2013 CVE Vulnerabilities
6,830 CVEs published in 2013.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2013-2161 | — | — | 1.9% | Aug 20, 2013 | XML injection vulnerability in account/utils.py in OpenStack Swift Folsom, Grizzly, and Havana allows attackers to trigg... |
| CVE-2013-2157 | — | — | 3.1% | Aug 20, 2013 | OpenStack Keystone Folsom, Grizzly before 2013.1.3, and Havana, when using LDAP with Anonymous binding, allows remote at... |
| CVE-2013-2156 | — | — | 8.4% | Aug 20, 2013 | Heap-based buffer overflow in the Exclusive Canonicalization functionality (xsec/canon/XSECC14n20010315.cpp) in Apache S... |
| CVE-2013-2155 | — | — | 5.8% | Aug 20, 2013 | Apache Santuario XML Security for C++ (aka xml-security-c) before 1.7.1 does not properly validate length values, which ... |
| CVE-2013-2154 | — | — | 8.0% | Aug 20, 2013 | Stack-based buffer overflow in the XML Signature Reference functionality (xsec/dsig/DSIGReference.cpp) in Apache Santuar... |
| CVE-2013-2153 | — | — | 4.8% | Aug 20, 2013 | The XML digital signature functionality (xsec/dsig/DSIGReference.cpp) in Apache Santuario XML Security for C++ (aka xml-... |
| CVE-2013-5323 | — | — | 1.3% | Aug 20, 2013 | Cross-site scripting (XSS) vulnerability in the Static Info Tables (static_info_tables) extension before 2.3.1 for TYPO3... |
| CVE-2013-5322 | — | — | 1.4% | Aug 20, 2013 | SQL injection vulnerability in the CoolURI extension before 1.0.30 for TYPO3 allows remote attackers to execute arbitrar... |
| CVE-2013-5321 | — | — | 1.4% | Aug 20, 2013 | Multiple SQL injection vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 4.1 allow remot... |
| CVE-2013-5320 | — | — | 2.1% | Aug 20, 2013 | Cross-site scripting (XSS) vulnerability in Forums/EditPost.aspx in mojoPortal before 2.3.9.8 allows remote attackers to... |
| CVE-2013-5319 | — | — | 2.1% | Aug 20, 2013 | Cross-site scripting (XSS) vulnerability in secure/admin/user/views/deleteuserconfirm.jsp in the Admin Panel in Atlassia... |
| CVE-2013-5318 | — | — | 2.3% | Aug 20, 2013 | SQL injection vulnerability in Ginkgo CMS 5.0 allows remote attackers to execute arbitrary SQL commands via the rang par... |
| CVE-2013-5317 | — | — | 2.6% | Aug 20, 2013 | Cross-site scripting (XSS) vulnerability in RiteCMS 1.0.0 allows remote authenticated users to inject arbitrary web scri... |
| CVE-2013-5316 | — | — | 2.3% | Aug 20, 2013 | Cross-site request forgery (CSRF) vulnerability in RiteCMS 1.0.0 allows remote attackers to hijack the authentication of... |
| CVE-2013-4653 | — | — | 1.3% | Aug 20, 2013 | Multiple cross-site scripting (XSS) vulnerabilities in the signin functionality of ics in MyTeamwork services in Alcatel... |
| CVE-2013-5315 | — | — | 1.7% | Aug 19, 2013 | Cross-site scripting (XSS) vulnerability in the Resource Manager in the MEE submodule (mee.module) in the Scald module 6... |
| CVE-2013-5029 | — | — | 2.3% | Aug 19, 2013 | phpMyAdmin 3.5.x and 4.0.x before 4.0.5 allows remote attackers to bypass the clickjacking protection mechanism via cert... |
| CVE-2013-4852 | — | — | 3.4% | Aug 19, 2013 | Integer overflow in PuTTY 0.62 and earlier, WinSCP before 5.1.6, and other products that use PuTTY allows remote SSH ser... |
| CVE-2013-4242 | — | — | 0.5% | Aug 19, 2013 | GnuPG before 1.4.14, and Libgcrypt before 1.5.3 as used in GnuPG 2.0.x and possibly other products, allows local users t... |
| CVE-2013-4236 | — | — | 0.6% | Aug 19, 2013 | VDSM in Red Hat Enterprise Virtualization 3 and 3.2 allows privileged guest users to cause the host to become "unavailab... |
| CVE-2013-4208 | — | — | 0.4% | Aug 19, 2013 | The rsa_verify function in PuTTY before 0.63 (1) does not clear sensitive process memory after use and (2) does not free... |
| CVE-2013-4207 | — | — | 1.8% | Aug 19, 2013 | Buffer overflow in sshbn.c in PuTTY before 0.63 allows remote SSH servers to cause a denial of service (crash) via an in... |
| CVE-2013-4206 | — | — | 2.5% | Aug 19, 2013 | Heap-based buffer underflow in the modmul function in sshbn.c in PuTTY before 0.63 allows remote SSH servers to cause a ... |
| CVE-2013-4174 | — | — | 1.4% | Aug 19, 2013 | Multiple cross-site scripting (XSS) vulnerabilities in the Scald module 7.x-1.x before 7.x-1.1 for Drupal allow remote a... |
| CVE-2013-3567 | — | — | 3.4% | Aug 19, 2013 | Puppet 2.7.x before 2.7.22 and 3.2.x before 3.2.2, and Puppet Enterprise before 2.8.2, deserializes untrusted YAML, whic... |
Check if your code is affected by 2013 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now