2013 CVE Vulnerabilities

6,831 CVEs published in 2013.

CVE IDSeverityCVSSDescription
CVE-2013-4151——The virtio_load function in virtio/virtio.c in QEMU 1.x before 1.7.2 allows remote attackers to execute arbitrary code v...
CVE-2013-4150——The virtio_net_load function in hw/net/virtio-net.c in QEMU 1.5.0 through 1.7.x before 1.7.2 allows remote attackers to ...
CVE-2013-4149——Buffer overflow in virtio_net_load function in net/virtio-net.c in QEMU 1.3.0 through 1.7.x before 1.7.2 might allow rem...
CVE-2013-4148——Integer signedness error in the virtio_net_load function in hw/net/virtio-net.c in QEMU 1.x before 1.7.2 allows remote a...
CVE-2013-7057——Cross-site request forgery (CSRF) vulnerability in Axway SecureTransport 5.1 SP2 and earlier allows remote attackers to ...
CVE-2013-0336——The ipapwd_chpwop function in daemons/ipa-slapi-plugins/ipa-pwd-extop/ipa_pwd_extop.c in the directory server (dirsrv) i...
CVE-2013-0334——Bundler before 1.7, when multiple top-level source lines are used, allows remote attackers to install arbitrary gems by ...
CVE-2013-7409——Buffer overflow in ALLPlayer 5.6.2 through 5.8.1 allows remote attackers to cause a denial of service (crash) and possib...
CVE-2013-3304——Directory traversal vulnerability in Dell EqualLogic PS4000 with firmware 6.0 allows remote attackers to read arbitrary ...
CVE-2013-7408——F5 BIG-IP Analytics 11.x before 11.4.0 uses a predictable session cookie, which makes it easier for remote attackers to ...
CVE-2013-6796——The SMTP server in DeepOfix 3.3 and earlier allows remote attackers to bypass authentication via an empty password, whic...
CVE-2013-1641——Directory traversal vulnerability in the zip download functionality in QuiXplorer before 2.5.5 allows remote attackers t...
CVE-2013-4594——The Payment for Webform module 7.x-1.x before 7.x-1.5 for Drupal does not restrict access by anonymous users, which allo...
CVE-2013-7407——Cross-site request forgery (CSRF) vulnerability in the MRBS module for Drupal allows remote attackers to hijack the auth...
CVE-2013-7406——SQL injection vulnerability in the MRBS module for Drupal allows remote attackers to execute arbitrary SQL commands via ...
CVE-2013-7330——Jenkins before 1.502 allows remote authenticated users to configure an otherwise restricted project via vectors related ...
CVE-2013-4488——libgadu before 1.12.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to s...
CVE-2013-7329——The CGI::Application module before 4.50_50 and 4.50_51 for Perl, when run modes are not specified, allows remote attacke...
CVE-2013-1436——The XMonad.Hooks.DynamicLog module in xmonad-contrib before 0.11.2 allows remote attackers to execute arbitrary commands...
CVE-2013-6496——Red Hat Conga 0.12.2 allows remote attackers to obtain sensitive information via a crafted request to the (1) homebase, ...
CVE-2013-2645——Multiple cross-site request forgery (CSRF) vulnerabilities on the TP-LINK WR1043N router with firmware TL-WR1043ND_V1_12...
CVE-2013-2644——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-2645, CVE-2014-2644. Reason: this ID was inten...
CVE-2013-3632HIGH8.8The Cron service in rpc.php in OpenMediaVault allows remote authenticated users to execute cron jobs as arbitrary users ...
CVE-2013-3092——The Belkin N300 (F7D7301v1) router allows remote attackers to bypass authentication and gain privileges via vectors rela...
CVE-2013-3089——Cross-site request forgery (CSRF) vulnerability in apply.cgi in Belkin N300 (F7D7301v1) router allows remote attackers t...

Check if your code is affected by 2013 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now