2013 CVE Vulnerabilities

6,830 CVEs published in 2013.

CVE IDSeverityCVSSDescription
CVE-2013-2904Use-after-free vulnerability in the Document::finishedParsing function in core/dom/Document.cpp in Blink, as used in Goo...
CVE-2013-2903Use-after-free vulnerability in the HTMLMediaElement::didMoveToNewDocument function in core/html/HTMLMediaElement.cpp in...
CVE-2013-2902Use-after-free vulnerability in the XSLT ProcessingInstruction implementation in Blink, as used in Google Chrome before ...
CVE-2013-2901Multiple integer overflows in (1) libGLESv2/renderer/Renderer9.cpp and (2) libGLESv2/renderer/Renderer11.cpp in Almost N...
CVE-2013-2900The FilePath::ReferencesParent function in files/file_path.cc in Google Chrome before 29.0.1547.57 on Windows does not p...
CVE-2013-2887Multiple unspecified vulnerabilities in Google Chrome before 29.0.1547.57 allow attackers to cause a denial of service o...
CVE-2013-4967Puppet Enterprise before 3.0.1 allows remote attackers to obtain the database password via vectors related to how the pa...
CVE-2013-4964Puppet Enterprise before 3.0.1 does not set the secure flag for the session cookie in an https session, which makes it e...
CVE-2013-4962The reset password page in Puppet Enterprise before 3.0.1 does not force entry of the current password, which allows att...
CVE-2013-4961Puppet Enterprise before 3.0.1 includes version information for the Apache and Phusion Passenger products in its HTTP re...
CVE-2013-4959Puppet Enterprise before 3.0.1 uses HTTP responses that contain sensitive information without the "no-cache" setting, wh...
CVE-2013-4958Puppet Enterprise before 3.0.1 does not use a session timeout, which makes it easier for attackers to gain privileges by...
CVE-2013-4956Puppet Module Tool (PMT), as used in Puppet 2.7.x before 2.7.23 and 3.2.x before 3.2.4, and Puppet Enterprise 2.8.x befo...
CVE-2013-4955Open redirect vulnerability in the login page in Puppet Enterprise before 3.0.1 allows remote attackers to redirect user...
CVE-2013-4762Puppet Enterprise before 3.0.1 does not sufficiently invalidate a session when a user logs out, which might allow remote...
CVE-2013-4761Unspecified vulnerability in Puppet 2.7.x before 2.7.23 and 3.2.x before 3.2.4, and Puppet Enterprise 2.8.x before 2.8.3...
CVE-2013-4155OpenStack Swift before 1.9.1 in Folsom, Grizzly, and Havana allows authenticated users to cause a denial of service ("su...
CVE-2013-4130The (1) red_channel_pipes_add_type and (2) red_channel_pipes_add_empty_msg functions in server/red_channel.c in SPICE be...
CVE-2013-2210Heap-based buffer overflow in the XML Signature Reference functionality in Apache Santuario XML Security for C++ (aka xm...
CVE-2013-2172jcp/xml/dsig/internal/dom/DOMCanonicalizationMethod.java in Apache Santuario XML Security for Java 1.4.x before 1.4.8 an...
CVE-2013-2161XML injection vulnerability in account/utils.py in OpenStack Swift Folsom, Grizzly, and Havana allows attackers to trigg...
CVE-2013-2157OpenStack Keystone Folsom, Grizzly before 2013.1.3, and Havana, when using LDAP with Anonymous binding, allows remote at...
CVE-2013-2156Heap-based buffer overflow in the Exclusive Canonicalization functionality (xsec/canon/XSECC14n20010315.cpp) in Apache S...
CVE-2013-2155Apache Santuario XML Security for C++ (aka xml-security-c) before 1.7.1 does not properly validate length values, which ...
CVE-2013-2154Stack-based buffer overflow in the XML Signature Reference functionality (xsec/dsig/DSIGReference.cpp) in Apache Santuar...

Check if your code is affected by 2013 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now