2013 CVE Vulnerabilities

6,831 CVEs published in 2013.

CVE IDSeverityCVSSDescription
CVE-2013-6310——Cross-site scripting (XSS) vulnerability in IBM Marketing Platform 9.1 before FP2 allows remote authenticated users to i...
CVE-2013-6309——IBM Marketing Platform 9.1 before FP2 allows remote authenticated users to hijack sessions, and consequently read record...
CVE-2013-6308——IBM Marketing Platform 9.1 before FP2 allows remote authenticated users to conduct phishing attacks and capture login cr...
CVE-2013-6737——IBM System Storage Storwize V7000 Unified 1.3.x and 1.4.x before 1.4.3.0 does not properly restrict the content of a dum...
CVE-2013-1068——The OpenStack Nova (python-nova) package 1:2013.2.3-0 before 1:2013.2.3-0ubuntu1.2 and 1:2014.1-0 before 1:2014.1-0ubunt...
CVE-2013-5017——SNMPConfig.php in the management console in Symantec Web Gateway (SWG) before 5.2.1 allows remote attackers to execute a...
CVE-2013-6221——Directory traversal vulnerability in CommunicationServlet in HP Service Virtualization 3.x before 3.50.1, when the AutoP...
CVE-2013-6078——The default configuration of EMC RSA BSAFE Toolkits and RSA Data Protection Manager (DPM) 20130918 uses the Dual Ellipti...
CVE-2013-7072——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ...
CVE-2013-5356——Sharetronix 3.1.1.3, 3.1.1, and earlier does not properly restrict access to unspecified AJAX functionality, which allow...
CVE-2013-5353——Unrestricted file upload vulnerability in system/controllers/ajax/attachments.php in Sharetronix 3.1.1.3, 3.1.1, and ear...
CVE-2013-5352——Sharetronix 3.1.1.3, 3.1.1, and earlier allows remote attackers to execute arbitrary PHP code via the (1) activities_tex...
CVE-2013-4099——Multiple unspecified vulnerabilities in OpenAL32.dll in JOAL 2.0-rc11, as used in JOGAMP, allow context-dependent attack...
CVE-2013-3843——Stack-based buffer overflow in the mk_request_header_process function in mk_request.c in Monkey HTTP Daemon (monkeyd) be...
CVE-2013-3663——Heap-based buffer overflow in paintlib, as used in Trimble SketchUp (formerly Google SketchUp) before 8 Maintenance 3, a...
CVE-2013-2182——The Mandril security plugin in Monkey HTTP Daemon (monkeyd) before 1.5.0 allows remote attackers to bypass access restri...
CVE-2013-2163——Monkey HTTP Daemon (monkeyd) before 1.2.2 allows remote attackers to cause a denial of service (infinite loop) via an of...
CVE-2013-1841——Net-Server, when the reverse-lookups option is enabled, does not check if the hostname resolves to the source IP address...
CVE-2013-6825——(1) movescu.cc and (2) storescp.cc in dcmnet/apps/, (3) dcmnet/libsrc/scp.cc, (4) dcmwlm/libsrc/wlmactmg.cc, (5) dcmprsc...
CVE-2013-5643——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ...
CVE-2013-7323——python-gnupg before 0.3.5 allows context-dependent attackers to execute arbitrary commands via shell metacharacters in u...
CVE-2013-6223——LiveZilla before 5.1.1.0 stores the admin Base64 encoded username and password in a 1click file, which allows local user...
CVE-2013-5760——QNAP Photo Station before firmware 4.0.3 build0912 allows remote attackers to list OS user accounts via a request to pho...
CVE-2013-4599——The Misery module 6.x-2.x before 6.x-2.5 and 7.x-2.x before 7.x-2.2 for Drupal, when the "delay misery" configuration is...
CVE-2013-4597——The Revisioning module 7.x-1.x before 7.x-1.6 for Drupal does not properly check node access permissions for content mar...

Check if your code is affected by 2013 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now