2013 CVE Vulnerabilities

6,830 CVEs published in 2013.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2013-6656The XSSAuditor::init function in core/html/parser/XSSAuditor.cpp in the XSS auditor in Blink, as used in Google Chrome b...
CVE-2013-6655Use-after-free vulnerability in Blink, as used in Google Chrome before 33.0.1750.117, allows remote attackers to cause a...
CVE-2013-6654The SVGAnimateElement::calculateAnimatedValue function in core/svg/SVGAnimateElement.cpp in Blink, as used in Google Chr...
CVE-2013-6653Use-after-free vulnerability in the web contents implementation in Google Chrome before 33.0.1750.117 allows remote atta...
CVE-2013-6652Directory traversal vulnerability in sandbox/win/src/named_pipe_dispatcher.cc in Google Chrome before 33.0.1750.117 on W...
CVE-2013-6202Multiple cross-site request forgery (CSRF) vulnerabilities in HP Service Manager 9.30, 9.31, 9.32, and 9.33 allow remote...
CVE-2013-2817An ActiveX control in IcoLaunch.dll in Mitsubishi Electric Automation MC-WorX Suite 8.02 allows user-assisted remote att...
CVE-2013-6952The Belkin WeMo Home Automation firmware before 3949 has a hardcoded GPG key, which makes it easier for remote attackers...
CVE-2013-6951The Belkin WeMo Home Automation firmware before 3949 does not maintain a set of Certification Authority public keys, whi...
CVE-2013-6950The Belkin WeMo Home Automation firmware before 3949 does not use SSL for the distribution feed, which allows man-in-the...
CVE-2013-6949The Belkin WeMo Home Automation firmware before 3949 does not properly use the STUN and TURN protocols, which allows rem...
CVE-2013-6948The peerAddresses API in the Belkin WeMo Home Automation firmware before 3949 allows remote attackers to read arbitrary ...
CVE-2013-6734IBM WebSphere eXtreme Scale Client 7.1 through 8.6.0.4 does not properly isolate the cached data of different users, whi...
CVE-2013-6732Cross-site scripting (XSS) vulnerability in the server in IBM Cognos Business Intelligence (BI) 8.4.1, 10.1 before IF6, ...
CVE-2013-4420Multiple directory traversal vulnerabilities in the (1) tar_extract_glob and (2) tar_extract_all functions in libtar 1.2...
CVE-2013-6396The OpenStack Python client library for Swift (python-swiftclient) 1.0 through 1.9.0 does not verify X.509 certificates ...
CVE-2013-7328Multiple integer signedness errors in the gdImageCrop function in ext/gd/gd.c in PHP 5.5.x before 5.5.9 allow remote att...
CVE-2013-7327The gdImageCrop function in ext/gd/gd.c in PHP 5.5.x before 5.5.9 does not check return values, which allows remote atta...
CVE-2013-7226Integer overflow in the gdImageCrop function in ext/gd/gd.c in PHP 5.5.x before 5.5.9 allows remote attackers to cause a...
CVE-2013-6674Cross-site scripting (XSS) vulnerability in Mozilla Thunderbird 17.x through 17.0.8, Thunderbird ESR 17.x through 17.0.1...
CVE-2013-1070Cross-site scripting (XSS) vulnerability in the API in Ubuntu Metal as a Service (MaaS) 1.2 and 1.4 allows remote attack...
CVE-2013-1069Ubuntu Metal as a Service (MaaS) 1.2 and 1.4 uses world-readable permissions for txlongpoll.yaml, which allows local use...
CVE-2013-6167Mozilla Firefox through 27 sends HTTP Cookie headers without first validating that they have the required character-set ...
CVE-2013-6166Google Chrome before 29 sends HTTP Cookie headers without first validating that they have the required character-set res...
CVE-2013-4737The CONFIG_STRICT_MEMORY_RWX implementation for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Andro...

Check if your code is affected by 2013 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now