2013 CVE Vulnerabilities
6,830 CVEs published in 2013.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2013-4153 | — | — | 1.7% | Sep 30, 2013 | Double free vulnerability in the qemuAgentGetVCPUs function in qemu/qemu_agent.c in libvirt 1.0.6 through 1.1.0 allows r... |
| CVE-2013-2230 | — | — | 2.1% | Sep 30, 2013 | The qemu driver (qemu/qemu_driver.c) in libvirt before 1.1.1 allows remote authenticated users to cause a denial of serv... |
| CVE-2013-2218 | — | — | 8.3% | Sep 30, 2013 | Double free vulnerability in the virConnectListAllInterfaces method in interface/interface_backend_netcf.c in libvirt 1.... |
| CVE-2013-5965 | — | — | 1.4% | Sep 30, 2013 | The Node View Permissions module 7.x-1.x before 7.x-1.2 for Drupal does not properly implement the hook_query_alter func... |
| CVE-2013-5964 | — | — | 0.9% | Sep 30, 2013 | Cross-site scripting (XSS) vulnerability in the administration page in the Flag module 7.x-3.x before 7.x-3.1 for Drupal... |
| CVE-2013-4372 | — | — | 2.2% | Sep 30, 2013 | Multiple cross-site scripting (XSS) vulnerabilities in Fuse Management Console in Red Hat JBoss Fuse 6.0.0 before patch ... |
| CVE-2013-4359 | — | — | 3.0% | Sep 30, 2013 | Integer overflow in kbdint.c in mod_sftp in ProFTPD 1.3.4d and 1.3.5r3 allows remote attackers to cause a denial of serv... |
| CVE-2013-4136 | — | — | 0.3% | Sep 30, 2013 | ext/common/ServerInstanceDir.h in Phusion Passenger gem before 4.0.6 for Ruby allows local users to gain privileges or p... |
| CVE-2013-1442 | — | — | 0.4% | Sep 30, 2013 | Xen 4.0 through 4.3.x, when using AVX or LWP capable CPUs, does not properly clear previous data from registers when usi... |
| CVE-2013-5960 | — | — | 1.7% | Sep 30, 2013 | The authenticated-encryption feature in the symmetric-encryption implementation in the OWASP Enterprise Security API (ES... |
| CVE-2013-5679 | — | — | 2.4% | Sep 30, 2013 | The authenticated-encryption feature in the symmetric-encryption implementation in the OWASP Enterprise Security API (ES... |
| CVE-2013-5505 | — | — | 1.3% | Sep 30, 2013 | Cross-site scripting (XSS) vulnerability in an administration page in Cisco Identity Services Engine (ISE) allows remote... |
| CVE-2013-5504 | — | — | 1.5% | Sep 30, 2013 | Cross-site scripting (XSS) vulnerability in the Mobile Device Management (MDM) portal in Cisco Identity Services Engine ... |
| CVE-2013-3417 | — | — | 1.3% | Sep 30, 2013 | The administrative web interface in Cisco Video Surveillance Operations Manager does not properly perform authentication... |
| CVE-2013-5959 | — | — | 1.5% | Sep 28, 2013 | Blue Coat ProxySG before 6.2.14.1, 6.3.x, 6.4.x, and 6.5 before 6.5.2 allows remote attackers to cause a denial of servi... |
| CVE-2013-4276 | — | — | 3.5% | Sep 28, 2013 | Multiple stack-based buffer overflows in LittleCMS (aka lcms or liblcms) 1.19 and earlier allow remote attackers to caus... |
| CVE-2013-4244 | — | — | 2.7% | Sep 28, 2013 | The LZW decompressor in the gif2tiff tool in libtiff 4.0.3 and earlier allows context-dependent attackers to cause a den... |
| CVE-2013-4112 | — | — | 1.6% | Sep 28, 2013 | The DiagnosticsHandler in JGroup 3.0.x, 3.1.x, 3.2.x before 3.2.9, and 3.3.x before 3.3.3 allows remote attackers to obt... |
| CVE-2013-2068 | — | — | 58.6% | Sep 28, 2013 | Multiple directory traversal vulnerabilities in the AgentController in Red Hat CloudForms Management Engine 2.0 allow re... |
| CVE-2013-1921 | — | — | 0.2% | Sep 28, 2013 | PicketBox, as used in Red Hat JBoss Enterprise Application Platform before 6.1.1, allows local users to obtain the admin... |
| CVE-2013-5161 | — | — | 0.3% | Sep 28, 2013 | Passcode Lock in Apple iOS before 7.0.2 does not properly manage the lock state, which allows physically proximate attac... |
| CVE-2013-5160 | — | — | 0.3% | Sep 28, 2013 | Passcode Lock in Apple iOS before 7.0.2 on iPhone devices allows physically proximate attackers to bypass an intended pa... |
| CVE-2013-0598 | — | — | 0.6% | Sep 28, 2013 | Cross-site request forgery (CSRF) vulnerability in the Web Client in IBM Rational ClearQuest 7.1 before 7.1.2.12, 8.0 be... |
| CVE-2013-5498 | — | — | 2.3% | Sep 27, 2013 | The PPTP-ALG component in CRS Carrier Grade Services Engine (CGSE) and ASR 9000 Integrated Service Module (ISM) in Cisco... |
| CVE-2013-5403 | — | — | 2.4% | Sep 27, 2013 | Unspecified vulnerability on the IBM WebSphere DataPower XC10 appliance 2.0 through 2.5.0.1 allows remote attackers to o... |
Check if your code is affected by 2013 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now