrary YAML code via a crafted rep...
CVE-2013-4465Unrestricted file upload vulnerability in the avatar upload functionality in Simple Machines Forum before 2.0.6 and 2.1 ...
CVE-2013-4434Dropbear SSH Server before 2013.59 generates error messages for a failed logon attempt with different time delays depend...
CVE-2013-4421The buf_decompress function in packet.c in Dropbear SSH Server before 2013.59 allows remote attackers to cause a denial ...
CVE-2013-1067Apport 2.12.5 and earlier uses weak permissions for core dump files created by setuid binaries, which allows local users...
CVE-2013-6128The KCHARTXYLib.KChartXY ActiveX control in KChartXY.ocx before 65.30.30000.10002 in WellinTech KingView before 6.53 doe...
CVE-2013-6127The SUPERGRIDLib.SuperGrid ActiveX control in SuperGrid.ocx before 65.30.30000.10002 in WellinTech KingView before 6.53 ...
CVE-2013-5424IBM Flex System Manager (FSM) 1.3.0 allows remote attackers to bypass intended access restrictions, and create new user ...
CVE-2013-3989IBM Security AppScan Enterprise 8.x before 8.8 sends a cleartext AppScan Source database password in a response, which a...
CVE-2013-6281Cross-site scripting (XSS) vulnerability in codebase/spreadsheet.php in the Spreadsheet (dhtmlxSpreadsheet) plugin 2.0 f...
CVE-2013-6280Cross-site scripting (XSS) vulnerability in Social Sharing Toolkit plugin before 2.1.2 for WordPress allows remote attac...
CVE-2013-5549Cisco IOS XR 3.8.1 through 4.2.0 does not properly process fragmented packets within the RP-A, RP-B, PRP, and DRP-B rout...
CVE-2013-5531Cisco Identity Services Engine (ISE) 1.x before 1.1.1 allows remote attackers to bypass authentication, and read support...

Check if your code is affected by 2013 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now