2013 CVE Vulnerabilities

6,830 CVEs published in 2013.

CVE IDSeverityCVSSDescription
CVE-2013-7172HIGH7.8Slackware 13.1, 13.37, 14.0 and 14.1 contain world-writable permissions on the iodbctest and iodbctestw programs within ...
CVE-2013-7171CRITICAL9.8Slackware 14.0 and 14.1, and Slackware LLVM 3.0-i486-2 and 3.3-i486-2, contain world-writable permissions on the /tmp di...
CVE-2013-2093CRITICAL9.8Dolibarr ERP/CRM 3.3.1 does not properly validate user input in viewimage.php and barcode.lib.php which allows remote at...
CVE-2013-2092MEDIUM6.1Cross-site Scripting (XSS) in Dolibarr ERP/CRM 3.3.1 allows remote attackers to inject arbitrary web script or HTML in f...
CVE-2013-2091CRITICAL9.8SQL injection vulnerability in Dolibarr ERP/CRM 3.3.1 allows remote attackers to execute arbitrary SQL commands via the ...
CVE-2013-1817HIGH7.5MediaWiki before 1.19.4 and 1.20.x before 1.20.3 contains an error in the api.php script which allows remote attackers t...
CVE-2013-1816HIGH7.5MediaWiki before 1.19.4 and 1.20.x before 1.20.3 allows remote attackers to cause a denial of service (application crash...
CVE-2013-0195MEDIUM6.1Cross-site Scripting (XSS) in Piwik before 1.10.1 allows remote attackers to inject arbitrary web script or HTML via uns...
CVE-2013-0194MEDIUM6.1Cross-site Scripting (XSS) in Piwik before 1.10.1 allows remote attackers to inject arbitrary web script or HTML via uns...
CVE-2013-0193MEDIUM6.1Cross-site Scripting (XSS) in Piwik before 1.10.1 allows remote attackers to inject arbitrary web script or HTML via uns...
CVE-2013-7089HIGH7.5ClamAV before 0.97.7: dbg_printhex possible information leak
CVE-2013-7088CRITICAL9.8ClamAV before 0.97.7 has buffer overflow in the libclamav component
CVE-2013-7087CRITICAL9.8ClamAV before 0.97.7 has WWPack corrupt heap memory
CVE-2013-4584MEDIUM5.9Perdition before 2.2 may have weak security when handling outbound connections, caused by an error in the STARTTLS IMAP ...
CVE-2013-4108CRITICAL9.8Multiple unspecified vulnerabilities in Cryptocat Project Cryptocat 2.0.18 have unknown impact and attack vectors.
CVE-2013-4106MEDIUM6.1A Cross-site scripting (XSS) vulnerability exists in Conversation Overview Nickname in Cryptocat before 2.0.22.
CVE-2013-4109MEDIUM6.1An unspecified cross-site scripting (XSS) vulnerability exists in Cryptocat Message Handling 1.1.165.
CVE-2013-3072CRITICAL9.8An Authentication Bypass vulnerability exists in NETGEAR Centria WNDR4700 Firmware 1.0.0.34 in http://<router_ip>/apply....
CVE-2013-3070HIGH7.5An Information Disclosure vulnerability exists in Netgear WNDR4700 running firmware 1.0.0.34 in the management web inter...
CVE-2013-3073CRITICAL9.8A Symlink Traversal vulnerability exists in NETGEAR Centria WNDR4700 Firmware 1.0.0.34.
CVE-2013-3366HIGH8.8Undocumented TELNET service in TRENDnet TEW-812DRU when a web page named backdoor contains an HTML parameter of password...
CVE-2013-3097MEDIUM6.1Unspecified Cross-site scripting (XSS) vulnerability in the Verizon FIOS Actiontec MI424WR-GEN3I router.
CVE-2013-4275MEDIUM5.4Cross-site scripting (XSS) vulnerability in the zen_breadcrumb function in template.php in the Zen theme 6.x-1.x, 7.x-3....
CVE-2013-3367CRITICAL9.8Undocumented TELNET service in TRENDnet TEW-691GR and TEW-692GR when a web page named backdoor contains an HTML paramete...
CVE-2013-3516MEDIUM6.5NETGEAR WNR3500U and WNR3500L routers uses form tokens abased solely on router's current date and time, which allows att...

Check if your code is affected by 2013 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now