2013 CVE Vulnerabilities
6,830 CVEs published in 2013.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2013-5711 | — | — | 1.6% | Sep 17, 2013 | Cross-site scripting (XSS) vulnerability in admin/walkthrough/walkthrough.php in the Design Approval System plugin befor... |
| CVE-2013-4766 | — | — | 1.2% | Sep 17, 2013 | The gather log service in Eucalyptus before 3.3.1 allows remote attackers to read log files via an unspecified request t... |
| CVE-2013-2297 | — | — | 0.3% | Sep 17, 2013 | Eucalyptus EuStore sets a blank root password in the default configuration of EMI 3868652036, EMI 0400376721, EMI 242535... |
| CVE-2013-2296 | — | — | 1.0% | Sep 17, 2013 | Walrus in Eucalyptus before 3.2.2 does not verify authorization for the GetBucketLoggingStatus, SetBucketLoggingStatus, ... |
| CVE-2013-5751 | — | — | 2.1% | Sep 16, 2013 | Directory traversal vulnerability in SAP NetWeaver 7.x allows remote attackers to read arbitrary files via unspecified v... |
| CVE-2013-5650 | — | — | 1.8% | Sep 16, 2013 | Junos Pulse Secure Access Service (IVE) 7.1 before 7.1r5, 7.2 before 7.2r10, 7.3 before 7.3r6, and 7.4 before 7.4r3 and ... |
| CVE-2013-4315 | — | — | 3.2% | Sep 16, 2013 | Directory traversal vulnerability in Django 1.4.x before 1.4.7, 1.5.x before 1.5.3, and 1.6.x before 1.6 beta 3 allows r... |
| CVE-2013-4278 | — | — | 1.5% | Sep 16, 2013 | The "create an instance" API in OpenStack Compute (Nova) Folsom, Grizzly, and Havana does not properly enforce the os-fl... |
| CVE-2013-4277 | — | — | 0.7% | Sep 16, 2013 | Svnserve in Apache Subversion 1.4.0 through 1.7.12 and 1.8.0 through 1.8.1 allows local users to overwrite arbitrary fil... |
| CVE-2013-4260 | — | — | 0.3% | Sep 16, 2013 | lib/ansible/playbook/__init__.py in Ansible 1.2.x before 1.2.3, when playbook does not run due to an error, allows local... |
| CVE-2013-4259 | — | — | 0.3% | Sep 16, 2013 | runner/connection_plugins/ssh.py in Ansible before 1.2.3, when using ControlPersist, allows local users to redirect a ss... |
| CVE-2013-4234 | — | — | 4.4% | Sep 16, 2013 | Multiple heap-based buffer overflows in the (1) abc_MIDI_drum and (2) abc_MIDI_gchord functions in load_abc.cpp in libmo... |
| CVE-2013-4233 | — | — | 4.1% | Sep 16, 2013 | Integer overflow in the abc_set_parts function in load_abc.cpp in libmodplug 0.8.8.4 and earlier allows remote attackers... |
| CVE-2013-4183 | — | — | 0.4% | Sep 16, 2013 | The clear_volume function in LVMVolumeDriver driver in OpenStack Cinder 2013.1.1 through 2013.1.2 does not properly clea... |
| CVE-2013-4202 | — | — | 2.6% | Sep 16, 2013 | The (1) backup (api/contrib/backups.py) and (2) volume transfer (contrib/volume_transfer.py) APIs in OpenStack Cinder Gr... |
| CVE-2013-4182 | — | — | 2.4% | Sep 16, 2013 | app/controllers/api/v1/hosts_controller.rb in Foreman before 1.2.2 does not properly restrict access to hosts, which all... |
| CVE-2013-4181 | — | — | 1.4% | Sep 16, 2013 | Cross-site scripting (XSS) vulnerability in the addAlert function in the RedirectServlet servlet in oVirt Engine and Red... |
| CVE-2013-4180 | — | — | 2.4% | Sep 16, 2013 | The (1) power and (2) ipmi_boot actions in the HostController in Foreman before 1.2.2 allow remote attackers to cause a ... |
| CVE-2013-4179 | — | — | 2.7% | Sep 16, 2013 | The security group extension in OpenStack Compute (Nova) Grizzly 2013.1.3, Havana before havana-3, and earlier allows re... |
| CVE-2013-4132 | — | — | 2.4% | Sep 16, 2013 | KDE-Workspace 4.10.5 and earlier does not properly handle the return value of the glibc 2.17 crypt and pw_encrypt functi... |
| CVE-2013-4123 | — | — | 80.5% | Sep 16, 2013 | client_side_request.cc in Squid 3.2.x before 3.2.13 and 3.3.x before 3.3.8 allows remote attackers to cause a denial of ... |
| CVE-2013-2256 | — | — | 1.8% | Sep 16, 2013 | OpenStack Compute (Nova) before 2013.1.3 and Havana before havana-2 does not properly enforce the os-flavor-access:is_pu... |
| CVE-2013-1441 | — | — | 1.3% | Sep 16, 2013 | econvert in ExactImage 0.8.9 and earlier does not properly initialize the setjmp variable, which allows context-dependen... |
| CVE-2013-1439 | — | — | 1.8% | Sep 16, 2013 | The "faster LJPEG decoder" in libraw 0.13.x, 0.14.x, and 0.15.x before 0.15.4 allows context-dependent attackers to caus... |
| CVE-2013-5369 | — | — | 3.1% | Sep 16, 2013 | IBM SPSS Analytical Decision Management 6.1 before IF1, 6.2 before IF1, and 7.0 before FP1 IF6 might allow remote attack... |
Check if your code is affected by 2013 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now