2013 CVE Vulnerabilities

6,830 CVEs published in 2013.

CVE IDSeverityCVSSDescription
CVE-2013-2604RealNetworks GameHouse RealArcade Installer (aka ActiveMARK Game Installer) 2.6.0.481 and 3.0.7 uses weak permissions (C...
CVE-2013-2603The RACInstaller.StateCtrl.1 ActiveX control in InstallerDlg.dll in RealNetworks GameHouse RealArcade Installer 2.6.0.48...
CVE-2013-7420Buffer overflow in Hancom Office 2010 SE allows remote attackers to execute arbitrary via a long string in the Text attr...
CVE-2013-7419Cross-site scripting (XSS) vulnerability in includes/refreshDate.php in the Joomlaskin JS Multi Hotel (aka JS MultiHotel...
CVE-2013-6126Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was...
CVE-2013-6125Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was...
CVE-2013-2131Format string vulnerability in the rrdtool module 1.4.7 for Python, as used in Zenoss, allows context-dependent attacker...
CVE-2013-7418cgi-bin/iptablesgui.cgi in IPCop (aka IPCop Firewall) before 2.1.5 allows remote authenticated users to execute arbitrar...
CVE-2013-7417Cross-site scripting (XSS) vulnerability in cgi-bin/ipinfo.cgi in IPCop (aka IPCop Firewall) before 2.1.3 allows remote ...
CVE-2013-3295Directory traversal vulnerability in install/popup.php in Exponent CMS before 2.2.0 RC1 allows remote attackers to inclu...
CVE-2013-4663git_http_controller.rb in the redmine_git_hosting plugin for Redmine allows remote attackers to execute arbitrary comman...
CVE-2013-6998Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-6870. Reason: This candidate is a duplicate of...
CVE-2013-6919The default configuration of phpThumb before 1.7.12 has a false value for the disable_debug option, which allows remote ...
CVE-2013-6241The Birthday widget in the backend in Open-Xchange (OX) AppSuite 7.2.x before 7.2.2-rev25 and 7.4.x before 7.4.0-rev14, ...
CVE-2013-6227Unrestricted file upload vulnerability in plugins/editor.zoho/agent/save_zoho.php in the Zoho plugin in Pydio (formerly ...
CVE-2013-6043The login function in Softaculous Webuzo before 2.1.4 provides different error messages for invalid authentication attem...
CVE-2013-6041index.php in Softaculous Webuzo before 2.1.4 allows remote attackers to execute arbitrary commands via shell metacharact...
CVE-2013-5958The Security component in Symfony 2.0.x before 2.0.25, 2.1.x before 2.1.13, 2.2.x before 2.2.9, and 2.3.x before 2.3.6 a...
CVE-2013-4793The update function in umbraco.webservices/templates/templateService.cs in the TemplateService component in Umbraco CMS ...
CVE-2013-4769The cloud controller (aka CLC) component in Eucalyptus 3.3.x and 3.4.x before 3.4.2, when the dns.recursive.enabled sett...
CVE-2013-4754Multiple cross-site scripting (XSS) vulnerabilities in Owl Intranet Knowledgebase 1.10 allow remote authenticated users ...
CVE-2013-4753Multiple cross-site scripting (XSS) vulnerabilities in Claroline 1.11.9 and earlier allow remote authenticated users to ...
CVE-2013-7401The parse_request function in request.c in c-icap 0.2.x allows remote attackers to cause a denial of service (crash) via...
CVE-2013-4442Password Generator (aka Pwgen) before 2.07 uses weak pseudo generated numbers when /dev/urandom is unavailable, which ma...
CVE-2013-4440Password Generator (aka Pwgen) before 2.07 generates weak non-tty passwords, which makes it easier for context-dependent...

Check if your code is affected by 2013 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now