2013 CVE Vulnerabilities

6,830 CVEs published in 2013.

CVE IDSeverityCVSSDescription
CVE-2013-3931MEDIUM5.4Cross-site scripting (XSS) vulnerability in the Jomres (com_jomres) component before 7.3.1 for Joomla! allows remote aut...
CVE-2013-3247HIGH7.8Heap-based buffer overflow in xnview.exe in XnView before 2.03 allows remote attackers to execute arbitrary code via a c...
CVE-2013-3246HIGH7.8Stack-based buffer overflow in xnview.exe in XnView before 2.03 allows remote attackers to execute arbitrary code via a ...
CVE-2013-7486MEDIUM6.1Cross-site scripting (XSS) vulnerability in the backend in Open-Xchange (OX) AppSuite 7.2.x before 7.2.2-rev27 and 7.4.x...
CVE-2013-7485MEDIUM6.1Cross-site scripting (XSS) vulnerability in the backend in Open-Xchange (OX) AppSuite 7.2.x before 7.2.2-rev26 and 7.4.x...
CVE-2013-7062MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in Zope, as used in Plone 3.3.x through 3.3.6, 4.0.x through 4.0.9, ...
CVE-2013-6242MEDIUM6.1Cross-site scripting (XSS) vulnerability in the frontend in Open-Xchange (OX) AppSuite 6.22.3 before 6.22.3-rev5 and 6.2...
CVE-2013-3946HIGH7.8Heap-based buffer overflow in the MrSID plugin (MrSID.dll) before 4.37 for IrfanView allows remote attackers to execute ...
CVE-2013-3945HIGH7.8The MrSID plugin (MrSID.dll) before 4.37 for IrfanView allows remote attackers to execute arbitrary code via a nband tag...
CVE-2013-3944HIGH7.8Stack-based buffer overflow in the MrSID plugin (MrSID.dll) before 4.37 for IrfanView allows remote attackers to execute...
CVE-2013-3621Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-3607. Reason: This candidate is a reservation du...
CVE-2013-3620HIGH7.5Hardcoded WSMan credentials in Intelligent Platform Management Interface (IPMI) with firmware for Supermicro X9 generati...
CVE-2013-3619HIGH8.1Intelligent Platform Management Interface (IPMI) with firmware for Supermicro X9 generation motherboards before SMT_X9_3...
CVE-2013-4752MEDIUM6.1Symfony 2.0.X before 2.0.24, 2.1.X before 2.1.12, 2.2.X before 2.2.5, and 2.3.X before 2.3.3 have an issue in the HttpFo...
CVE-2013-4532HIGH7.8Qemu 1.1.2+dfsg to 2.1+dfsg suffers from a buffer overrun which could potentially result in arbitrary code execution on ...
CVE-2013-3936MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in Opsview before 4.4.1 and Opsview Core before 20130522 allow remot...
CVE-2013-3935HIGH8.8Cross-site request forgery (CSRF) vulnerability in Opsview before 4.4.1 and Opsview Core before 20130522 allows remote a...
CVE-2013-7071MEDIUM6.1Cross-site scripting (XSS) vulnerability in the handle_request function in lib/HTTPServer.pm in Monitorix before 3.4.0 a...
CVE-2013-7070CRITICAL9.8The handle_request function in lib/HTTPServer.pm in Monitorix before 3.3.1 allows remote attackers to execute arbitrary ...
CVE-2013-4357HIGH7.5The eglibc package before 2.14 incorrectly handled the getaddrinfo() function. An attacker could use this issue to cause...
CVE-2013-4161HIGH7.8gksu-polkit-0.0.3-6.fc18 was reported as fixing the issue in CVE-2012-5617 but the patch was improperly applied and it d...
CVE-2013-2016HIGH7.8A flaw was found in the way qemu v1.3.0 and later (virtio-rng) validates addresses when guest accesses the config space ...
CVE-2013-0264HIGH7.5An import error was introduced in Cumin in the code refactoring in r5310. Server certificate validation is always disabl...
CVE-2013-0196MEDIUM6.5A CSRF issue was found in OpenShift Enterprise 1.2. The web console is using 'Basic authentication' and the REST API has...
CVE-2013-5027CRITICAL9.8Collabtive 1.0 has incorrect access control

Check if your code is affected by 2013 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now