2013 CVE Vulnerabilities
6,830 CVEs published in 2013.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2013-5759 | — | — | — | Aug 3, 2014 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-5758. Reason: This candidate is not an indepen... |
| CVE-2013-5758 | — | — | 11.9% | Aug 3, 2014 | cgi-bin/cgiServer.exx in Yealink VoIP Phone SIP-T38G allows remote authenticated users to execute arbitrary commands by ... |
| CVE-2013-5757 | — | — | 2.8% | Aug 3, 2014 | Absolute path traversal vulnerability in Yealink VoIP Phone SIP-T38G allows remote authenticated users to read arbitrary... |
| CVE-2013-5756 | — | — | 3.1% | Aug 3, 2014 | Directory traversal vulnerability in Yealink VoIP Phone SIP-T38G allows remote authenticated users to read arbitrary fil... |
| CVE-2013-7393 | — | — | 0.6% | Jul 28, 2014 | The daemonize.py module in Subversion 1.8.0 before 1.8.2 allows local users to gain privileges via a symlink attack on t... |
| CVE-2013-4262 | — | — | 0.6% | Jul 28, 2014 | svnwcsub.py in Subversion 1.8.0 before 1.8.3, when using the --pidfile option and running in foreground mode, allows loc... |
| CVE-2013-4840 | — | — | 2.5% | Jul 28, 2014 | Unspecified vulnerability in HP and H3C VPN Firewall Module products SECPATH1000FE before 5.20.R3177 and SECBLADEFW befo... |
| CVE-2013-7392 | — | — | 8.5% | Jul 22, 2014 | Gitlist allows remote attackers to execute arbitrary commands via shell metacharacters in a file name to Source/. |
| CVE-2013-4352 | — | — | 11.5% | Jul 20, 2014 | The cache_invalidate function in modules/cache/cache_storage.c in the mod_cache module in the Apache HTTP Server 2.4.6, ... |
| CVE-2013-7391 | — | — | 1.4% | Jul 19, 2014 | The Entity API module 7.x-1.x before 7.x-1.2 for Drupal, when using the (a) Views field or (b) area plugins, allows remo... |
| CVE-2013-4273 | — | — | 1.1% | Jul 19, 2014 | The Entity API module 7.x-1.x before 7.x-1.2 for Drupal does not properly restrict access to node comments, which allows... |
| CVE-2013-5855 | — | — | 4.7% | Jul 17, 2014 | Oracle Mojarra 2.2.x before 2.2.6 and 2.1.x before 2.1.28 does not perform appropriate encoding when a (1) <h:outputText... |
| CVE-2013-5755 | — | — | 4.3% | Jul 16, 2014 | config/.htpasswd in Yealink IP Phone SIP-T38G has a hardcoded password of (1) user (s7C9Cx.rLsWFA) for the user account,... |
| CVE-2013-6691 | — | — | 1.7% | Jul 14, 2014 | The WebVPN CIFS implementation in Cisco Adaptive Security Appliance (ASA) Software 9.0(.4.1) and earlier allows remote C... |
| CVE-2013-5567 | — | — | 2.1% | Jul 14, 2014 | Cisco Adaptive Security Appliance (ASA) Software 8.4(.6) and earlier, when using an unsupported configuration with overl... |
| CVE-2013-6117 | — | — | 70.7% | Jul 11, 2014 | Dahua DVR 2.608.0000.0 and 2.608.GV00.0 allows remote attackers to bypass authentication and obtain sensitive informatio... |
| CVE-2013-7389 | — | — | 27.8% | Jul 7, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in D-Link DIR-645 Router (Rev. A1) with firmware before 1.04B11 allo... |
| CVE-2013-5423 | — | — | 1.4% | Jul 7, 2014 | IBM Flex System Manager (FSM) 1.1 through 1.3 before 1.3.2.0 allows remote attackers to enumerate user accounts via unsp... |
| CVE-2013-3993 | MEDIUM | 6.5 | 5.2% | Jul 7, 2014 | IBM InfoSphere BigInsights before 2.1.0.3 allows remote authenticated users to bypass intended file and directory restri... |
| CVE-2013-3004 | — | — | 1.9% | Jul 1, 2014 | Directory traversal vulnerability in BIRT-Report Viewer in IBM Tivoli Application Dependency Discovery Manager (TADDM) 7... |
| CVE-2013-7388 | — | — | 13.2% | Jul 1, 2014 | Heap-based buffer overflow in paintlib, as used in Trimble SketchUp (formerly Google SketchUp) before 2013 (13.0.3689), ... |
| CVE-2013-3664 | — | — | 29.8% | Jul 1, 2014 | Trimble SketchUp (formerly Google SketchUp) before 2013 (13.0.3689) allows remote attackers to execute arbitrary code vi... |
| CVE-2013-3662 | — | — | 31.9% | Jul 1, 2014 | Timbre SketchUp (formerly Google SketchUp) before 8 Maintenance 2 allows remote attackers to execute arbitrary code via ... |
| CVE-2013-6311 | — | — | 1.0% | Jun 28, 2014 | SQL injection vulnerability in IBM Marketing Platform 9.1 before FP2 allows remote authenticated users to execute arbitr... |
| CVE-2013-6310 | — | — | 0.8% | Jun 28, 2014 | Cross-site scripting (XSS) vulnerability in IBM Marketing Platform 9.1 before FP2 allows remote authenticated users to i... |
Check if your code is affected by 2013 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now