2013 CVE Vulnerabilities

6,830 CVEs published in 2013.

CVE IDSeverityCVSSDescription
CVE-2013-4150The virtio_net_load function in hw/net/virtio-net.c in QEMU 1.5.0 through 1.7.x before 1.7.2 allows remote attackers to ...
CVE-2013-4149Buffer overflow in virtio_net_load function in net/virtio-net.c in QEMU 1.3.0 through 1.7.x before 1.7.2 might allow rem...
CVE-2013-4148Integer signedness error in the virtio_net_load function in hw/net/virtio-net.c in QEMU 1.x before 1.7.2 allows remote a...
CVE-2013-7057Cross-site request forgery (CSRF) vulnerability in Axway SecureTransport 5.1 SP2 and earlier allows remote attackers to ...
CVE-2013-0336The ipapwd_chpwop function in daemons/ipa-slapi-plugins/ipa-pwd-extop/ipa_pwd_extop.c in the directory server (dirsrv) i...
CVE-2013-0334Bundler before 1.7, when multiple top-level source lines are used, allows remote attackers to install arbitrary gems by ...
CVE-2013-7409Buffer overflow in ALLPlayer 5.6.2 through 5.8.1 allows remote attackers to cause a denial of service (crash) and possib...
CVE-2013-3304Directory traversal vulnerability in Dell EqualLogic PS4000 with firmware 6.0 allows remote attackers to read arbitrary ...
CVE-2013-7408F5 BIG-IP Analytics 11.x before 11.4.0 uses a predictable session cookie, which makes it easier for remote attackers to ...
CVE-2013-6796The SMTP server in DeepOfix 3.3 and earlier allows remote attackers to bypass authentication via an empty password, whic...
CVE-2013-1641Directory traversal vulnerability in the zip download functionality in QuiXplorer before 2.5.5 allows remote attackers t...
CVE-2013-4594The Payment for Webform module 7.x-1.x before 7.x-1.5 for Drupal does not restrict access by anonymous users, which allo...
CVE-2013-7407Cross-site request forgery (CSRF) vulnerability in the MRBS module for Drupal allows remote attackers to hijack the auth...
CVE-2013-7406SQL injection vulnerability in the MRBS module for Drupal allows remote attackers to execute arbitrary SQL commands via ...
CVE-2013-7330Jenkins before 1.502 allows remote authenticated users to configure an otherwise restricted project via vectors related ...
CVE-2013-4488libgadu before 1.12.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to s...
CVE-2013-7329The CGI::Application module before 4.50_50 and 4.50_51 for Perl, when run modes are not specified, allows remote attacke...
CVE-2013-1436The XMonad.Hooks.DynamicLog module in xmonad-contrib before 0.11.2 allows remote attackers to execute arbitrary commands...
CVE-2013-6496Red Hat Conga 0.12.2 allows remote attackers to obtain sensitive information via a crafted request to the (1) homebase, ...
CVE-2013-2645Multiple cross-site request forgery (CSRF) vulnerabilities on the TP-LINK WR1043N router with firmware TL-WR1043ND_V1_12...
CVE-2013-2644Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-2645, CVE-2014-2644. Reason: this ID was inten...
CVE-2013-3632HIGH8.8The Cron service in rpc.php in OpenMediaVault allows remote authenticated users to execute cron jobs as arbitrary users ...
CVE-2013-3092The Belkin N300 (F7D7301v1) router allows remote attackers to bypass authentication and gain privileges via vectors rela...
CVE-2013-3089Cross-site request forgery (CSRF) vulnerability in apply.cgi in Belkin N300 (F7D7301v1) router allows remote attackers t...
CVE-2013-3086Cross-site request forgery (CSRF) vulnerability in util_system.html in Belkin N900 router allows remote attackers to hij...

Check if your code is affected by 2013 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now