2013 CVE Vulnerabilities

6,830 CVEs published in 2013.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2013-3016IBM WebSphere Portal 6.1, 7.0, and 8.0 allows remote attackers to access the user directory via a crafted request for a ...
CVE-2013-0526ping.php in Global Console Manager 16 (GCM16) and Global Console Manager 32 (GCM32) before 1.20.0.22575 on the IBM Avoce...
CVE-2013-4230The mm_webform submodule in the Monster Menus module 6.x-6.x before 6.x-6.61 and 7.x-1.x before 7.x-1.13 for Drupal does...
CVE-2013-4229Cross-site scripting (XSS) vulnerability in the Monster Menus module 7.x-1.x before 7.x-1.12 for Drupal allows remote au...
CVE-2013-2905The SharedMemory::Create function in memory/shared_memory_posix.cc in Google Chrome before 29.0.1547.57 uses weak permis...
CVE-2013-2904Use-after-free vulnerability in the Document::finishedParsing function in core/dom/Document.cpp in Blink, as used in Goo...
CVE-2013-2903Use-after-free vulnerability in the HTMLMediaElement::didMoveToNewDocument function in core/html/HTMLMediaElement.cpp in...
CVE-2013-2902Use-after-free vulnerability in the XSLT ProcessingInstruction implementation in Blink, as used in Google Chrome before ...
CVE-2013-2901Multiple integer overflows in (1) libGLESv2/renderer/Renderer9.cpp and (2) libGLESv2/renderer/Renderer11.cpp in Almost N...
CVE-2013-2900The FilePath::ReferencesParent function in files/file_path.cc in Google Chrome before 29.0.1547.57 on Windows does not p...
CVE-2013-2887Multiple unspecified vulnerabilities in Google Chrome before 29.0.1547.57 allow attackers to cause a denial of service o...
CVE-2013-4967Puppet Enterprise before 3.0.1 allows remote attackers to obtain the database password via vectors related to how the pa...
CVE-2013-4964Puppet Enterprise before 3.0.1 does not set the secure flag for the session cookie in an https session, which makes it e...
CVE-2013-4962The reset password page in Puppet Enterprise before 3.0.1 does not force entry of the current password, which allows att...
CVE-2013-4961Puppet Enterprise before 3.0.1 includes version information for the Apache and Phusion Passenger products in its HTTP re...
CVE-2013-4959Puppet Enterprise before 3.0.1 uses HTTP responses that contain sensitive information without the "no-cache" setting, wh...
CVE-2013-4958Puppet Enterprise before 3.0.1 does not use a session timeout, which makes it easier for attackers to gain privileges by...
CVE-2013-4956Puppet Module Tool (PMT), as used in Puppet 2.7.x before 2.7.23 and 3.2.x before 3.2.4, and Puppet Enterprise 2.8.x befo...
CVE-2013-4955Open redirect vulnerability in the login page in Puppet Enterprise before 3.0.1 allows remote attackers to redirect user...
CVE-2013-4762Puppet Enterprise before 3.0.1 does not sufficiently invalidate a session when a user logs out, which might allow remote...
CVE-2013-4761Unspecified vulnerability in Puppet 2.7.x before 2.7.23 and 3.2.x before 3.2.4, and Puppet Enterprise 2.8.x before 2.8.3...
CVE-2013-4155OpenStack Swift before 1.9.1 in Folsom, Grizzly, and Havana allows authenticated users to cause a denial of service ("su...
CVE-2013-4130The (1) red_channel_pipes_add_type and (2) red_channel_pipes_add_empty_msg functions in server/red_channel.c in SPICE be...
CVE-2013-2210Heap-based buffer overflow in the XML Signature Reference functionality in Apache Santuario XML Security for C++ (aka xm...
CVE-2013-2172jcp/xml/dsig/internal/dom/DOMCanonicalizationMethod.java in Apache Santuario XML Security for Java 1.4.x before 1.4.8 an...

Check if your code is affected by 2013 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now