2013 CVE Vulnerabilities
6,830 CVEs published in 2013.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2013-4347 | — | — | 2.4% | May 20, 2014 | The (1) make_nonce, (2) generate_nonce, and (3) generate_verifier functions in SimpleGeo python-oauth2 uses weak random ... |
| CVE-2013-4346 | — | — | 2.4% | May 20, 2014 | The Server.verify_request function in SimpleGeo python-oauth2 does not check the nonce, which allows remote attackers to... |
| CVE-2013-4321 | — | — | 1.1% | May 20, 2014 | The File Abstraction Layer (FAL) in TYPO3 6.0.x before 6.0.8 and 6.1.x before 6.1.4 allows remote authenticated editors ... |
| CVE-2013-4320 | — | — | 1.0% | May 20, 2014 | The File Abstraction Layer (FAL) in TYPO3 6.0.x before 6.0.9 and 6.1.x before 6.1.4 does not properly check permissions,... |
| CVE-2013-4250 | — | — | 1.2% | May 20, 2014 | The (1) file upload component and (2) File Abstraction Layer (FAL) in TYPO3 6.0.x before 6.0.8 and 6.1.x before 6.1.3 do... |
| CVE-2013-6975 | — | — | 0.5% | May 20, 2014 | Directory traversal vulnerability in the command-line interface in Cisco NX-OS 6.2(2a) and earlier allows local users to... |
| CVE-2013-7385 | — | — | 1.3% | May 19, 2014 | LiveZilla 5.1.2.1 and earlier includes the MD5 hash of the operator password in plaintext in Javascript code that is gen... |
| CVE-2013-7384 | — | — | 2.4% | May 19, 2014 | UnrealIRCd 3.2.10 before 3.2.10.2 allows remote attackers to cause a denial of service (NULL pointer dereference and cra... |
| CVE-2013-7040 | — | — | 3.3% | May 19, 2014 | Python 2.7 before 3.4 only uses the last eight bits of the prefix to randomize hash values, which causes it to compute h... |
| CVE-2013-7033 | — | — | 1.2% | May 19, 2014 | LiveZilla before 5.1.2.1 includes the operator password in plaintext in Javascript code that is generated by lz/mobile/c... |
| CVE-2013-6994 | — | — | 1.2% | May 19, 2014 | OpenText Exceed OnDemand (EoD) 8 transmits the session ID in cleartext, which allows remote attackers to perform session... |
| CVE-2013-6807 | — | — | 0.6% | May 19, 2014 | The client in OpenText Exceed OnDemand (EoD) 8 supports anonymous ciphers by default, which allows man-in-the-middle att... |
| CVE-2013-6806 | — | — | 1.0% | May 19, 2014 | OpenText Exceed OnDemand (EoD) 8 allows man-in-the-middle attackers to disable bidirectional authentication and obtain s... |
| CVE-2013-6805 | — | — | 0.7% | May 19, 2014 | OpenText Exceed OnDemand (EoD) 8 uses weak encryption for passwords, which makes it easier for (1) remote attackers to d... |
| CVE-2013-6766 | — | — | 1.6% | May 19, 2014 | OpenVAS Administrator 1.2 before 1.2.2 and 1.3 before 1.3.2 allows remote attackers to bypass the OAP authentication res... |
| CVE-2013-6765 | — | — | 7.3% | May 19, 2014 | OpenVAS Manager 3.0 before 3.0.7 and 4.0 before 4.0.4 allows remote attackers to bypass the OMP authentication restricti... |
| CVE-2013-6764 | — | — | — | May 19, 2014 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-6795. Reason: This candidate is a duplicate of ... |
| CVE-2013-6413 | — | — | 2.4% | May 19, 2014 | Use-after-free vulnerability in UnrealIRCd 3.2.10 before 3.2.10.2 allows remote attackers to cause a denial of service (... |
| CVE-2013-4432 | — | — | 1.1% | May 19, 2014 | Mahara before 1.5.13, 1.6.x before 1.6.8, and 1.7.x before 1.7.4 does not properly restrict access to folders, which all... |
| CVE-2013-4431 | — | — | 1.3% | May 19, 2014 | Mahara before 1.5.12, 1.6.x before 1.6.7, and 1.7.x before 1.7.3 does not properly prevent access to blocks, which allow... |
| CVE-2013-4430 | — | — | 1.2% | May 19, 2014 | Cross-site scripting (XSS) vulnerability in Mahara before 1.5.12, 1.6.x before 1.6.7, and 1.7.x before 1.7.3 allows remo... |
| CVE-2013-4429 | — | — | 1.1% | May 19, 2014 | Mahara before 1.5.12, 1.6.x before 1.6.7, and 1.7.x before 1.7.3 does not properly restrict access to artefacts, which a... |
| CVE-2013-4427 | — | — | 0.3% | May 19, 2014 | pyxtrlock before 0.2 does not properly check the return values of the (1) xcb_grab_pointer and (2) xcb_grab_keyboard XCB... |
| CVE-2013-4426 | — | — | 0.4% | May 19, 2014 | pyxtrlock before 0.1 uses an incorrect variable name, which allows physically proximate attackers to bypass the lock scr... |
| CVE-2013-4406 | — | — | 1.5% | May 19, 2014 | The Quick Tabs module 6.x-2.x before 6.x-2.2, 6.x-3.x before 6.x-3.2, and 7.x-3.x before 7.x-3.6 for Drupal does not pro... |
Check if your code is affected by 2013 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now