2013 CVE Vulnerabilities
6,830 CVEs published in 2013.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2013-3416 | — | — | 1.1% | Jul 10, 2013 | Cross-site scripting (XSS) vulnerability in the web framework in the unified-communications management implementation in... |
| CVE-2013-3408 | — | — | 0.3% | Jul 10, 2013 | The firmware on Cisco Virtualization Experience Client 6000 devices sets incorrect operating-system permissions, which a... |
| CVE-2013-1132 | — | — | 0.9% | Jul 10, 2013 | Multiple cross-site scripting (XSS) vulnerabilities in Cisco Unified Communications Domain Manager allow remote attacker... |
| CVE-2013-3405 | — | — | 1.2% | Jul 10, 2013 | The web portal in TC software on Cisco TelePresence endpoints does not require an exact password match during a login at... |
| CVE-2013-3400 | — | — | 0.4% | Jul 10, 2013 | The license-installation module in Cisco NX-OS on Nexus 1000V devices allows local users to execute arbitrary commands v... |
| CVE-2013-1896 | — | — | 29.5% | Jul 10, 2013 | mod_dav.c in the Apache HTTP Server before 2.2.25 does not properly determine whether DAV is enabled for a URI, which al... |
| CVE-2013-1966 | — | — | 71.8% | Jul 10, 2013 | Apache Struts 2 before 2.3.14.2 allows remote attackers to execute arbitrary OGNL code via a crafted request that is not... |
| CVE-2013-1965 | — | — | 93.8% | Jul 10, 2013 | Apache Struts Showcase App 2.0.0 through 2.3.13, as used in Struts 2 before 2.3.14.3, allows remote attackers to execute... |
| CVE-2013-1954 | — | — | 6.1% | Jul 10, 2013 | The ASF Demuxer (modules/demux/asf/asf.c) in VideoLAN VLC media player 2.0.5 and earlier allows remote attackers to caus... |
| CVE-2013-1868 | — | — | 11.0% | Jul 10, 2013 | Multiple buffer overflows in VideoLAN VLC media player 2.0.4 and earlier allow remote attackers to cause a denial of ser... |
| CVE-2013-3350 | — | — | 7.6% | Jul 10, 2013 | Adobe ColdFusion 10 before Update 11 allows remote attackers to call ColdFusion Components (CFC) public methods via WebS... |
| CVE-2013-3349 | — | — | 2.2% | Jul 10, 2013 | Unspecified vulnerability in Adobe ColdFusion 9.0 through 9.0.2, when the JRun application server is used, allows remote... |
| CVE-2013-3348 | — | — | 3.8% | Jul 10, 2013 | Adobe Shockwave Player before 12.0.3.133 allows attackers to execute arbitrary code or cause a denial of service (memory... |
| CVE-2013-3347 | — | — | 4.8% | Jul 10, 2013 | Integer overflow in Adobe Flash Player before 11.7.700.232 and 11.8.x before 11.8.800.94 on Windows and Mac OS X, before... |
| CVE-2013-3345 | — | — | 4.1% | Jul 10, 2013 | Adobe Flash Player before 11.7.700.232 and 11.8.x before 11.8.800.94 on Windows and Mac OS X, before 11.2.202.297 on Lin... |
| CVE-2013-3344 | — | — | 8.0% | Jul 10, 2013 | Heap-based buffer overflow in Adobe Flash Player before 11.7.700.232 and 11.8.x before 11.8.800.94 on Windows and Mac OS... |
| CVE-2013-2880 | — | — | 1.6% | Jul 10, 2013 | Multiple unspecified vulnerabilities in Google Chrome before 28.0.1500.71 allow attackers to cause a denial of service o... |
| CVE-2013-2879 | — | — | 0.9% | Jul 10, 2013 | Google Chrome before 28.0.1500.71 does not properly determine the circumstances in which a renderer process can be consi... |
| CVE-2013-2878 | — | — | 1.1% | Jul 10, 2013 | Google Chrome before 28.0.1500.71 allows remote attackers to cause a denial of service (out-of-bounds read) via vectors ... |
| CVE-2013-2877 | — | — | 4.7% | Jul 10, 2013 | parser.c in libxml2 before 2.9.0, as used in Google Chrome before 28.0.1500.71 and other products, allows remote attacke... |
| CVE-2013-2876 | — | — | 1.1% | Jul 10, 2013 | browser/extensions/api/tabs/tabs_api.cc in Google Chrome before 28.0.1500.71 does not properly enforce restrictions on t... |
| CVE-2013-2875 | — | — | 1.7% | Jul 10, 2013 | core/rendering/svg/SVGInlineTextBox.cpp in the SVG implementation in Blink, as used in Google Chrome before 28.0.1500.71... |
| CVE-2013-2874 | — | — | 1.3% | Jul 10, 2013 | Google Chrome before 28.0.1500.71 on Windows, when an Nvidia GPU is used, allows remote attackers to bypass intended res... |
| CVE-2013-2873 | — | — | 1.3% | Jul 10, 2013 | Use-after-free vulnerability in Google Chrome before 28.0.1500.71 allows remote attackers to cause a denial of service o... |
| CVE-2013-2872 | — | — | 0.9% | Jul 10, 2013 | Google Chrome before 28.0.1500.71 on Mac OS X does not ensure a sufficient source of entropy for renderer processes, whi... |
Check if your code is affected by 2013 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now