2013 CVE Vulnerabilities

6,830 CVEs published in 2013.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2013-0262rack/file.rb (Rack::File) in Rack 1.5.x before 1.5.2 and 1.4.x before 1.4.5 allows attackers to access arbitrary files o...
CVE-2013-0242Buffer overflow in the extend_buffers function in the regular expression matcher (posix/regexec.c) in glibc, possibly 2....
CVE-2013-0189cachemgr.cgi in Squid 3.1.x and 3.2.x, possibly 3.1.22, 3.2.4, and other versions, allows remote attackers to cause a de...
CVE-2013-0170Use-after-free vulnerability in the virNetMessageFree function in rpc/virnetserverclient.c in libvirt 1.0.x before 1.0.2...
CVE-2013-1624The TLS implementation in the Bouncy Castle Java library before 1.48 and C# library before 1.8 does not properly conside...
CVE-2013-1623The TLS and DTLS implementations in wolfSSL CyaSSL before 2.5.0 do not properly consider timing side-channel attacks on ...
CVE-2013-1622Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is not a security issue. ...
CVE-2013-1621Array index error in the SSL module in PolarSSL before 1.2.5 might allow remote attackers to cause a denial of service v...
CVE-2013-1620The TLS implementation in Mozilla Network Security Services (NSS) does not properly consider timing side-channel attacks...
CVE-2013-1619The TLS implementation in GnuTLS before 2.12.23, 3.0.x before 3.0.28, and 3.1.x before 3.1.7 does not properly consider ...
CVE-2013-1618The TLS implementation in Opera before 12.13 does not properly consider timing side-channel attacks on a MAC check opera...
CVE-2013-0169The TLS protocol 1.1 and 1.2 and the DTLS protocol 1.0 and 1.2, as used in OpenSSL, OpenJDK, PolarSSL, and other product...
CVE-2013-0166OpenSSL before 0.9.8y, 1.0.0 before 1.0.0k, and 1.0.1 before 1.0.1d does not properly perform signature verification for...
CVE-2013-1639Opera before 12.13 does not send CORS preflight requests in all required cases, which allows remote attackers to bypass ...
CVE-2013-1638Opera before 12.13 allows remote attackers to execute arbitrary code via crafted clipPaths in an SVG document.
CVE-2013-1637Opera before 12.13 allows remote attackers to execute arbitrary code via vectors involving DOM events.
CVE-2013-0634Adobe Flash Player before 10.3.183.51 and 11.x before 11.5.502.149 on Windows and Mac OS X, before 10.3.183.51 and 11.x ...
CVE-2013-0633Buffer overflow in Adobe Flash Player before 10.3.183.51 and 11.x before 11.5.502.149 on Windows and Mac OS X, before 10...
CVE-2013-1464Cross-site scripting (XSS) vulnerability in assets/player.swf in the Audio Player plugin before 2.0.4.6 for Wordpress al...
CVE-2013-1463Cross-site scripting (XSS) vulnerability in js/tabletools/zeroclipboard.swf in the WP-Table Reloaded module before 1.9.4...
CVE-2013-1120Multiple cross-site request forgery (CSRF) vulnerabilities on the Cisco Unity Express with software before 8.0 allow rem...
CVE-2013-1107The search function in Cisco Webex Social (formerly Cisco Quad) allows remote authenticated users to read files via unsp...
CVE-2013-0254The QSharedMemory class in Qt 5.0.0, 4.8.x before 4.8.5, 4.7.x before 4.7.6, and other versions including 4.4.0 uses wea...
CVE-2013-0218The GUI installer in JBoss Enterprise Application Platform (EAP) and Enterprise Web Platform (EWP) 5.2.0 and possibly 5....
CVE-2013-0176The publickey_from_privatekey function in libssh before 0.5.4, when no algorithm is matched during negotiations, allows ...

Check if your code is affected by 2013 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now