2013 CVE Vulnerabilities

6,830 CVEs published in 2013.

CVE IDSeverityCVSSDescription
CVE-2013-3469Cisco Mobility Services Engine does not properly set up the Oracle SSL service, which allows remote attackers to obtain ...
CVE-2013-1661VMware ESXi 4.0 through 5.1, and ESX 4.0 and 4.1, does not properly implement the Network File Copy (NFC) protocol, whic...
CVE-2013-5664Cross-site scripting (XSS) vulnerability in the web-based device-management API browser in Palo Alto Networks PAN-OS bef...
CVE-2013-5663The App-ID cache feature in Palo Alto Networks PAN-OS before 4.0.14, 4.1.x before 4.1.11, and 5.0.x before 5.0.2 allows ...
CVE-2013-4702Multiple directory traversal vulnerabilities in the doApiAction function in data/class/api/SC_Api_Operation.php in LOCKO...
CVE-2013-3485Multiple untrusted search path vulnerabilities in Soda PDF 5.1.183.10520 allow local users to gain privileges via a Troj...
CVE-2013-5469The TCP implementation in Cisco IOS does not properly implement the transitions from the ESTABLISHED state to the CLOSED...
CVE-2013-3474The Web Administrator Interface on Cisco Wireless LAN Controller (WLC) devices allows remote authenticated users to caus...
CVE-2013-3346CRITICAL9.8Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitr...
CVE-2013-3470The RIP process in Cisco IOS XR allows remote attackers to cause a denial of service (process crash) via a crafted versi...
CVE-2013-3467Memory leak in the CLI component on Cisco Unified Computing System (UCS) 6100 Fabric Interconnect devices, in certain si...
CVE-2013-3463The protocol-inspection feature on Cisco Adaptive Security Appliances (ASA) devices does not properly implement the idle...
CVE-2013-5648Absolute path traversal vulnerability in the handleStartDataFile function in DigiDocSAXParser.c in libdigidoc 3.6.0.0, a...
CVE-2013-5647lib/sounder/sound.rb in the sounder gem 1.0.1 for Ruby allows remote attackers to execute arbitrary commands via shell m...
CVE-2013-5646Cross-site scripting (XSS) vulnerability in Roundcube webmail 1.0-git allows remote authenticated users to inject arbitr...
CVE-2013-5645Multiple cross-site scripting (XSS) vulnerabilities in Roundcube webmail before 0.9.3 allow user-assisted remote attacke...
CVE-2013-5589SQL injection vulnerability in cacti/host.php in Cacti 0.8.8b and earlier allows remote attackers to execute arbitrary S...
CVE-2013-5588Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.8b and earlier allow remote attackers to inject arbitra...
CVE-2013-5209The sctp_send_initiate_ack function in sys/netinet/sctp_output.c in the SCTP implementation in the kernel in FreeBSD 8.3...
CVE-2013-4003Multiple cross-site scripting (XSS) vulnerabilities in IBM TRIRIGA Application Platform 2.x and 3.x before 3.3.1.1, and ...
CVE-2013-3472Cross-site request forgery (CSRF) vulnerability in the Enterprise License Manager (ELM) in Cisco Unified Communications ...
CVE-2013-3471The captive portal application in Cisco Identity Services Engine (ISE) allows remote attackers to discover cleartext use...
CVE-2013-3468The Cisco Unified IP Phone 8945 with software 9.3(2) allows remote attackers to cause a denial of service (device hang) ...
CVE-2013-3466The EAP-FAST authentication module in Cisco Secure Access Control Server (ACS) 4.x before 4.2.1.15.11, when a RADIUS ser...
CVE-2013-5018The is_asn1 function in strongSwan 4.1.11 through 5.0.4 does not properly validate the return value of the asn1_length f...

Check if your code is affected by 2013 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now