2013 CVE Vulnerabilities

6,830 CVEs published in 2013.

CVE IDSeverityCVSSDescription
CVE-2013-4251HIGH7.8The scipy.weave component in SciPy before 0.12.1 creates insecure temporary directories.
CVE-2013-4280MEDIUM5.5Insecure temporary file vulnerability in RedHat vsdm 4.9.6.
CVE-2013-4105HIGH7.5Cryptocat before 2.0.22 has Multiparty Encryption Scheme Information Disclosure
CVE-2013-2260CRITICAL9.8Cryptocat before 2.0.22: Cryptocat.random() Function Array Key has Entropy Weakness
CVE-2013-2259CRITICAL9.8Cryptocat before 2.0.22 has Arbitrary Code Execution on Firefox Conversation Overview
CVE-2013-2258MEDIUM5.3Cryptocat before 2.0.22 has Nickname User Impersonation
CVE-2013-2257HIGH7.5Cryptocat before 2.0.42 has Group Chat ECC Private Key Generation Brute Force Weakness
CVE-2013-4104HIGH7.5Cryptocat before 2.0.22 has weak encryption in the Socialist Millionnaire Protocol
CVE-2013-2262HIGH7.5Cryptocat strophe.js before 2.0.22 has information disclosure
CVE-2013-2261HIGH7.5Cryptocat before 2.0.22 Chrome Extension 'img/keygen.gif' has Information Disclosure
CVE-2013-4103CRITICAL9.8Cryptocat before 2.0.22 has Remote Script Injection due to improperly sanitizing user input
CVE-2013-4102CRITICAL9.1Cryptocat before 2.0.22 strophe.js Math.random() Random Number Generator Weakness
CVE-2013-4101MEDIUM5.3Cryptocat before 2.0.22 Link Markup Decorator HTML Handling Weakness
CVE-2013-4100HIGH7.5Cryptocat before 2.0.22 has Remote Denial of Service via username
CVE-2013-4518MEDIUM5.5RHUI (Red Hat Update Infrastructure) 2.1.3 has world readable PKI entitlement certificates
CVE-2013-4423MEDIUM5.5CloudForms stores user passwords in recoverable format
CVE-2013-4412HIGH7.5slim has NULL pointer dereference when using crypt() method from glibc 2.17
CVE-2013-4168MEDIUM6.1Cross-site scripting (XSS) vulnerability in SmokePing 2.6.9 in the start and end time fields.
CVE-2013-2255MEDIUM5.9HTTPSConnections in OpenStack Keystone 2013, OpenStack Compute 2013.1, and possibly other OpenStack components, fail to ...
CVE-2013-0186MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in ManageIQ EVM allows remote attackers to inject arbitrary web scri...
CVE-2013-0180MEDIUM5.5Insecure temporary file vulnerability in Redis 2.6 related to /tmp/redis.ds.
CVE-2013-0178MEDIUM5.5Insecure temporary file vulnerability in Redis before 2.6 related to /tmp/redis-%p.vm.
CVE-2013-0165HIGH7.3cartridges/openshift-origin-cartridge-mongodb-2.2/info/bin/dump.sh in OpenShift does not properly create files in /tmp.
CVE-2013-4367HIGH7.8ovirt-engine 3.2 running on Linux kernel 3.1 and newer creates certain files world-writeable due to an upstream kernel c...
CVE-2013-2227HIGH7.5GLPI 0.83.7 has Local File Inclusion in common.tabs.php.

Check if your code is affected by 2013 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now