2013 CVE Vulnerabilities
6,830 CVEs published in 2013.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2013-4342 | — | — | 6.4% | Oct 10, 2013 | xinetd does not enforce the user and group configuration directives for TCPMUX services, which causes these services to ... |
| CVE-2013-4271 | — | — | 2.8% | Oct 10, 2013 | The default configuration of the ObjectRepresentation class in Restlet before 2.1.4 deserializes objects from untrusted ... |
| CVE-2013-4221 | — | — | 2.9% | Oct 10, 2013 | The default configuration of the ObjectRepresentation class in Restlet before 2.1.4 deserializes objects from untrusted ... |
| CVE-2013-2241 | — | — | 1.6% | Oct 10, 2013 | modules/gallery/helpers/data_rest.php in Gallery 3 before 3.0.9 allows remote attackers to bypass intended access restri... |
| CVE-2013-2240 | — | — | 1.7% | Oct 10, 2013 | lib/flowplayer.swf.php in Gallery 3 before 3.0.9 does not properly remove query fragments, which allows remote attackers... |
| CVE-2013-2138 | — | — | 2.7% | Oct 10, 2013 | The (1) uploadify and (2) flowplayer SWF files in Gallery 3 before 3.0.8 do not properly remove query parameters and fra... |
| CVE-2013-1881 | — | — | 3.2% | Oct 10, 2013 | GNOME libsvg before 2.39.0 allows remote attackers to read arbitrary files via an XML document containing an external en... |
| CVE-2013-4356 | — | — | 0.6% | Oct 9, 2013 | Xen 4.3.x writes hypervisor mappings to certain shadow pagetables when live migration is performed on hosts with more th... |
| CVE-2013-4332 | — | — | 2.6% | Oct 9, 2013 | Multiple integer overflows in malloc/malloc.c in the GNU C Library (aka glibc or libc6) 2.18 and earlier allow context-d... |
| CVE-2013-4237 | — | — | 3.8% | Oct 9, 2013 | sysdeps/posix/readdir_r.c in the GNU C Library (aka glibc or libc6) 2.18 and earlier allows context-dependent attackers ... |
| CVE-2013-2207 | — | — | 0.4% | Oct 9, 2013 | pt_chown in GNU C Library (aka glibc or libc6) before 2.18 does not properly check permissions for tty files, which allo... |
| CVE-2013-0736 | — | — | 1.1% | Oct 9, 2013 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Mingle Forum plugin 1.0.34 and possibly earlier for Wo... |
| CVE-2013-4379 | — | — | 1.4% | Oct 9, 2013 | The Make Meeting Scheduler module 6.x-1.x before 6.x-1.3 for Drupal allows remote attackers to bypass intended access re... |
| CVE-2013-5967 | — | — | 19.0% | Oct 9, 2013 | Multiple SQL injection vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 4.3 and earlier... |
| CVE-2013-5576 | — | — | 48.2% | Oct 9, 2013 | administrator/components/com_media/helpers/media.php in the media manager in Joomla! 2.5.x before 2.5.14 and 3.x before ... |
| CVE-2013-5327 | — | — | 3.8% | Oct 9, 2013 | MDBMS.dll in Adobe RoboHelp 10 allows attackers to execute arbitrary code or cause a denial of service (memory corruptio... |
| CVE-2013-5325 | — | — | 3.6% | Oct 9, 2013 | Adobe Reader and Acrobat 11.x before 11.0.05 on Windows allow remote attackers to execute arbitrary JavaScript code in a... |
| CVE-2013-4385 | — | — | 3.4% | Oct 9, 2013 | Buffer overflow in the "read-string!" procedure in the "extras" unit in CHICKEN stable before 4.8.0.5 and development sn... |
| CVE-2013-4384 | — | — | 1.8% | Oct 9, 2013 | Cross-site scripting (XSS) vulnerability in Google Site Search module 6.x-1.x before 6.x-1.4 and 7.x-1.x before 7.x-1.10... |
| CVE-2013-4284 | — | — | 2.4% | Oct 9, 2013 | Cumin, as used in Red Hat Enterprise MRG 2.4, allows remote attackers to cause a denial of service (CPU and memory consu... |
| CVE-2013-4258 | — | — | 4.1% | Oct 9, 2013 | Format string vulnerability in the osLogMsg function in server/os/aulog.c in Network Audio System (NAS) 1.9.3 allows rem... |
| CVE-2013-4257 | — | — | — | Oct 9, 2013 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-4256. Reason: This issue was MERGED into CVE-2... |
| CVE-2013-4256 | — | — | 0.7% | Oct 9, 2013 | Multiple stack-based and heap-based buffer overflows in Network Audio System (NAS) 1.9.3 allow local users to cause a de... |
| CVE-2013-3897 | HIGH | 8.8 | 77.5% | Oct 9, 2013 | Use-after-free vulnerability in the CDisplayPointer class in mshtml.dll in Microsoft Internet Explorer 6 through 11 allo... |
| CVE-2013-3896 | MEDIUM | 5.5 | 69.6% | Oct 9, 2013 | Microsoft Silverlight 5 before 5.1.20913.0 does not properly validate pointers during access to Silverlight elements, wh... |
Check if your code is affected by 2013 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now