2013 CVE Vulnerabilities
6,830 CVEs published in 2013.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2013-1304 | — | — | 20.0% | Apr 9, 2013 | Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary co... |
| CVE-2013-1303 | — | — | 20.5% | Apr 9, 2013 | Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary co... |
| CVE-2013-1296 | — | — | 20.7% | Apr 9, 2013 | The Remote Desktop ActiveX control in mstscax.dll in Microsoft Remote Desktop Connection Client 6.1 and 7.0 does not pro... |
| CVE-2013-1295 | — | — | 2.2% | Apr 9, 2013 | The Client/Server Run-time Subsystem (CSRSS) in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP2, and Server... |
| CVE-2013-1294 | HIGH | 7 | 1.1% | Apr 9, 2013 | Race condition in the kernel in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Se... |
| CVE-2013-1293 | — | — | 1.6% | Apr 9, 2013 | The NTFS kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold ... |
| CVE-2013-1292 | HIGH | 7.4 | 0.9% | Apr 9, 2013 | Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and... |
| CVE-2013-1291 | — | — | 4.6% | Apr 9, 2013 | win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows S... |
| CVE-2013-1290 | — | — | 17.0% | Apr 9, 2013 | Microsoft SharePoint Server 2013, in certain configurations involving legacy My Sites, does not properly establish defau... |
| CVE-2013-1289 | — | — | 15.4% | Apr 9, 2013 | Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2010 SP1, Groove Server 2010 SP1, SharePoint Fou... |
| CVE-2013-1284 | — | — | 1.5% | Apr 9, 2013 | Race condition in the kernel in Microsoft Windows 8, Windows Server 2012, and Windows RT allows local users to gain priv... |
| CVE-2013-1283 | — | — | 1.2% | Apr 9, 2013 | Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Wi... |
| CVE-2013-1282 | — | — | 27.0% | Apr 9, 2013 | The LDAP service in Microsoft Active Directory, Active Directory Application Mode (ADAM), Active Directory Lightweight D... |
| CVE-2013-0078 | — | — | 1.8% | Apr 9, 2013 | The Microsoft Antimalware Client in Windows Defender on Windows 8 and Windows RT uses an incorrect pathname for MsMpEng.... |
| CVE-2013-1821 | — | — | 6.6% | Apr 9, 2013 | lib/rexml/text.rb in the REXML parser in Ruby before 1.9.3-p392 allows remote attackers to cause a denial of service (me... |
| CVE-2013-1898 | — | — | 2.1% | Apr 9, 2013 | lib/thumbshooter.rb in the Thumbshooter 0.1.5 gem for Ruby allows remote attackers to execute arbitrary commands via she... |
| CVE-2013-1802 | — | — | 3.4% | Apr 9, 2013 | The extlib gem 0.9.15 and earlier for Ruby does not properly restrict casts of string values, which might allow remote a... |
| CVE-2013-1801 | — | — | 4.4% | Apr 9, 2013 | The httparty gem 0.9.0 and earlier for Ruby does not properly restrict casts of string values, which might allow remote ... |
| CVE-2013-1800 | — | — | 5.0% | Apr 9, 2013 | The crack gem 0.3.1 and earlier for Ruby does not properly restrict casts of string values, which might allow remote att... |
| CVE-2013-1790 | — | — | 2.6% | Apr 9, 2013 | poppler/Stream.cc in poppler before 0.22.1 allows context-dependent attackers to have an unspecified impact via vectors ... |
| CVE-2013-1789 | — | — | 2.4% | Apr 9, 2013 | splash/Splash.cc in poppler before 0.22.1 allows context-dependent attackers to cause a denial of service (NULL pointer ... |
| CVE-2013-1788 | — | — | 3.9% | Apr 9, 2013 | poppler before 0.22.1 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbit... |
| CVE-2013-0285 | — | — | 2.3% | Apr 9, 2013 | The nori gem 2.0.x before 2.0.2, 1.1.x before 1.1.4, and 1.0.x before 1.0.3 for Ruby does not properly restrict casts of... |
| CVE-2013-0284 | — | — | 1.3% | Apr 9, 2013 | Ruby agent 3.2.0 through 3.5.2 serializes sensitive data when communicating with servers operated by New Relic, which al... |
| CVE-2013-0253 | — | — | 1.6% | Apr 9, 2013 | The default configuration of Apache Maven 3.0.4, when using Maven Wagon 2.1, disables SSL certificate checks, which allo... |
Check if your code is affected by 2013 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now