2013 CVE Vulnerabilities
6,830 CVEs published in 2013.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2013-7064 | — | — | 0.9% | Apr 29, 2014 | Cross-site scripting (XSS) vulnerability in the EU Cookie Compliance module 7.x-1.x before 7.x-1.12 for Drupal allows re... |
| CVE-2013-7063 | — | — | 1.4% | Apr 29, 2014 | The Invitation module 7.x-2.x for Drupal does not properly check permissions, which allows remote attackers to obtain se... |
| CVE-2013-4285 | — | — | 0.3% | Apr 28, 2014 | A certain Gentoo patch for the PAM S/Key module does not properly clear credentials from memory, which allows local user... |
| CVE-2013-6053 | — | — | 2.2% | Apr 27, 2014 | OpenJPEG 1.5.1 allows remote attackers to obtain sensitive information via unspecified vectors that trigger a heap-based... |
| CVE-2013-4336 | — | — | — | Apr 27, 2014 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-5964. Reason: This candidate is a duplicate of C... |
| CVE-2013-0296 | — | — | 0.3% | Apr 27, 2014 | Race condition in pigz before 2.2.5 uses permissions derived from the umask when compressing a file before setting that ... |
| CVE-2013-6887 | — | — | 2.2% | Apr 27, 2014 | OpenJPEG 1.5.1 allows remote attackers to cause a denial of service via unspecified vectors that trigger NULL pointer de... |
| CVE-2013-4337 | — | — | — | Apr 27, 2014 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-5965. Reason: This candidate is a duplicate of... |
| CVE-2013-4145 | — | — | — | Apr 27, 2014 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-3414. Reason: This candidate is a duplicate of... |
| CVE-2013-5660 | — | — | 11.2% | Apr 25, 2014 | Buffer overflow in Power Software WinArchiver 3.2 allows remote attackers to execute arbitrary code via a crafted .zip f... |
| CVE-2013-4726 | — | — | 1.1% | Apr 25, 2014 | Cross-site request forgery (CSRF) vulnerability in DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1... |
| CVE-2013-4723 | — | — | 2.0% | Apr 25, 2014 | Open redirect vulnerability in DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly o... |
| CVE-2013-4722 | — | — | 1.9% | Apr 25, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in Admin/login/default.asp in DDSN Interactive cm3 Acora CMS 6.0.6/1... |
| CVE-2013-4565 | — | — | 3.5% | Apr 25, 2014 | Heap-based buffer overflow in the __OLEdecode function in ppthtml 0.5.1 and earlier allows remote attackers to cause a d... |
| CVE-2013-3069 | — | — | 1.1% | Apr 25, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in NETGEAR WNDR4700 with firmware 1.0.0.34 allow remote authenticate... |
| CVE-2013-2025 | — | — | 1.9% | Apr 25, 2014 | Cross-site scripting (XSS) vulnerability in Ushahidi Platform 2.5.x through 2.6.1 allows remote attackers to inject arbi... |
| CVE-2013-5956 | — | — | 1.9% | Apr 25, 2014 | Cross-site scripting (XSS) vulnerability in includes/flvthumbnail.php in the Youtube Gallery (com_youtubegallery) compon... |
| CVE-2013-5954 | — | — | 3.1% | Apr 25, 2014 | Multiple cross-site request forgery (CSRF) vulnerabilities in OpenX 2.8.11 and earlier allow remote attackers to hijack ... |
| CVE-2013-6738 | — | — | 2.1% | Apr 24, 2014 | Cross-site scripting (XSS) vulnerability in IBM SmartCloud Analytics Log Analysis 1.1 and 1.2 before 1.2.0.0-CSI-SCALA-I... |
| CVE-2013-7338 | — | — | 5.1% | Apr 22, 2014 | Python before 3.3.4 RC1 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a f... |
| CVE-2013-4472 | — | — | 0.4% | Apr 22, 2014 | The openTempFile function in goo/gfile.cc in Xpdf and Poppler 0.24.3 and earlier, when running on a system other than Un... |
| CVE-2013-4116 | — | — | 0.4% | Apr 22, 2014 | lib/npm.js in Node Packaged Modules (npm) before 1.3.3 allows local users to overwrite arbitrary files via a symlink att... |
| CVE-2013-2187 | — | — | 5.5% | Apr 22, 2014 | Cross-site scripting (XSS) vulnerability in Apache Archiva 1.2 through 1.2.2 and 1.3 before 1.3.8 allows remote attacker... |
| CVE-2013-2105 | — | — | 0.4% | Apr 22, 2014 | The Show In Browser (show_in_browser) gem 0.0.3 for Ruby allows local users to inject arbitrary web script or HTML via a... |
| CVE-2013-1421 | — | — | 1.2% | Apr 22, 2014 | Cross-site scripting (XSS) vulnerability in Craig Knudsen WebCalendar before 1.2.5, 1.2.6, and other versions before 1.2... |
Check if your code is affected by 2013 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now