2013 CVE Vulnerabilities

6,831 CVEs published in 2013.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2013-6889——GNU Rush 1.7 does not properly drop privileges, which allows local users to read arbitrary files via the --lint option.
CVE-2013-6372——The Subversion plugin before 1.54 for Jenkins stores credentials using base64 encoding, which allows local users to obta...
CVE-2013-4544——hw/net/vmxnet3.c in QEMU 2.0.0-rc0, 1.7.1, and earlier allows local guest users to cause a denial of service or possibly...
CVE-2013-3571——socat 1.2.0.0 before 1.7.2.2 and 2.0.0-b1 before 2.0.0-b6, when used for a listen type address and the fork option is en...
CVE-2013-0345——varnish 3.0.3 uses world-readable permissions for the /var/log/varnish/ directory and the log files in the directory, wh...
CVE-2013-0210——The smart proxy Puppet run API in Foreman before 1.2.0 allows remote attackers to execute arbitrary commands via vectors...
CVE-2013-0187——Foreman before 1.1 allows remote authenticated users to gain privileges via a (1) XMLHttpRequest or (2) AJAX request.
CVE-2013-0174——The external node classifier (ENC) API in Foreman before 1.1 allows remote attackers to obtain the hashed root password ...
CVE-2013-0173——Foreman before 1.1 uses a salt of "foreman" to hash root passwords, which makes it easier for attackers to guess the pas...
CVE-2013-0171——Foreman before 1.1 allows remote attackers to execute arbitrary code via a crafted YAML object to the (1) fact or (2) re...
CVE-2013-5016——Symantec Critical System Protection (SCSP) before 5.2.9, when installed on an unpatched Windows Server 2003 R2 platform,...
CVE-2013-7336——The qemuMigrationWaitForSpice function in qemu/qemu_migration.c in libvirt before 1.1.3 does not properly enter a monito...
CVE-2013-6726——Multiple cross-site scripting (XSS) vulnerabilities in WebProcess.srv in IBM TRIRIGA Application Platform 3.2.x and 3.3....
CVE-2013-7375——SQL injection vulnerability in includes/classes/Authenticate.class.php in PHP-Fusion 7.02.01 through 7.02.05 allows remo...
CVE-2013-7034——The setCookieValue function in _lib/functions.global.inc.php in LiveZilla before 5.1.2.1 allows remote attackers to exec...
CVE-2013-7003——Multiple cross-site scripting (XSS) vulnerabilities in LiveZilla before 5.1.2.0 allow remote attackers to inject arbitra...
CVE-2013-6444——PyWBEM 0.7 and earlier does not verify that the server hostname matches a domain name in the subject's Common Name (CN) ...
CVE-2013-6418——PyWBEM 0.7 and earlier uses a separate connection to validate X.509 certificates, which allows man-in-the-middle attacke...
CVE-2013-4215——The IPXPING_COMMAND in contrib/check_ipxping.c in Nagios Plugins 1.4.16 allows local users to gain privileges via a syml...
CVE-2013-3736——Cross-site scripting (XSS) vulnerability in the MobileUI (aka RT-Extension-MobileUI) extension before 1.04 in Request Tr...
CVE-2013-1803——Multiple SQL injection vulnerabilities in PHP-Fusion before 7.02.06 allow remote attackers to execute arbitrary SQL comm...
CVE-2013-0350——tmp_smtp.c in pktstat 1.8.5 allows local users to overwrite arbitrary files via a symlink attack on /tmp/smtp.log.
CVE-2013-7061——Products/CMFPlone/CatalogTool.py in Plone 3.3 through 4.3.2 allows remote administrators to bypass restrictions and obta...
CVE-2013-7060——Products/CMFPlone/FactoryTool.py in Plone 3.3 through 4.3.2 allows remote attackers to obtain the installation path via ...
CVE-2013-7110——Transifex command-line client before 0.10 does not validate X.509 certificates for data transfer connections, which allo...

Check if your code is affected by 2013 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now