2013 CVE Vulnerabilities

6,830 CVEs published in 2013.

CVE IDSeverityCVSSDescription
CVE-2013-4342xinetd does not enforce the user and group configuration directives for TCPMUX services, which causes these services to ...
CVE-2013-4271The default configuration of the ObjectRepresentation class in Restlet before 2.1.4 deserializes objects from untrusted ...
CVE-2013-4221The default configuration of the ObjectRepresentation class in Restlet before 2.1.4 deserializes objects from untrusted ...
CVE-2013-2241modules/gallery/helpers/data_rest.php in Gallery 3 before 3.0.9 allows remote attackers to bypass intended access restri...
CVE-2013-2240lib/flowplayer.swf.php in Gallery 3 before 3.0.9 does not properly remove query fragments, which allows remote attackers...
CVE-2013-2138The (1) uploadify and (2) flowplayer SWF files in Gallery 3 before 3.0.8 do not properly remove query parameters and fra...
CVE-2013-1881GNOME libsvg before 2.39.0 allows remote attackers to read arbitrary files via an XML document containing an external en...
CVE-2013-4356Xen 4.3.x writes hypervisor mappings to certain shadow pagetables when live migration is performed on hosts with more th...
CVE-2013-4332Multiple integer overflows in malloc/malloc.c in the GNU C Library (aka glibc or libc6) 2.18 and earlier allow context-d...
CVE-2013-4237sysdeps/posix/readdir_r.c in the GNU C Library (aka glibc or libc6) 2.18 and earlier allows context-dependent attackers ...
CVE-2013-2207pt_chown in GNU C Library (aka glibc or libc6) before 2.18 does not properly check permissions for tty files, which allo...
CVE-2013-0736Multiple cross-site request forgery (CSRF) vulnerabilities in the Mingle Forum plugin 1.0.34 and possibly earlier for Wo...
CVE-2013-4379The Make Meeting Scheduler module 6.x-1.x before 6.x-1.3 for Drupal allows remote attackers to bypass intended access re...
CVE-2013-5967Multiple SQL injection vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 4.3 and earlier...
CVE-2013-5576administrator/components/com_media/helpers/media.php in the media manager in Joomla! 2.5.x before 2.5.14 and 3.x before ...
CVE-2013-5327MDBMS.dll in Adobe RoboHelp 10 allows attackers to execute arbitrary code or cause a denial of service (memory corruptio...
CVE-2013-5325Adobe Reader and Acrobat 11.x before 11.0.05 on Windows allow remote attackers to execute arbitrary JavaScript code in a...
CVE-2013-4385Buffer overflow in the "read-string!" procedure in the "extras" unit in CHICKEN stable before 4.8.0.5 and development sn...
CVE-2013-4384Cross-site scripting (XSS) vulnerability in Google Site Search module 6.x-1.x before 6.x-1.4 and 7.x-1.x before 7.x-1.10...
CVE-2013-4284Cumin, as used in Red Hat Enterprise MRG 2.4, allows remote attackers to cause a denial of service (CPU and memory consu...
CVE-2013-4258Format string vulnerability in the osLogMsg function in server/os/aulog.c in Network Audio System (NAS) 1.9.3 allows rem...
CVE-2013-4257Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-4256. Reason: This issue was MERGED into CVE-2...
CVE-2013-4256Multiple stack-based and heap-based buffer overflows in Network Audio System (NAS) 1.9.3 allow local users to cause a de...
CVE-2013-3897HIGH8.8Use-after-free vulnerability in the CDisplayPointer class in mshtml.dll in Microsoft Internet Explorer 6 through 11 allo...
CVE-2013-3896MEDIUM5.5Microsoft Silverlight 5 before 5.1.20913.0 does not properly validate pointers during access to Silverlight elements, wh...

Check if your code is affected by 2013 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now