2013 CVE Vulnerabilities

6,830 CVEs published in 2013.

CVE IDSeverityCVSSDescription
CVE-2013-6309IBM Marketing Platform 9.1 before FP2 allows remote authenticated users to hijack sessions, and consequently read record...
CVE-2013-6308IBM Marketing Platform 9.1 before FP2 allows remote authenticated users to conduct phishing attacks and capture login cr...
CVE-2013-6737IBM System Storage Storwize V7000 Unified 1.3.x and 1.4.x before 1.4.3.0 does not properly restrict the content of a dum...
CVE-2013-1068The OpenStack Nova (python-nova) package 1:2013.2.3-0 before 1:2013.2.3-0ubuntu1.2 and 1:2014.1-0 before 1:2014.1-0ubunt...
CVE-2013-5017SNMPConfig.php in the management console in Symantec Web Gateway (SWG) before 5.2.1 allows remote attackers to execute a...
CVE-2013-6221Directory traversal vulnerability in CommunicationServlet in HP Service Virtualization 3.x before 3.50.1, when the AutoP...
CVE-2013-6078The default configuration of EMC RSA BSAFE Toolkits and RSA Data Protection Manager (DPM) 20130918 uses the Dual Ellipti...
CVE-2013-7072Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ...
CVE-2013-5356Sharetronix 3.1.1.3, 3.1.1, and earlier does not properly restrict access to unspecified AJAX functionality, which allow...
CVE-2013-5353Unrestricted file upload vulnerability in system/controllers/ajax/attachments.php in Sharetronix 3.1.1.3, 3.1.1, and ear...
CVE-2013-5352Sharetronix 3.1.1.3, 3.1.1, and earlier allows remote attackers to execute arbitrary PHP code via the (1) activities_tex...
CVE-2013-4099Multiple unspecified vulnerabilities in OpenAL32.dll in JOAL 2.0-rc11, as used in JOGAMP, allow context-dependent attack...
CVE-2013-3843Stack-based buffer overflow in the mk_request_header_process function in mk_request.c in Monkey HTTP Daemon (monkeyd) be...
CVE-2013-3663Heap-based buffer overflow in paintlib, as used in Trimble SketchUp (formerly Google SketchUp) before 8 Maintenance 3, a...
CVE-2013-2182The Mandril security plugin in Monkey HTTP Daemon (monkeyd) before 1.5.0 allows remote attackers to bypass access restri...
CVE-2013-2163Monkey HTTP Daemon (monkeyd) before 1.2.2 allows remote attackers to cause a denial of service (infinite loop) via an of...
CVE-2013-1841Net-Server, when the reverse-lookups option is enabled, does not check if the hostname resolves to the source IP address...
CVE-2013-6825(1) movescu.cc and (2) storescp.cc in dcmnet/apps/, (3) dcmnet/libsrc/scp.cc, (4) dcmwlm/libsrc/wlmactmg.cc, (5) dcmprsc...
CVE-2013-5643Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ...
CVE-2013-7323python-gnupg before 0.3.5 allows context-dependent attackers to execute arbitrary commands via shell metacharacters in u...
CVE-2013-6223LiveZilla before 5.1.1.0 stores the admin Base64 encoded username and password in a 1click file, which allows local user...
CVE-2013-5760QNAP Photo Station before firmware 4.0.3 build0912 allows remote attackers to list OS user accounts via a request to pho...
CVE-2013-4599The Misery module 6.x-2.x before 6.x-2.5 and 7.x-2.x before 7.x-2.2 for Drupal, when the "delay misery" configuration is...
CVE-2013-4597The Revisioning module 7.x-1.x before 7.x-1.6 for Drupal does not properly check node access permissions for content mar...
CVE-2013-4595The Secure Pages module 6.x-2.x before 6.x-2.0 for Drupal does not properly match URLs, which causes HTTP to be used ins...

Check if your code is affected by 2013 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now