2013 CVE Vulnerabilities
6,830 CVEs published in 2013.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2013-1676 | — | — | 5.6% | May 16, 2013 | The SelectionIterator::GetNextSegment function in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbi... |
| CVE-2013-1674 | — | — | 5.8% | May 16, 2013 | Use-after-free vulnerability in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, ... |
| CVE-2013-1673 | — | — | 0.3% | May 16, 2013 | The Mozilla Updater in Mozilla Firefox before 21.0 on Windows does not properly maintain Mozilla Maintenance Service reg... |
| CVE-2013-1672 | — | — | 0.3% | May 16, 2013 | The Mozilla Maintenance Service in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.... |
| CVE-2013-1671 | — | — | 1.0% | May 16, 2013 | Mozilla Firefox before 21.0 does not properly implement the INPUT element, which allows remote attackers to obtain the f... |
| CVE-2013-1670 | — | — | 11.0% | May 16, 2013 | The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbi... |
| CVE-2013-1669 | — | — | 5.4% | May 16, 2013 | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 21.0 allow remote attackers to caus... |
| CVE-2013-1389 | — | — | 6.1% | May 16, 2013 | Unspecified vulnerability in Adobe ColdFusion 9.0 before Update 11, 9.0.1 before Update 10, 9.0.2 before Update 5, and 1... |
| CVE-2013-0801 | — | — | 5.4% | May 16, 2013 | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.... |
| CVE-2013-1245 | — | — | 1.0% | May 16, 2013 | The user-management page in Cisco WebEx Social relies on client-side validation of values in the Screen Name, First Name... |
| CVE-2013-1244 | — | — | 0.8% | May 16, 2013 | Cross-site scripting (XSS) vulnerability in the portal module in Cisco WebEx Social allows remote authenticated users to... |
| CVE-2013-1236 | — | — | 1.3% | May 16, 2013 | Cisco TelePresence Supervisor MSE 8050 before 2.3(1.31) allows remote attackers to cause a denial of service (CPU consum... |
| CVE-2013-1200 | — | — | 1.2% | May 16, 2013 | Session fixation vulnerability in Cisco Secure Access Control System (ACS) allows remote attackers to hijack web session... |
| CVE-2013-1188 | — | — | 1.4% | May 16, 2013 | Cisco Unified Communications Manager (CUCM) does not properly limit the rate of authentication attempts, which allows re... |
| CVE-2013-1175 | — | — | — | May 16, 2013 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This issue was announced by the vendor an... |
| CVE-2013-1346 | — | — | 11.6% | May 15, 2013 | mpengine.dll in Microsoft Malware Protection Engine before 1.1.9506.0 on x64 platforms allows remote attackers to execut... |
| CVE-2013-1337 | — | — | 20.6% | May 15, 2013 | Microsoft .NET Framework 4.5 does not properly create policy requirements for custom Windows Communication Foundation (W... |
| CVE-2013-1336 | — | — | 19.3% | May 15, 2013 | The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly check si... |
| CVE-2013-1335 | — | — | 20.9% | May 15, 2013 | Microsoft Word 2003 SP3 and Word Viewer allow remote attackers to execute arbitrary code via crafted shape data in a Wor... |
| CVE-2013-1334 | — | — | 1.7% | May 15, 2013 | win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, W... |
| CVE-2013-1333 | — | — | 2.1% | May 15, 2013 | Buffer overflow in win32k.sys in the kernel-mode drivers in Microsoft Windows 7 SP1 allows local users to gain privilege... |
| CVE-2013-1332 | — | — | 1.9% | May 15, 2013 | dxgkrnl.sys (aka the DirectX graphics kernel subsystem) in the kernel-mode drivers in Microsoft Windows Vista SP2, Windo... |
| CVE-2013-1329 | — | — | 20.8% | May 15, 2013 | Integer signedness error in Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code via a crafted... |
| CVE-2013-1328 | — | — | 20.8% | May 15, 2013 | Microsoft Publisher 2003 SP3, 2007 SP3, and 2010 SP1 allows remote attackers to execute arbitrary code via a crafted Pub... |
| CVE-2013-1327 | — | — | 20.8% | May 15, 2013 | Integer signedness error in Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code via a crafted... |
Check if your code is affected by 2013 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now