2013 CVE Vulnerabilities

6,831 CVEs published in 2013.

CVE IDSeverityCVSSDescription
CVE-2013-4409CRITICAL9.8An eval() vulnerability exists in Python Software Foundation Djblets 0.7.21 and Beanbag Review Board before 1.7.15 when ...
CVE-2013-4251HIGH7.8The scipy.weave component in SciPy before 0.12.1 creates insecure temporary directories.
CVE-2013-4280MEDIUM5.5Insecure temporary file vulnerability in RedHat vsdm 4.9.6.
CVE-2013-4105HIGH7.5Cryptocat before 2.0.22 has Multiparty Encryption Scheme Information Disclosure
CVE-2013-2260CRITICAL9.8Cryptocat before 2.0.22: Cryptocat.random() Function Array Key has Entropy Weakness
CVE-2013-2259CRITICAL9.8Cryptocat before 2.0.22 has Arbitrary Code Execution on Firefox Conversation Overview
CVE-2013-2258MEDIUM5.3Cryptocat before 2.0.22 has Nickname User Impersonation
CVE-2013-2257HIGH7.5Cryptocat before 2.0.42 has Group Chat ECC Private Key Generation Brute Force Weakness
CVE-2013-4104HIGH7.5Cryptocat before 2.0.22 has weak encryption in the Socialist Millionnaire Protocol
CVE-2013-2262HIGH7.5Cryptocat strophe.js before 2.0.22 has information disclosure
CVE-2013-2261HIGH7.5Cryptocat before 2.0.22 Chrome Extension 'img/keygen.gif' has Information Disclosure
CVE-2013-4103CRITICAL9.8Cryptocat before 2.0.22 has Remote Script Injection due to improperly sanitizing user input
CVE-2013-4102CRITICAL9.1Cryptocat before 2.0.22 strophe.js Math.random() Random Number Generator Weakness
CVE-2013-4101MEDIUM5.3Cryptocat before 2.0.22 Link Markup Decorator HTML Handling Weakness
CVE-2013-4100HIGH7.5Cryptocat before 2.0.22 has Remote Denial of Service via username
CVE-2013-4518MEDIUM5.5RHUI (Red Hat Update Infrastructure) 2.1.3 has world readable PKI entitlement certificates
CVE-2013-4423MEDIUM5.5CloudForms stores user passwords in recoverable format
CVE-2013-4412HIGH7.5slim has NULL pointer dereference when using crypt() method from glibc 2.17
CVE-2013-4168MEDIUM6.1Cross-site scripting (XSS) vulnerability in SmokePing 2.6.9 in the start and end time fields.
CVE-2013-2255MEDIUM5.9HTTPSConnections in OpenStack Keystone 2013, OpenStack Compute 2013.1, and possibly other OpenStack components, fail to ...
CVE-2013-0186MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in ManageIQ EVM allows remote attackers to inject arbitrary web scri...
CVE-2013-0180MEDIUM5.5Insecure temporary file vulnerability in Redis 2.6 related to /tmp/redis.ds.
CVE-2013-0178MEDIUM5.5Insecure temporary file vulnerability in Redis before 2.6 related to /tmp/redis-%p.vm.
CVE-2013-0165HIGH7.3cartridges/openshift-origin-cartridge-mongodb-2.2/info/bin/dump.sh in OpenShift does not properly create files in /tmp.
CVE-2013-4367HIGH7.8ovirt-engine 3.2 running on Linux kernel 3.1 and newer creates certain files world-writeable due to an upstream kernel c...

Check if your code is affected by 2013 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now