2013 CVE Vulnerabilities

6,831 CVEs published in 2013.

CVE IDSeverityCVSSDescription
CVE-2013-3932HIGH8.8SQL injection vulnerability in the Jomres (com_jomres) component before 7.3.1 for Joomla! allows remote authenticated us...
CVE-2013-3931MEDIUM5.4Cross-site scripting (XSS) vulnerability in the Jomres (com_jomres) component before 7.3.1 for Joomla! allows remote aut...
CVE-2013-3247HIGH7.8Heap-based buffer overflow in xnview.exe in XnView before 2.03 allows remote attackers to execute arbitrary code via a c...
CVE-2013-3246HIGH7.8Stack-based buffer overflow in xnview.exe in XnView before 2.03 allows remote attackers to execute arbitrary code via a ...
CVE-2013-7486MEDIUM6.1Cross-site scripting (XSS) vulnerability in the backend in Open-Xchange (OX) AppSuite 7.2.x before 7.2.2-rev27 and 7.4.x...
CVE-2013-7485MEDIUM6.1Cross-site scripting (XSS) vulnerability in the backend in Open-Xchange (OX) AppSuite 7.2.x before 7.2.2-rev26 and 7.4.x...
CVE-2013-7062MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in Zope, as used in Plone 3.3.x through 3.3.6, 4.0.x through 4.0.9, ...
CVE-2013-6242MEDIUM6.1Cross-site scripting (XSS) vulnerability in the frontend in Open-Xchange (OX) AppSuite 6.22.3 before 6.22.3-rev5 and 6.2...
CVE-2013-3946HIGH7.8Heap-based buffer overflow in the MrSID plugin (MrSID.dll) before 4.37 for IrfanView allows remote attackers to execute ...
CVE-2013-3945HIGH7.8The MrSID plugin (MrSID.dll) before 4.37 for IrfanView allows remote attackers to execute arbitrary code via a nband tag...
CVE-2013-3944HIGH7.8Stack-based buffer overflow in the MrSID plugin (MrSID.dll) before 4.37 for IrfanView allows remote attackers to execute...
CVE-2013-3621——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-3607. Reason: This candidate is a reservation du...
CVE-2013-3620HIGH7.5Hardcoded WSMan credentials in Intelligent Platform Management Interface (IPMI) with firmware for Supermicro X9 generati...
CVE-2013-3619HIGH8.1Intelligent Platform Management Interface (IPMI) with firmware for Supermicro X9 generation motherboards before SMT_X9_3...
CVE-2013-4752MEDIUM6.1Symfony 2.0.X before 2.0.24, 2.1.X before 2.1.12, 2.2.X before 2.2.5, and 2.3.X before 2.3.3 have an issue in the HttpFo...
CVE-2013-4532HIGH7.8Qemu 1.1.2+dfsg to 2.1+dfsg suffers from a buffer overrun which could potentially result in arbitrary code execution on ...
CVE-2013-3936MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in Opsview before 4.4.1 and Opsview Core before 20130522 allow remot...
CVE-2013-3935HIGH8.8Cross-site request forgery (CSRF) vulnerability in Opsview before 4.4.1 and Opsview Core before 20130522 allows remote a...
CVE-2013-7071MEDIUM6.1Cross-site scripting (XSS) vulnerability in the handle_request function in lib/HTTPServer.pm in Monitorix before 3.4.0 a...
CVE-2013-7070CRITICAL9.8The handle_request function in lib/HTTPServer.pm in Monitorix before 3.3.1 allows remote attackers to execute arbitrary ...
CVE-2013-4357HIGH7.5The eglibc package before 2.14 incorrectly handled the getaddrinfo() function. An attacker could use this issue to cause...
CVE-2013-4161HIGH7.8gksu-polkit-0.0.3-6.fc18 was reported as fixing the issue in CVE-2012-5617 but the patch was improperly applied and it d...
CVE-2013-2016HIGH7.8A flaw was found in the way qemu v1.3.0 and later (virtio-rng) validates addresses when guest accesses the config space ...
CVE-2013-0264HIGH7.5An import error was introduced in Cumin in the code refactoring in r5310. Server certificate validation is always disabl...
CVE-2013-0196MEDIUM6.5A CSRF issue was found in OpenShift Enterprise 1.2. The web console is using 'Basic authentication' and the REST API has...

Check if your code is affected by 2013 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now