2013 CVE Vulnerabilities

6,830 CVEs published in 2013.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2013-6372The Subversion plugin before 1.54 for Jenkins stores credentials using base64 encoding, which allows local users to obta...
CVE-2013-4544hw/net/vmxnet3.c in QEMU 2.0.0-rc0, 1.7.1, and earlier allows local guest users to cause a denial of service or possibly...
CVE-2013-3571socat 1.2.0.0 before 1.7.2.2 and 2.0.0-b1 before 2.0.0-b6, when used for a listen type address and the fork option is en...
CVE-2013-0345varnish 3.0.3 uses world-readable permissions for the /var/log/varnish/ directory and the log files in the directory, wh...
CVE-2013-0210The smart proxy Puppet run API in Foreman before 1.2.0 allows remote attackers to execute arbitrary commands via vectors...
CVE-2013-0187Foreman before 1.1 allows remote authenticated users to gain privileges via a (1) XMLHttpRequest or (2) AJAX request.
CVE-2013-0174The external node classifier (ENC) API in Foreman before 1.1 allows remote attackers to obtain the hashed root password ...
CVE-2013-0173Foreman before 1.1 uses a salt of "foreman" to hash root passwords, which makes it easier for attackers to guess the pas...
CVE-2013-0171Foreman before 1.1 allows remote attackers to execute arbitrary code via a crafted YAML object to the (1) fact or (2) re...
CVE-2013-5016Symantec Critical System Protection (SCSP) before 5.2.9, when installed on an unpatched Windows Server 2003 R2 platform,...
CVE-2013-7336The qemuMigrationWaitForSpice function in qemu/qemu_migration.c in libvirt before 1.1.3 does not properly enter a monito...
CVE-2013-6726Multiple cross-site scripting (XSS) vulnerabilities in WebProcess.srv in IBM TRIRIGA Application Platform 3.2.x and 3.3....
CVE-2013-7375SQL injection vulnerability in includes/classes/Authenticate.class.php in PHP-Fusion 7.02.01 through 7.02.05 allows remo...
CVE-2013-7034The setCookieValue function in _lib/functions.global.inc.php in LiveZilla before 5.1.2.1 allows remote attackers to exec...
CVE-2013-7003Multiple cross-site scripting (XSS) vulnerabilities in LiveZilla before 5.1.2.0 allow remote attackers to inject arbitra...
CVE-2013-6444PyWBEM 0.7 and earlier does not verify that the server hostname matches a domain name in the subject's Common Name (CN) ...
CVE-2013-6418PyWBEM 0.7 and earlier uses a separate connection to validate X.509 certificates, which allows man-in-the-middle attacke...
CVE-2013-4215The IPXPING_COMMAND in contrib/check_ipxping.c in Nagios Plugins 1.4.16 allows local users to gain privileges via a syml...
CVE-2013-3736Cross-site scripting (XSS) vulnerability in the MobileUI (aka RT-Extension-MobileUI) extension before 1.04 in Request Tr...
CVE-2013-1803Multiple SQL injection vulnerabilities in PHP-Fusion before 7.02.06 allow remote attackers to execute arbitrary SQL comm...
CVE-2013-0350tmp_smtp.c in pktstat 1.8.5 allows local users to overwrite arbitrary files via a symlink attack on /tmp/smtp.log.
CVE-2013-7061Products/CMFPlone/CatalogTool.py in Plone 3.3 through 4.3.2 allows remote administrators to bypass restrictions and obta...
CVE-2013-7060Products/CMFPlone/FactoryTool.py in Plone 3.3 through 4.3.2 allows remote attackers to obtain the installation path via ...
CVE-2013-7110Transifex command-line client before 0.10 does not validate X.509 certificates for data transfer connections, which allo...
CVE-2013-2073Transifex command-line client before 0.9 does not validate X.509 certificates, which allows man-in-the-middle attackers ...

Check if your code is affected by 2013 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now