2013 CVE Vulnerabilities

6,831 CVEs published in 2013.

CVE IDSeverityCVSSDescription
CVE-2013-3086——Cross-site request forgery (CSRF) vulnerability in util_system.html in Belkin N900 router allows remote attackers to hij...
CVE-2013-3083——Cross-site request forgery (CSRF) vulnerability in cgi-bin/system_setting.exe in Belkin F5D8236-4 v2 allows remote attac...
CVE-2013-3068——Cross-site request forgery (CSRF) vulnerability in apply.cgi in Linksys WRT310Nv2 2.0.0.1 allows remote attackers to hij...
CVE-2013-3066——Linksys EA6500 with firmware 1.1.28.147876 does not properly restrict access, which allows remote attackers to obtain se...
CVE-2013-3065——Cross-site scripting (XSS) vulnerability in the Parental Controls section in Linksys EA6500 with firmware 1.1.28.147876 ...
CVE-2013-3064——Open redirect vulnerability in ui/dynamic/unsecured.html in Linksys EA6500 with firmware 1.1.28.147876 allows remote att...
CVE-2013-2586——XAMPP 1.8.1 does not properly restrict access to xampp/lang.php, which allows remote attackers to modify xampp/lang.tmp ...
CVE-2013-2100——The urlopen function in pym/portage/util/_urlopen.py in Gentoo Portage 2.1.12, when using HTTPS, does not verify X.509 c...
CVE-2013-1874——Untrusted search path vulnerability in csi in Chicken before 4.8.2 allows local users to execute arbitrary code via a Tr...
CVE-2013-4444——Unrestricted file upload vulnerability in Apache Tomcat 7.x before 7.0.40, in certain situations involving outdated java...
CVE-2013-6124——The Qualcomm Innovation Center (QuIC) init scripts in Code Aurora Forum (CAF) releases of Android 4.1.x through 4.4.x al...
CVE-2013-2599——A certain Qualcomm Innovation Center (QuIC) patch to the NativeDaemonConnector class in services/java/com/android/server...
CVE-2013-2598——app/aboot/aboot.c in the Little Kernel (LK) bootloader, as distributed with Qualcomm Innovation Center (QuIC) Android co...
CVE-2013-2597HIGH8.4Stack-based buffer overflow in the acdb_ioctl function in audio_acdb.c in the acdb audio driver for the Linux kernel 2.6...
CVE-2013-2595——The device-initialization functionality in the MSM camera driver for the Linux kernel 2.6.x and 3.x, as used in Qualcomm...
CVE-2013-5467——Monitoring Agent for UNIX Logs 6.2.0 through FP03, 6.2.1 through FP04, 6.2.2 through FP09, and 6.2.3 through FP04 and Mo...
CVE-2013-6335——The Backup-Archive client in IBM Tivoli Storage Manager (TSM) for Space Management 5.x and 6.x before 6.2.5.3, 6.3.x bef...
CVE-2013-6222——Cross-site scripting (XSS) vulnerability in the Mobility Web Client and Service Request Catalog (SRC) components in HP S...
CVE-2013-6306——Unspecified vulnerability on IBM Power 7 Systems 740 before 740.70 01Ax740_121, 760 before 760.40 Ax760_078, and 770 bef...
CVE-2013-7144——LINE 3.2.1.83 and earlier on Windows and 3.2.1 and earlier on OS X does not verify X.509 certificates from SSL servers, ...
CVE-2013-7180——Cobham SAILOR 900 VSAT; SAILOR FleetBroadBand 150, 250, and 500; EXPLORER BGAN; and AVIATOR 200, 300, 350, and 700D devi...
CVE-2013-7395——ZOLL Defibrillator / Monitor X Series has a default (1) supervisor password and (2) service password, which allows physi...
CVE-2013-5433——The Data Growth Solution for JD Edwards EnterpriseOne in IBM InfoSphere Optim 3.0 through 9.1 has hardcoded database cre...
CVE-2013-7394——The "runshellscript echo.sh" script in Splunk before 5.0.5 allows remote authenticated users to execute arbitrary comman...
CVE-2013-6771——Directory traversal vulnerability in the collect script in Splunk before 5.0.5 allows remote attackers to execute arbitr...

Check if your code is affected by 2013 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now