2013 CVE Vulnerabilities
6,830 CVEs published in 2013.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2013-0262 | — | — | 3.0% | Feb 8, 2013 | rack/file.rb (Rack::File) in Rack 1.5.x before 1.5.2 and 1.4.x before 1.4.5 allows attackers to access arbitrary files o... |
| CVE-2013-0242 | — | — | 2.9% | Feb 8, 2013 | Buffer overflow in the extend_buffers function in the regular expression matcher (posix/regexec.c) in glibc, possibly 2.... |
| CVE-2013-0189 | — | — | 23.0% | Feb 8, 2013 | cachemgr.cgi in Squid 3.1.x and 3.2.x, possibly 3.1.22, 3.2.4, and other versions, allows remote attackers to cause a de... |
| CVE-2013-0170 | — | — | 5.8% | Feb 8, 2013 | Use-after-free vulnerability in the virNetMessageFree function in rpc/virnetserverclient.c in libvirt 1.0.x before 1.0.2... |
| CVE-2013-1624 | — | — | 3.0% | Feb 8, 2013 | The TLS implementation in the Bouncy Castle Java library before 1.48 and C# library before 1.8 does not properly conside... |
| CVE-2013-1623 | — | — | 2.4% | Feb 8, 2013 | The TLS and DTLS implementations in wolfSSL CyaSSL before 2.5.0 do not properly consider timing side-channel attacks on ... |
| CVE-2013-1622 | — | — | — | Feb 8, 2013 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is not a security issue. ... |
| CVE-2013-1621 | — | — | 2.1% | Feb 8, 2013 | Array index error in the SSL module in PolarSSL before 1.2.5 might allow remote attackers to cause a denial of service v... |
| CVE-2013-1620 | — | — | 3.7% | Feb 8, 2013 | The TLS implementation in Mozilla Network Security Services (NSS) does not properly consider timing side-channel attacks... |
| CVE-2013-1619 | — | — | 6.4% | Feb 8, 2013 | The TLS implementation in GnuTLS before 2.12.23, 3.0.x before 3.0.28, and 3.1.x before 3.1.7 does not properly consider ... |
| CVE-2013-1618 | — | — | 2.2% | Feb 8, 2013 | The TLS implementation in Opera before 12.13 does not properly consider timing side-channel attacks on a MAC check opera... |
| CVE-2013-0169 | — | — | 35.6% | Feb 8, 2013 | The TLS protocol 1.1 and 1.2 and the DTLS protocol 1.0 and 1.2, as used in OpenSSL, OpenJDK, PolarSSL, and other product... |
| CVE-2013-0166 | — | — | 19.7% | Feb 8, 2013 | OpenSSL before 0.9.8y, 1.0.0 before 1.0.0k, and 1.0.1 before 1.0.1d does not properly perform signature verification for... |
| CVE-2013-1639 | — | — | 0.5% | Feb 8, 2013 | Opera before 12.13 does not send CORS preflight requests in all required cases, which allows remote attackers to bypass ... |
| CVE-2013-1638 | — | — | 8.0% | Feb 8, 2013 | Opera before 12.13 allows remote attackers to execute arbitrary code via crafted clipPaths in an SVG document. |
| CVE-2013-1637 | — | — | 4.6% | Feb 8, 2013 | Opera before 12.13 allows remote attackers to execute arbitrary code via vectors involving DOM events. |
| CVE-2013-0634 | — | — | 77.6% | Feb 8, 2013 | Adobe Flash Player before 10.3.183.51 and 11.x before 11.5.502.149 on Windows and Mac OS X, before 10.3.183.51 and 11.x ... |
| CVE-2013-0633 | — | — | 20.9% | Feb 8, 2013 | Buffer overflow in Adobe Flash Player before 10.3.183.51 and 11.x before 11.5.502.149 on Windows and Mac OS X, before 10... |
| CVE-2013-1464 | — | — | 6.4% | Feb 7, 2013 | Cross-site scripting (XSS) vulnerability in assets/player.swf in the Audio Player plugin before 2.0.4.6 for Wordpress al... |
| CVE-2013-1463 | — | — | 6.3% | Feb 7, 2013 | Cross-site scripting (XSS) vulnerability in js/tabletools/zeroclipboard.swf in the WP-Table Reloaded module before 1.9.4... |
| CVE-2013-1120 | — | — | 1.2% | Feb 6, 2013 | Multiple cross-site request forgery (CSRF) vulnerabilities on the Cisco Unity Express with software before 8.0 allow rem... |
| CVE-2013-1107 | — | — | 0.9% | Feb 6, 2013 | The search function in Cisco Webex Social (formerly Cisco Quad) allows remote authenticated users to read files via unsp... |
| CVE-2013-0254 | — | — | 0.4% | Feb 6, 2013 | The QSharedMemory class in Qt 5.0.0, 4.8.x before 4.8.5, 4.7.x before 4.7.6, and other versions including 4.4.0 uses wea... |
| CVE-2013-0218 | — | — | 0.4% | Feb 5, 2013 | The GUI installer in JBoss Enterprise Application Platform (EAP) and Enterprise Web Platform (EWP) 5.2.0 and possibly 5.... |
| CVE-2013-0176 | — | — | 3.0% | Feb 5, 2013 | The publickey_from_privatekey function in libssh before 0.5.4, when no algorithm is matched during negotiations, allows ... |
Check if your code is affected by 2013 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now