2013 CVE Vulnerabilities

6,830 CVEs published in 2013.

CVE IDSeverityCVSSDescription
CVE-2013-5501Cross-site scripting (XSS) vulnerability in the oraservice page in Cisco MediaSense allows remote attackers to inject ar...
CVE-2013-5500Multiple cross-site scripting (XSS) vulnerabilities in the oraadmin service page in Cisco MediaSense allow remote attack...
CVE-2013-1130Cisco AnyConnect Secure Mobility Client on Mac OS X uses weak permissions for a library directory, which allows local us...
CVE-2013-4709Buffer overflow in the PPP Access Concentrator (PPPAC) on the SEIL/x86 with firmware before 2.82, SEIL/X1 with firmware ...
CVE-2013-4707The SSH implementation on D-Link Japan DES-3810 devices with firmware before R2.20.011 allows remote authenticated users...
CVE-2013-4706The SSH implementation on the D-Link Japan DWL-2100AP with firmware before R252JP-RC572 allows remote authenticated user...
CVE-2013-4068Buffer overflow in iNotes in IBM Domino 8.5.3 before FP5 IF1 and 9.0 before IF4 allows remote authenticated users to exe...
CVE-2013-5497The authentication manager process in the web framework in Cisco Intrusion Prevention System (IPS) does not properly han...
CVE-2013-1121The regex engine in the BGP implementation in Cisco NX-OS, when a complex regular expression is configured for inbound r...
CVE-2013-5159WebKit in Apple iOS before 7 allows remote attackers to bypass the Same Origin Policy and obtain potentially sensitive i...
CVE-2013-5158The Social subsystem in Apple iOS before 7 does not properly restrict access to the cache of Twitter icons, which allows...
CVE-2013-5157The Twitter subsystem in Apple iOS before 7 does not require API conformity for access to Twitter daemon interfaces, whi...
CVE-2013-5156The Telephony subsystem in Apple iOS before 7 does not require API conformity for access to telephony-daemon interfaces,...
CVE-2013-5155The Sandbox subsystem in Apple iOS before 7 allows attackers to cause a denial of service (infinite loop) via an applica...
CVE-2013-5154The Sandbox subsystem in Apple iOS before 7 determines the sandboxing requirement for a #! application on the basis of t...
CVE-2013-5153Springboard in Apple iOS before 7 does not properly manage the lock state in Lost Mode, which allows physically proximat...
CVE-2013-5152Mobile Safari in Apple iOS before 7 allows remote attackers to spoof the URL bar via a crafted web site.
CVE-2013-5151Mobile Safari in Apple iOS before 7 does not prevent HTML interpretation of a document served with a text/plain content ...
CVE-2013-5150The history-clearing feature in Safari in Apple iOS before 7 does not clear the back/forward history of an open tab, whi...
CVE-2013-5149The Push Notifications subsystem in Apple iOS before 7 provides the push-notification token to an app without user appro...
CVE-2013-5147Passcode Lock in Apple iOS before 7 does not properly manage the lock state, which allows physically proximate attackers...
CVE-2013-5145kextd in Kext Management in Apple iOS before 7 does not properly verify authorization for IPC messages, which allows loc...
CVE-2013-5142The kernel in Apple iOS before 7 does not initialize unspecified kernel data structures, which allows local users to obt...
CVE-2013-5141The kernel in Apple iOS before 7 uses an incorrect data size for a certain integer variable, which allows attackers to c...
CVE-2013-5140The kernel in Apple iOS before 7 allows remote attackers to cause a denial of service (assertion failure and device rest...

Check if your code is affected by 2013 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now