2013 CVE Vulnerabilities

6,831 CVEs published in 2013.

CVE IDSeverityCVSSDescription
CVE-2013-3516MEDIUM6.5NETGEAR WNR3500U and WNR3500L routers uses form tokens abased solely on router's current date and time, which allows att...
CVE-2013-3517MEDIUM5.4Cross-site scripting (XSS) vulnerability in NETGEAR WNR3500U and WNR3500L.
CVE-2013-4657CRITICAL9.8Symlink Traversal vulnerability in NETGEAR WNR3500U and WNR3500L due to misconfiguration in the SMB service.
CVE-2013-4655HIGH7.5Symlink Traversal vulnerability in Belkin N900 due to misconfiguration in the SMB service.
CVE-2013-4654CRITICAL9.8Symlink Traversal vulnerability in TP-LINK TL-WDR4300 and TL-1043ND..
CVE-2013-4656CRITICAL9.8Symlink Traversal vulnerability in ASUS RT-AC66U and RT-N56U due to misconfiguration in the SMB service.
CVE-2013-1889HIGH7.5mod_ruid2 before 0.9.8 improperly handles file descriptors which allows remote attackers to bypass security using a CGI ...
CVE-2013-1820MEDIUM5.5tuned before 2.x allows local users to kill running processes due to insecure permissions with tuned's ktune service.
CVE-2013-1811MEDIUM4.3An access control issue in MantisBT before 1.2.13 allows users with "Reporter" permissions to change any issue to "New".
CVE-2013-1809HIGH7.5Gambas before 3.4.0 allows remote attackers to move or manipulate directory contents or perform symlink attacks due to t...
CVE-2013-1771HIGH7.5The web server Monkeyd produces a world-readable log (/var/log/monkeyd/master.log) on gentoo.
CVE-2013-1751CRITICAL9.8TWiki before 5.1.4 allows remote attackers to execute arbitrary shell commands by sending a crafted '%MAKETEXT{}%' param...
CVE-2013-1429MEDIUM6.3Lintian before 2.5.12 allows remote attackers to gather information about the "host" system using crafted symlinks.
CVE-2013-1426MEDIUM6.1Cross-site Scripting (XSS) in Mahara before 1.5.9 and 1.6.x before 1.6.4 allows remote attackers to inject arbitrary web...
CVE-2013-1425MEDIUM5.5ldap-git-backup before 1.0.4 exposes password hashes due to incorrect directory permissions.
CVE-2013-5123MEDIUM5.9The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks wh...
CVE-2013-6275MEDIUM6.5Multiple CSRF issues in Horde Groupware Webmail Edition 5.1.2 and earlier in basic.php.
CVE-2013-5661MEDIUM5.9Cache Poisoning issue exists in DNS Response Rate Limiting.
CVE-2013-6461MEDIUM6.5Nokogiri gem 1.5.x and 1.6.x has DoS while parsing XML entities by failing to apply limits
CVE-2013-6460MEDIUM6.5Nokogiri gem 1.5.x has Denial of Service via infinite loop when parsing XML documents
CVE-2013-6365MEDIUM5.3Horde Groupware Web mail 5.1.2 has CSRF with requests to change permissions
CVE-2013-6364HIGH8.8Horde Groupware Webmail Edition has CSRF and XSS when saving search as a virtual address book
CVE-2013-4110MEDIUM5.3Cryptocat has an Unspecified Chat Participant User List Disclosure
CVE-2013-4107MEDIUM6.1Cryptocat before 2.0.22: cryptocat.js handlePresence() has cross site scripting
CVE-2013-4374HIGH7.1An insecurity temporary file vulnerability exists in RHQ Mongo DB Drift Server through 2013-09-25 when unpacking zipped ...

Check if your code is affected by 2013 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now