2013 CVE Vulnerabilities
6,830 CVEs published in 2013.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2013-2909 | — | — | 1.6% | Oct 2, 2013 | Use-after-free vulnerability in Blink, as used in Google Chrome before 30.0.1599.66, allows remote attackers to cause a ... |
| CVE-2013-2908 | — | — | 1.3% | Oct 2, 2013 | Google Chrome before 30.0.1599.66 uses incorrect function calls to determine the values of NavigationEntry objects, whic... |
| CVE-2013-2907 | — | — | 1.4% | Oct 2, 2013 | The Window.prototype object implementation in Google Chrome before 30.0.1599.66 allows remote attackers to cause a denia... |
| CVE-2013-2906 | — | — | 1.2% | Oct 2, 2013 | Multiple race conditions in the Web Audio implementation in Blink, as used in Google Chrome before 30.0.1599.66, allow r... |
| CVE-2013-5976 | — | — | 1.8% | Oct 1, 2013 | Cross-site scripting (XSS) vulnerability in the access policy logout page (logout.inc) in F5 BIG-IP APM 10.1.0 through 1... |
| CVE-2013-5975 | — | — | 1.8% | Oct 1, 2013 | The access policy logon page (logon.inc) in F5 BIG-IP APM 11.1.0 through 11.2.1 allows remote attackers to conduct click... |
| CVE-2013-4142 | — | — | — | Oct 1, 2013 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-3969. Reason: This candidate is a duplicate of... |
| CVE-2013-3969 | — | — | 10.1% | Oct 1, 2013 | The find prototype in scripting/engine_v8.h in MongoDB 2.4.0 through 2.4.4 allows remote authenticated users to cause a ... |
| CVE-2013-2013 | — | — | 0.4% | Oct 1, 2013 | The user-password-update command in python-keystoneclient before 0.2.4 accepts the new password in the --password argume... |
| CVE-2013-1892 | — | — | 44.5% | Oct 1, 2013 | MongoDB before 2.0.9 and 2.2.x before 2.2.4 does not properly validate requests to the nativeHelper function in SpiderMo... |
| CVE-2013-5580 | — | — | 2.3% | Oct 1, 2013 | The (1) Conn_StartLogin and (2) cb_Read_Resolver_Result functions in conn.c in ngIRCd 18 through 20.2, when the configur... |
| CVE-2013-3964 | — | — | 3.4% | Oct 1, 2013 | Cross-site scripting (XSS) vulnerability in Samsung SHR-5162, SHR-5082, and possibly other models, allows remote attacke... |
| CVE-2013-3963 | — | — | 1.0% | Oct 1, 2013 | Cross-site request forgery (CSRF) vulnerability in goform/usermanage in Grandstream GXV3501, GXV3504, GXV3601, GXV3601HD... |
| CVE-2013-3962 | — | — | 0.9% | Oct 1, 2013 | Cross-site scripting (XSS) vulnerability in Grandstream GXV3501, GXV3504, GXV3601, GXV3601HD/LL, GXV3611HD/LL, GXV3615W/... |
| CVE-2013-3690 | — | — | 12.4% | Oct 1, 2013 | Cross-site request forgery (CSRF) vulnerability in cgi-bin/users.cgi in Brickcom FB-100Ap, WCB-100Ap, MD-100Ap, WFB-100A... |
| CVE-2013-3688 | — | — | 1.3% | Oct 1, 2013 | The TP-Link IP Cameras TL-SC3171, TL-SC3130, TL-SC3130G, TL-SC3171G, and possibly other models before beta firmware LM.1... |
| CVE-2013-3539 | — | — | 6.3% | Oct 1, 2013 | Cross-site request forgery (CSRF) vulnerability in the command/user.cgi in Sony SNC CH140, SNC CH180, SNC CH240, SNC CH2... |
| CVE-2013-5745 | — | — | 8.7% | Oct 1, 2013 | The vino_server_client_data_pending function in vino-server.c in GNOME Vino 2.26.1, 2.32.1, 3.7.3, and earlier, and 3.8 ... |
| CVE-2013-4708 | — | — | 1.3% | Oct 1, 2013 | The PPP Access Concentrator (PPPAC) in Internet Initiative Japan Inc. SEIL/x86 1.00 through 2.80, SEIL/X1 1.00 through 4... |
| CVE-2013-4361 | — | — | 0.4% | Oct 1, 2013 | The fbld instruction emulation in Xen 3.3.x through 4.3.x does not use the correct variable for the source effective add... |
| CVE-2013-4355 | — | — | 0.3% | Oct 1, 2013 | Xen 4.3.x and earlier does not properly handle certain errors, which allows local HVM guests to obtain hypervisor stack ... |
| CVE-2013-4210 | — | — | 2.7% | Oct 1, 2013 | The org.jboss.remoting.transport.socket.ServerThread class in Red Hat JBoss Remoting for Red Hat JBoss SOA Platform 5.3.... |
| CVE-2013-2269 | — | — | 1.4% | Oct 1, 2013 | The Sponsorship Confirmation functionality in Aruba Networks ClearPass 5.x, 6.0.1, and 6.0.2, and Amigopod/ClearPass Gue... |
| CVE-2013-2231 | — | — | 0.4% | Oct 1, 2013 | Unquoted Windows search path vulnerability in the QEMU Guest Agent service for Red Hat Enterprise Linux Desktop 6, HPC N... |
| CVE-2013-5395 | — | — | 1.5% | Oct 1, 2013 | IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 before 7.1.1.12, and 7.5 before 7.5.0.5 allows remote attackers to by... |
Check if your code is affected by 2013 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now