2013 CVE Vulnerabilities
6,830 CVEs published in 2013.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2013-1307 | — | — | 20.6% | May 15, 2013 | Use-after-free vulnerability in Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code vi... |
| CVE-2013-1306 | — | — | 33.4% | May 15, 2013 | Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code via a cr... |
| CVE-2013-1305 | — | — | 54.7% | May 15, 2013 | HTTP.sys in Microsoft Windows 8, Windows Server 2012, and Windows RT allows remote attackers to cause a denial of servic... |
| CVE-2013-1302 | — | — | 21.9% | May 15, 2013 | Microsoft Communicator 2007 R2, Lync 2010, Lync 2010 Attendee, and Lync Server 2013 do not properly handle objects in me... |
| CVE-2013-1301 | — | — | 16.7% | May 15, 2013 | Microsoft Visio 2003 SP3 2007 SP3, and 2010 SP1 allows remote attackers to read arbitrary files via an XML document cont... |
| CVE-2013-1297 | — | — | 16.8% | May 15, 2013 | Microsoft Internet Explorer 6 through 8 does not properly restrict data access by VBScript, which allows remote attacker... |
| CVE-2013-0811 | — | — | 20.6% | May 15, 2013 | Use-after-free vulnerability in Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code vi... |
| CVE-2013-0096 | — | — | 16.1% | May 15, 2013 | Writer in Microsoft Windows Essentials 2011 and 2012 allows remote attackers to bypass proxy settings and overwrite arbi... |
| CVE-2013-2094 | HIGH | 8.4 | 47.7% | May 14, 2013 | The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data t... |
| CVE-2013-3538 | — | — | 3.2% | May 13, 2013 | Multiple cross-site scripting (XSS) vulnerabilities in todooforum.php in Todoo Forum 2.0 allow remote attackers to injec... |
| CVE-2013-3537 | — | — | 2.2% | May 13, 2013 | Multiple SQL injection vulnerabilities in todooforum.php in Todoo Forum 2.0 allow remote attackers to execute arbitrary ... |
| CVE-2013-3536 | — | — | 2.2% | May 13, 2013 | SQL injection vulnerability in the gp_LoadUserFromHash function in functions_hash.php in the Group Pay module 1.5 and ea... |
| CVE-2013-3535 | — | — | 4.2% | May 13, 2013 | Multiple cross-site scripting (XSS) vulnerabilities in CMSLogik 1.2.0 and 1.2.1 allow remote attackers to inject arbitra... |
| CVE-2013-3534 | — | — | 1.2% | May 13, 2013 | Cross-site scripting (XSS) vulnerability in the aiContactSafe component before 2.0.21 for Joomla! allows remote attacker... |
| CVE-2013-2021 | — | — | 3.5% | May 13, 2013 | pdf.c in ClamAV 0.97.1 through 0.97.7 allows remote attackers to cause a denial of service (out-of-bounds-read) via a cr... |
| CVE-2013-2020 | — | — | 3.5% | May 13, 2013 | Integer underflow in the cli_scanpe function in pe.c in ClamAV before 0.97.8 allows remote attackers to cause a denial o... |
| CVE-2013-1952 | — | — | 0.4% | May 13, 2013 | Xen 4.x, when using Intel VT-d for a bus mastering capable PCI device, does not properly check the source when accessing... |
| CVE-2013-1940 | — | — | 0.4% | May 13, 2013 | X.Org X server before 1.13.4 and 1.4.x before 1.14.1 does not properly restrict access to input events when adding a new... |
| CVE-2013-1922 | — | — | 0.3% | May 13, 2013 | qemu-nbd in QEMU, as used in Xen 4.2.x, determines the format of a raw disk image based on the header, which allows loca... |
| CVE-2013-1919 | — | — | 0.4% | May 13, 2013 | Xen 4.2.x and 4.1.x does not properly restrict access to IRQs, which allows local stub domain clients to gain access to ... |
| CVE-2013-1918 | — | — | 0.4% | May 13, 2013 | Certain page table manipulation operations in Xen 4.1.x, 4.2.x, and earlier are not preemptible, which allows local PV k... |
| CVE-2013-1917 | — | — | 0.4% | May 13, 2013 | Xen 3.1 through 4.x, when running 64-bit hosts on Intel CPUs, does not clear the NT flag when using an IRET after a SYSE... |
| CVE-2013-1897 | — | — | 2.1% | May 13, 2013 | The do_search function in ldap/servers/slapd/search.c in 389 Directory Server 1.2.x before 1.2.11.20 and 1.3.x before 1.... |
| CVE-2013-1136 | — | — | 0.2% | May 13, 2013 | The crypto engine process in Cisco IOS on Aggregation Services Router (ASR) Route Processor 2 does not properly manage m... |
| CVE-2013-3533 | — | — | 1.3% | May 10, 2013 | Multiple SQL injection vulnerabilities in Virtual Access Monitor 3.10.17 and earlier allow attackers to execute arbitrar... |
Check if your code is affected by 2013 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now