2013 CVE Vulnerabilities
6,830 CVEs published in 2013.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2013-6656 | — | — | 1.1% | Feb 24, 2014 | The XSSAuditor::init function in core/html/parser/XSSAuditor.cpp in the XSS auditor in Blink, as used in Google Chrome b... |
| CVE-2013-6655 | — | — | 1.3% | Feb 24, 2014 | Use-after-free vulnerability in Blink, as used in Google Chrome before 33.0.1750.117, allows remote attackers to cause a... |
| CVE-2013-6654 | — | — | 1.3% | Feb 24, 2014 | The SVGAnimateElement::calculateAnimatedValue function in core/svg/SVGAnimateElement.cpp in Blink, as used in Google Chr... |
| CVE-2013-6653 | — | — | 1.3% | Feb 24, 2014 | Use-after-free vulnerability in the web contents implementation in Google Chrome before 33.0.1750.117 allows remote atta... |
| CVE-2013-6652 | — | — | 1.2% | Feb 24, 2014 | Directory traversal vulnerability in sandbox/win/src/named_pipe_dispatcher.cc in Google Chrome before 33.0.1750.117 on W... |
| CVE-2013-6202 | — | — | 2.3% | Feb 24, 2014 | Multiple cross-site request forgery (CSRF) vulnerabilities in HP Service Manager 9.30, 9.31, 9.32, and 9.33 allow remote... |
| CVE-2013-2817 | — | — | 5.9% | Feb 24, 2014 | An ActiveX control in IcoLaunch.dll in Mitsubishi Electric Automation MC-WorX Suite 8.02 allows user-assisted remote att... |
| CVE-2013-6952 | — | — | 3.8% | Feb 22, 2014 | The Belkin WeMo Home Automation firmware before 3949 has a hardcoded GPG key, which makes it easier for remote attackers... |
| CVE-2013-6951 | — | — | 0.6% | Feb 22, 2014 | The Belkin WeMo Home Automation firmware before 3949 does not maintain a set of Certification Authority public keys, whi... |
| CVE-2013-6950 | — | — | 1.1% | Feb 22, 2014 | The Belkin WeMo Home Automation firmware before 3949 does not use SSL for the distribution feed, which allows man-in-the... |
| CVE-2013-6949 | — | — | 1.9% | Feb 22, 2014 | The Belkin WeMo Home Automation firmware before 3949 does not properly use the STUN and TURN protocols, which allows rem... |
| CVE-2013-6948 | — | — | 1.6% | Feb 22, 2014 | The peerAddresses API in the Belkin WeMo Home Automation firmware before 3949 allows remote attackers to read arbitrary ... |
| CVE-2013-6734 | — | — | 1.0% | Feb 22, 2014 | IBM WebSphere eXtreme Scale Client 7.1 through 8.6.0.4 does not properly isolate the cached data of different users, whi... |
| CVE-2013-6732 | — | — | 1.4% | Feb 22, 2014 | Cross-site scripting (XSS) vulnerability in the server in IBM Cognos Business Intelligence (BI) 8.4.1, 10.1 before IF6, ... |
| CVE-2013-4420 | — | — | 3.3% | Feb 20, 2014 | Multiple directory traversal vulnerabilities in the (1) tar_extract_glob and (2) tar_extract_all functions in libtar 1.2... |
| CVE-2013-6396 | — | — | 0.7% | Feb 18, 2014 | The OpenStack Python client library for Swift (python-swiftclient) 1.0 through 1.9.0 does not verify X.509 certificates ... |
| CVE-2013-7328 | — | — | 1.5% | Feb 18, 2014 | Multiple integer signedness errors in the gdImageCrop function in ext/gd/gd.c in PHP 5.5.x before 5.5.9 allow remote att... |
| CVE-2013-7327 | — | — | 2.7% | Feb 18, 2014 | The gdImageCrop function in ext/gd/gd.c in PHP 5.5.x before 5.5.9 does not check return values, which allows remote atta... |
| CVE-2013-7226 | — | — | 6.7% | Feb 18, 2014 | Integer overflow in the gdImageCrop function in ext/gd/gd.c in PHP 5.5.x before 5.5.9 allows remote attackers to cause a... |
| CVE-2013-6674 | — | — | 7.7% | Feb 17, 2014 | Cross-site scripting (XSS) vulnerability in Mozilla Thunderbird 17.x through 17.0.8, Thunderbird ESR 17.x through 17.0.1... |
| CVE-2013-1070 | — | — | 2.4% | Feb 17, 2014 | Cross-site scripting (XSS) vulnerability in the API in Ubuntu Metal as a Service (MaaS) 1.2 and 1.4 allows remote attack... |
| CVE-2013-1069 | — | — | 0.4% | Feb 17, 2014 | Ubuntu Metal as a Service (MaaS) 1.2 and 1.4 uses world-readable permissions for txlongpoll.yaml, which allows local use... |
| CVE-2013-6167 | — | — | 1.6% | Feb 15, 2014 | Mozilla Firefox through 27 sends HTTP Cookie headers without first validating that they have the required character-set ... |
| CVE-2013-6166 | — | — | 1.9% | Feb 15, 2014 | Google Chrome before 29 sends HTTP Cookie headers without first validating that they have the required character-set res... |
| CVE-2013-4737 | — | — | 1.4% | Feb 15, 2014 | The CONFIG_STRICT_MEMORY_RWX implementation for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Andro... |
Check if your code is affected by 2013 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now