2013 CVE Vulnerabilities
6,830 CVEs published in 2013.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2013-4260 | — | — | 0.3% | Sep 16, 2013 | lib/ansible/playbook/__init__.py in Ansible 1.2.x before 1.2.3, when playbook does not run due to an error, allows local... |
| CVE-2013-4259 | — | — | 0.3% | Sep 16, 2013 | runner/connection_plugins/ssh.py in Ansible before 1.2.3, when using ControlPersist, allows local users to redirect a ss... |
| CVE-2013-4234 | — | — | 4.4% | Sep 16, 2013 | Multiple heap-based buffer overflows in the (1) abc_MIDI_drum and (2) abc_MIDI_gchord functions in load_abc.cpp in libmo... |
| CVE-2013-4233 | — | — | 4.1% | Sep 16, 2013 | Integer overflow in the abc_set_parts function in load_abc.cpp in libmodplug 0.8.8.4 and earlier allows remote attackers... |
| CVE-2013-4202 | — | — | 2.6% | Sep 16, 2013 | The (1) backup (api/contrib/backups.py) and (2) volume transfer (contrib/volume_transfer.py) APIs in OpenStack Cinder Gr... |
| CVE-2013-4183 | — | — | 0.4% | Sep 16, 2013 | The clear_volume function in LVMVolumeDriver driver in OpenStack Cinder 2013.1.1 through 2013.1.2 does not properly clea... |
| CVE-2013-4182 | — | — | 2.4% | Sep 16, 2013 | app/controllers/api/v1/hosts_controller.rb in Foreman before 1.2.2 does not properly restrict access to hosts, which all... |
| CVE-2013-4181 | — | — | 1.4% | Sep 16, 2013 | Cross-site scripting (XSS) vulnerability in the addAlert function in the RedirectServlet servlet in oVirt Engine and Red... |
| CVE-2013-4180 | — | — | 2.4% | Sep 16, 2013 | The (1) power and (2) ipmi_boot actions in the HostController in Foreman before 1.2.2 allow remote attackers to cause a ... |
| CVE-2013-4179 | — | — | 2.7% | Sep 16, 2013 | The security group extension in OpenStack Compute (Nova) Grizzly 2013.1.3, Havana before havana-3, and earlier allows re... |
| CVE-2013-4132 | — | — | 2.4% | Sep 16, 2013 | KDE-Workspace 4.10.5 and earlier does not properly handle the return value of the glibc 2.17 crypt and pw_encrypt functi... |
| CVE-2013-4123 | — | — | 80.5% | Sep 16, 2013 | client_side_request.cc in Squid 3.2.x before 3.2.13 and 3.3.x before 3.3.8 allows remote attackers to cause a denial of ... |
| CVE-2013-2256 | — | — | 1.8% | Sep 16, 2013 | OpenStack Compute (Nova) before 2013.1.3 and Havana before havana-2 does not properly enforce the os-flavor-access:is_pu... |
| CVE-2013-1441 | — | — | 1.3% | Sep 16, 2013 | econvert in ExactImage 0.8.9 and earlier does not properly initialize the setjmp variable, which allows context-dependen... |
| CVE-2013-1439 | — | — | 1.8% | Sep 16, 2013 | The "faster LJPEG decoder" in libraw 0.13.x, 0.14.x, and 0.15.x before 0.15.4 allows context-dependent attackers to caus... |
| CVE-2013-4049 | — | — | 2.2% | Sep 16, 2013 | Unrestricted file upload vulnerability in IBM SPSS Analytical Decision Management 6.1 before IF1, 6.2 before IF1, and 7.... |
| CVE-2013-5369 | — | — | 3.1% | Sep 16, 2013 | IBM SPSS Analytical Decision Management 6.1 before IF1, 6.2 before IF1, and 7.0 before FP1 IF6 might allow remote attack... |
| CVE-2013-4048 | — | — | 0.8% | Sep 16, 2013 | Cross-site scripting (XSS) vulnerability in IBM SPSS Analytical Decision Management 6.1 before IF1, 6.2 before IF1, and ... |
| CVE-2013-4047 | — | — | 0.9% | Sep 16, 2013 | Cross-site scripting (XSS) vulnerability in IBM SPSS Analytical Decision Management 6.1 before IF1, 6.2 before IF1, and ... |
| CVE-2013-5674 | — | — | 2.1% | Sep 16, 2013 | badges/external.php in Moodle 2.5.x before 2.5.2 does not properly handle an object obtained by unserializing a descript... |
| CVE-2013-4341 | — | — | 21.9% | Sep 16, 2013 | Multiple cross-site scripting (XSS) vulnerabilities in Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, an... |
| CVE-2013-4313 | — | — | 1.2% | Sep 16, 2013 | Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 does not prevent use of '\0' chara... |
| CVE-2013-5496 | — | — | 1.6% | Sep 16, 2013 | Open Network Environment Platform (ONEP) in Cisco NX-OS allows remote authenticated users to cause a denial of service (... |
| CVE-2013-5494 | — | — | 0.8% | Sep 16, 2013 | Cross-site request forgery (CSRF) vulnerability in the web framework in Cisco Unified MeetingPlace Solution, as used in ... |
| CVE-2013-5495 | — | — | 1.4% | Sep 16, 2013 | Cross-site scripting (XSS) vulnerability in the web framework in the Application Server in Cisco Unified MeetingPlace al... |
Check if your code is affected by 2013 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now