2013 CVE Vulnerabilities
6,830 CVEs published in 2013.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2013-3041 | — | — | 1.1% | Oct 1, 2013 | The Web Client in IBM Rational ClearQuest 7.1 before 7.1.2.12, 8.0 before 8.0.0.8, and 8.0.1 before 8.0.1.1 allows remot... |
| CVE-2013-5693 | — | — | 3.2% | Sep 30, 2013 | Cross-site scripting (XSS) vulnerability in X2Engine X2CRM before 3.5 allows remote attackers to inject arbitrary web sc... |
| CVE-2013-5692 | — | — | 5.8% | Sep 30, 2013 | Directory traversal vulnerability in X2Engine X2CRM before 3.5 allows remote authenticated administrators to include and... |
| CVE-2013-4623 | — | — | 1.9% | Sep 30, 2013 | The x509parse_crt function in x509.h in PolarSSL 1.1.x before 1.1.7 and 1.2.x before 1.2.8 does not properly parse certi... |
| CVE-2013-4362 | — | — | 1.2% | Sep 30, 2013 | WEB-DAV Linux File System (davfs2) 1.4.6 and 1.4.7 allow local users to gain privileges via unknown attack vectors in (1... |
| CVE-2013-4222 | — | — | 1.9% | Sep 30, 2013 | OpenStack Identity (Keystone) Folsom, Grizzly 2013.1.3 and earlier, and Havana before havana-3 does not properly revoke ... |
| CVE-2013-2238 | — | — | 2.7% | Sep 30, 2013 | Multiple buffer overflows in the switch_perform_substitution function in switch_regex.c in FreeSWITCH 1.2 allow remote a... |
| CVE-2013-1839 | — | — | 18.3% | Sep 30, 2013 | The strHdrAcptLangGetItem function in errorpage.cc in Squid 3.2.x before 3.2.9 and 3.3.x before 3.3.3 allows remote atta... |
| CVE-2013-1444 | — | — | 0.3% | Sep 30, 2013 | A certain Debian patch for txt2man 1.5.5, as used in txt2man 1.5.5-2, 1.5.5-4, and others, allows local users to overwri... |
| CVE-2013-0211 | — | — | 3.9% | Sep 30, 2013 | Integer signedness error in the archive_write_zip_data function in archive_write_set_format_zip.c in libarchive 3.1.2 an... |
| CVE-2013-5963 | — | — | 4.2% | Sep 30, 2013 | Unrestricted file upload vulnerability in multi.php in Simple Dropbox Upload plugin before 1.8.8.1 for WordPress allows ... |
| CVE-2013-5962 | — | — | 14.8% | Sep 30, 2013 | Unrestricted file upload vulnerability in frames/upload-images.php in the Complete Gallery Manager plugin before 3.3.4 r... |
| CVE-2013-5961 | — | — | 5.5% | Sep 30, 2013 | Unrestricted file upload vulnerability in lazyseo.php in the Lazy SEO plugin 1.1.9 for WordPress allows remote attackers... |
| CVE-2013-4378 | — | — | 2.8% | Sep 30, 2013 | Cross-site scripting (XSS) vulnerability in HtmlSessionInformationsReport.java in JavaMelody 1.46 and earlier allows rem... |
| CVE-2013-5697 | — | — | 1.3% | Sep 30, 2013 | SQL injection vulnerability in mod_accounting.c in the mod_accounting module 0.5 and earlier for Apache allows remote at... |
| CVE-2013-5651 | — | — | 2.3% | Sep 30, 2013 | The virBitmapParse function in util/virbitmap.c in libvirt before 1.1.2 allows context-dependent attackers to cause a de... |
| CVE-2013-4316 | — | — | 8.6% | Sep 30, 2013 | Apache Struts 2.0.0 through 2.3.15.1 enables Dynamic Method Invocation by default, which has unknown impact and attack v... |
| CVE-2013-4314 | — | — | 1.2% | Sep 30, 2013 | The X509Extension in pyOpenSSL before 0.13.1 does not properly handle a '\0' character in a domain name in the Subject A... |
| CVE-2013-4310 | — | — | 7.7% | Sep 30, 2013 | Apache Struts 2.0.0 through 2.3.15.1 allows remote attackers to bypass access controls via a crafted action: prefix. |
| CVE-2013-4297 | — | — | 2.0% | Sep 30, 2013 | The virFileNBDDeviceAssociate function in util/virfile.c in libvirt 1.1.2 and earlier allows remote authenticated users ... |
| CVE-2013-4296 | — | — | 2.7% | Sep 30, 2013 | The remoteDispatchDomainMemoryStats function in daemon/remote.c in libvirt 0.9.1 through 0.10.1.x, 0.10.2.x before 0.10.... |
| CVE-2013-4292 | — | — | 0.3% | Sep 30, 2013 | libvirt 1.1.0 and 1.1.1 allows local users to cause a denial of service (memory consumption) via a large number of domai... |
| CVE-2013-4291 | — | — | 0.5% | Sep 30, 2013 | The virSecurityManagerSetProcessLabel function in libvirt 0.10.2.7, 1.0.5.5, and 1.1.1, when the domain has read an uid:... |
| CVE-2013-4239 | — | — | 2.0% | Sep 30, 2013 | The xenDaemonListDefinedDomains function in xen/xend_internal.c in libvirt 1.1.1 allows remote authenticated users to ca... |
| CVE-2013-4154 | — | — | 2.2% | Sep 30, 2013 | The qemuAgentCommand function in libvirt before 1.1.1, when a guest agent is not configured, allows remote attackers to ... |
Check if your code is affected by 2013 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now