2013 CVE Vulnerabilities

6,831 CVEs published in 2013.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2013-5352——Sharetronix 3.1.1.3, 3.1.1, and earlier allows remote attackers to execute arbitrary PHP code via the (1) activities_tex...
CVE-2013-4099——Multiple unspecified vulnerabilities in OpenAL32.dll in JOAL 2.0-rc11, as used in JOGAMP, allow context-dependent attack...
CVE-2013-3843——Stack-based buffer overflow in the mk_request_header_process function in mk_request.c in Monkey HTTP Daemon (monkeyd) be...
CVE-2013-3663——Heap-based buffer overflow in paintlib, as used in Trimble SketchUp (formerly Google SketchUp) before 8 Maintenance 3, a...
CVE-2013-2182——The Mandril security plugin in Monkey HTTP Daemon (monkeyd) before 1.5.0 allows remote attackers to bypass access restri...
CVE-2013-2163——Monkey HTTP Daemon (monkeyd) before 1.2.2 allows remote attackers to cause a denial of service (infinite loop) via an of...
CVE-2013-1841——Net-Server, when the reverse-lookups option is enabled, does not check if the hostname resolves to the source IP address...
CVE-2013-6825——(1) movescu.cc and (2) storescp.cc in dcmnet/apps/, (3) dcmnet/libsrc/scp.cc, (4) dcmwlm/libsrc/wlmactmg.cc, (5) dcmprsc...
CVE-2013-5643——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ...
CVE-2013-7323——python-gnupg before 0.3.5 allows context-dependent attackers to execute arbitrary commands via shell metacharacters in u...
CVE-2013-6223——LiveZilla before 5.1.1.0 stores the admin Base64 encoded username and password in a 1click file, which allows local user...
CVE-2013-5760——QNAP Photo Station before firmware 4.0.3 build0912 allows remote attackers to list OS user accounts via a request to pho...
CVE-2013-4599——The Misery module 6.x-2.x before 6.x-2.5 and 7.x-2.x before 7.x-2.2 for Drupal, when the "delay misery" configuration is...
CVE-2013-4597——The Revisioning module 7.x-1.x before 7.x-1.6 for Drupal does not properly check node access permissions for content mar...
CVE-2013-4595——The Secure Pages module 6.x-2.x before 6.x-2.0 for Drupal does not properly match URLs, which causes HTTP to be used ins...
CVE-2013-3082——Cross-site scripting (XSS) vulnerability in plugins/jojo_core/forgot_password.php in Jojo before 1.2.2 allows remote att...
CVE-2013-3081——SQL injection vulnerability in the checkEmailFormat function in plugins/jojo_core/classes/Jojo.php in Jojo before 1.2.2 ...
CVE-2013-2564——Mambo CMS 4.6.5 allows remote attackers to cause a denial of service (memory and bandwidth consumption) by uploading a c...
CVE-2013-2563——Mambo CMS 4.6.5 uses world-readable permissions on configuration.php, which allows local users to obtain the admin passw...
CVE-2013-2562——Mambo CMS 4.6.5 stores the MySQL database password in cleartext in the document root, which allows local users to obtain...
CVE-2013-1973——The autocomplete callback in Autocomplete Widgets for Text and Number Fields (autocomplete_widgets) module 6.x-1.x befor...
CVE-2013-1756——The Dragonfly gem 0.7 before 0.8.6 and 0.9.x before 0.9.13 for Ruby, when used with Ruby on Rails, allows remote attacke...
CVE-2013-4728——DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, allows remote at...
CVE-2013-4727——DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, allows remote at...
CVE-2013-4725——DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, does not set the...

Check if your code is affected by 2013 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now