2013 CVE Vulnerabilities
6,830 CVEs published in 2013.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2013-4980 | — | — | 6.9% | Mar 3, 2014 | Buffer overflow in the RTSP Packet Handler in AVTECH AVN801 DVR with firmware 1017-1003-1009-1003 and earlier, and possi... |
| CVE-2013-4977 | — | — | 16.7% | Mar 3, 2014 | Buffer overflow in the RTSP Packet Handler in Hikvision DS-2CD7153-E IP camera with firmware 4.1.0 b130111 (Jan 2013), a... |
| CVE-2013-3487 | — | — | 2.3% | Mar 3, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in the security log in the BulletProof Security plugin before .49 fo... |
| CVE-2013-3260 | — | — | 2.7% | Mar 3, 2014 | Heap-based buffer overflow in INMATRIX Zoom Player before 8.7 beta 11 allows remote attackers to execute arbitrary code ... |
| CVE-2013-3259 | — | — | 3.0% | Mar 3, 2014 | Stack-based buffer overflow in INMATRIX Zoom Player before 8.7 beta 11 allows remote attackers to execute arbitrary code... |
| CVE-2013-1409 | — | — | 4.5% | Mar 3, 2014 | Cross-site scripting (XSS) vulnerability in the CommentLuv plugin before 2.92.4 for WordPress allows remote attackers to... |
| CVE-2013-4710 | — | — | 42.6% | Mar 3, 2014 | Android 3.0 through 4.1.x on Disney Mobile, eAccess, KDDI, NTT DOCOMO, SoftBank, and other devices does not properly imp... |
| CVE-2013-4054 | — | — | 2.3% | Mar 2, 2014 | Directory traversal vulnerability in WMQ Telemetry in IBM WebSphere MQ 7.5 before 7.5.0.3 allows remote attackers to rea... |
| CVE-2013-2498 | — | — | 1.3% | Mar 1, 2014 | SQL injection vulnerability in the login page in flexycms/modules/user/user_manager.php in SimpleHRM 2.3, 2.2, and earli... |
| CVE-2013-3712 | — | — | 1.4% | Feb 26, 2014 | SUSE Studio Onsite 1.3.x before 1.3.6 and SUSE Studio Extension for System z 1.3 uses "static" secret tokens, which has ... |
| CVE-2013-7332 | — | — | 13.3% | Feb 26, 2014 | The Microsoft.XMLDOM ActiveX control in Microsoft Windows 8.1 and earlier does not properly detect recursion during enti... |
| CVE-2013-6731 | — | — | 0.8% | Feb 26, 2014 | IBM Netezza Performance Portal 2.x before 2.0.0.3 allows remote authenticated users to change arbitrary passwords via an... |
| CVE-2013-6204 | — | — | 5.5% | Feb 26, 2014 | The Web Console in HP Application Information Optimizer (formerly HP Database Archiving) 6.2, 6.3, 6.4, 7.0, and 7.1 all... |
| CVE-2013-6203 | — | — | 5.5% | Feb 26, 2014 | The Web Console in HP Application Information Optimizer (formerly HP Database Archiving) 6.2, 6.3, 6.4, 7.0, and 7.1 all... |
| CVE-2013-4841 | — | — | 10.4% | Feb 26, 2014 | Unspecified vulnerability in dbd_manager in LeftHand OS before 11.0 in HP StoreVirtual 4000 and StoreVirtual VSA Softwar... |
| CVE-2013-4590 | — | — | 9.5% | Feb 26, 2014 | Apache Tomcat before 6.0.39, 7.x before 7.0.50, and 8.x before 8.0.0-RC10 allows attackers to obtain "Tomcat internals" ... |
| CVE-2013-4322 | — | — | 9.5% | Feb 26, 2014 | Apache Tomcat before 6.0.39, 7.x before 7.0.50, and 8.x before 8.0.0-RC10 processes chunked transfer coding without prop... |
| CVE-2013-4286 | — | — | 16.8% | Feb 26, 2014 | Apache Tomcat before 6.0.39, 7.x before 7.0.47, and 8.x before 8.0.0-RC3, when an HTTP connector or AJP connector is use... |
| CVE-2013-2824 | — | — | 1.8% | Feb 26, 2014 | Schneider Electric StruxureWare SCADA Expert Vijeo Citect 7.40, Vijeo Citect 7.20 through 7.30SP1, CitectSCADA 7.20 thro... |
| CVE-2013-6047 | — | — | 1.2% | Feb 25, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in the site creation interface in ikiwiki-hosting before 0.20131025 ... |
| CVE-2013-6661 | — | — | 1.3% | Feb 24, 2014 | Multiple unspecified vulnerabilities in Google Chrome before 33.0.1750.117 allow attackers to bypass the sandbox protect... |
| CVE-2013-6660 | — | — | 0.9% | Feb 24, 2014 | The drag-and-drop implementation in Google Chrome before 33.0.1750.117 does not properly restrict the information in Web... |
| CVE-2013-6659 | — | — | 0.8% | Feb 24, 2014 | The SSLClientSocketNSS::Core::OwnAuthCertHandler function in net/socket/ssl_client_socket_nss.cc in Google Chrome before... |
| CVE-2013-6658 | — | — | 2.1% | Feb 24, 2014 | Multiple use-after-free vulnerabilities in the layout implementation in Blink, as used in Google Chrome before 33.0.1750... |
| CVE-2013-6657 | — | — | 1.2% | Feb 24, 2014 | core/html/parser/XSSAuditor.cpp in the XSS auditor in Blink, as used in Google Chrome before 33.0.1750.117, inserts the ... |
Check if your code is affected by 2013 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now