2013 CVE Vulnerabilities

6,831 CVEs published in 2013.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2013-4699——The Yahoo! Japan Yafuoku! application 4.3.0 and earlier for iOS and Android does not verify X.509 certificates from SSL ...
CVE-2013-3016——IBM WebSphere Portal 6.1, 7.0, and 8.0 allows remote attackers to access the user directory via a crafted request for a ...
CVE-2013-0526——ping.php in Global Console Manager 16 (GCM16) and Global Console Manager 32 (GCM32) before 1.20.0.22575 on the IBM Avoce...
CVE-2013-4230——The mm_webform submodule in the Monster Menus module 6.x-6.x before 6.x-6.61 and 7.x-1.x before 7.x-1.13 for Drupal does...
CVE-2013-4229——Cross-site scripting (XSS) vulnerability in the Monster Menus module 7.x-1.x before 7.x-1.12 for Drupal allows remote au...
CVE-2013-2905——The SharedMemory::Create function in memory/shared_memory_posix.cc in Google Chrome before 29.0.1547.57 uses weak permis...
CVE-2013-2904——Use-after-free vulnerability in the Document::finishedParsing function in core/dom/Document.cpp in Blink, as used in Goo...
CVE-2013-2903——Use-after-free vulnerability in the HTMLMediaElement::didMoveToNewDocument function in core/html/HTMLMediaElement.cpp in...
CVE-2013-2902——Use-after-free vulnerability in the XSLT ProcessingInstruction implementation in Blink, as used in Google Chrome before ...
CVE-2013-2901——Multiple integer overflows in (1) libGLESv2/renderer/Renderer9.cpp and (2) libGLESv2/renderer/Renderer11.cpp in Almost N...
CVE-2013-2900——The FilePath::ReferencesParent function in files/file_path.cc in Google Chrome before 29.0.1547.57 on Windows does not p...
CVE-2013-2887——Multiple unspecified vulnerabilities in Google Chrome before 29.0.1547.57 allow attackers to cause a denial of service o...
CVE-2013-4967——Puppet Enterprise before 3.0.1 allows remote attackers to obtain the database password via vectors related to how the pa...
CVE-2013-4964——Puppet Enterprise before 3.0.1 does not set the secure flag for the session cookie in an https session, which makes it e...
CVE-2013-4962——The reset password page in Puppet Enterprise before 3.0.1 does not force entry of the current password, which allows att...
CVE-2013-4961——Puppet Enterprise before 3.0.1 includes version information for the Apache and Phusion Passenger products in its HTTP re...
CVE-2013-4959——Puppet Enterprise before 3.0.1 uses HTTP responses that contain sensitive information without the "no-cache" setting, wh...
CVE-2013-4958——Puppet Enterprise before 3.0.1 does not use a session timeout, which makes it easier for attackers to gain privileges by...
CVE-2013-4956——Puppet Module Tool (PMT), as used in Puppet 2.7.x before 2.7.23 and 3.2.x before 3.2.4, and Puppet Enterprise 2.8.x befo...
CVE-2013-4955——Open redirect vulnerability in the login page in Puppet Enterprise before 3.0.1 allows remote attackers to redirect user...
CVE-2013-4762——Puppet Enterprise before 3.0.1 does not sufficiently invalidate a session when a user logs out, which might allow remote...
CVE-2013-4761——Unspecified vulnerability in Puppet 2.7.x before 2.7.23 and 3.2.x before 3.2.4, and Puppet Enterprise 2.8.x before 2.8.3...
CVE-2013-4155——OpenStack Swift before 1.9.1 in Folsom, Grizzly, and Havana allows authenticated users to cause a denial of service ("su...
CVE-2013-4130——The (1) red_channel_pipes_add_type and (2) red_channel_pipes_add_empty_msg functions in server/red_channel.c in SPICE be...
CVE-2013-2210——Heap-based buffer overflow in the XML Signature Reference functionality in Apache Santuario XML Security for C++ (aka xm...

Check if your code is affected by 2013 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now