2013 CVE Vulnerabilities
6,830 CVEs published in 2013.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2013-0346 | — | — | 0.7% | Feb 15, 2014 | Apache Tomcat 7.x uses world-readable permissions for the log directory and its files, which might allow local users to ... |
| CVE-2013-7326 | — | — | 2.1% | Feb 14, 2014 | Cross-site scripting (XSS) vulnerability in vTiger CRM 5.4.0 allows remote attackers to inject arbitrary web script or H... |
| CVE-2013-7032 | — | — | 1.8% | Feb 14, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in the web based operator client in LiveZilla before 5.1.2.1 allow r... |
| CVE-2013-5351 | — | — | 5.0% | Feb 14, 2014 | Heap-based buffer overflow in IrfanView before 4.37 allows remote attackers to execute arbitrary code via the LZW code s... |
| CVE-2013-4499 | — | — | 1.1% | Feb 14, 2014 | Cross-site scripting (XSS) vulnerability in the Bean module 7.x-1.x before 7.x-1.5 for Drupal allows remote attackers to... |
| CVE-2013-6492 | — | — | 4.0% | Feb 14, 2014 | The Piranha Configuration Tool in Piranha 0.8.6 does not properly restrict access to webpages, which allows remote attac... |
| CVE-2013-6441 | — | — | 0.5% | Feb 14, 2014 | The lxc-sshd template (templates/lxc-sshd.in) in LXC before 1.0.0.beta2 uses read-write permissions when mounting /sbin/... |
| CVE-2013-6440 | — | — | 2.8% | Feb 14, 2014 | The (1) BasicParserPool, (2) StaticBasicParserPool, (3) XML Decrypter, and (4) SAML Decrypter in Shibboleth OpenSAML-Jav... |
| CVE-2013-4415 | — | — | 1.7% | Feb 14, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in Spacewalk and Red Hat Network (RHN) Satellite 5.6 allow remote at... |
| CVE-2013-1871 | — | — | 1.6% | Feb 14, 2014 | Cross-site scripting (XSS) vulnerability in account/EditAddress.do in Spacewalk and Red Hat Network (RHN) Satellite 5.6 ... |
| CVE-2013-6743 | — | — | 0.9% | Feb 14, 2014 | Cross-site scripting (XSS) vulnerability in the Meeting Server in IBM Sametime 8.5.2 through 8.5.2.1 and 9.x through 9.0... |
| CVE-2013-6742 | — | — | 1.3% | Feb 14, 2014 | The Meeting Server in IBM Sametime 8.5.2 through 8.5.2.1 and 9.x through 9.0.0.1 do not have an off autocomplete attribu... |
| CVE-2013-3988 | — | — | 1.2% | Feb 14, 2014 | The Meeting Server in IBM Sametime 8.5.2 through 8.5.2.1 and 9.x through 9.0.0.1 allows remote attackers to conduct clic... |
| CVE-2013-3983 | — | — | 1.1% | Feb 14, 2014 | The Meeting Server in IBM Sametime 8.5.2 through 8.5.2.1 and 9.x through 9.0.0.1 does not validate URLs in Cookie header... |
| CVE-2013-3978 | — | — | 1.2% | Feb 14, 2014 | The Meeting Server in IBM Sametime 8.5.2 through 8.5.2.1 and 9.x through 9.0.0.1 does not send the appropriate HTTP resp... |
| CVE-2013-2829 | — | — | 1.3% | Feb 14, 2014 | MatrikonOPC SCADA DNP3 OPC Server 1.2.2.0 and earlier allows remote attackers to cause a denial of service (infinite loo... |
| CVE-2013-6722 | — | — | 1.3% | Feb 14, 2014 | Unrestricted file upload vulnerability in the Registration/Edit My Profile portlet in IBM WebSphere Portal 7.x before 7.... |
| CVE-2013-6728 | — | — | 1.2% | Feb 14, 2014 | The charting component in IBM WebSphere Dashboard Framework (WDF) 6.1.5 and 7.0.1 allows remote attackers to view or del... |
| CVE-2013-5400 | — | — | 2.3% | Feb 14, 2014 | An unspecified servlet in IBM Platform Symphony Developer Edition (DE) 5.2 and 6.1.x through 6.1.1 has hardcoded credent... |
| CVE-2013-5015 | — | — | 28.8% | Feb 14, 2014 | SQL injection vulnerability in the management console in Symantec Endpoint Protection Manager (SEPM) 11.0 before 11.0.74... |
| CVE-2013-5014 | — | — | 67.6% | Feb 14, 2014 | The management console in Symantec Endpoint Protection Manager (SEPM) 11.0 before 11.0.7405.1424 and 12.1 before 12.1.40... |
| CVE-2013-2585 | — | — | 1.9% | Feb 12, 2014 | Cross-site scripting (XSS) vulnerability in Atmail Webmail Server 6.6.x before 6.6.3 and 7.0.x before 7.0.3 allows remot... |
| CVE-2013-6229 | — | — | 1.8% | Feb 12, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in Atmail Webmail Server 7.0.2 allow remote attackers to inject arbi... |
| CVE-2013-3933 | — | — | 1.1% | Feb 11, 2014 | Cross-site scripting (XSS) vulnerability in the JoomShopping (com_joomshopping) component before 4.3.1 for Joomla! allow... |
| CVE-2013-3294 | — | — | 2.5% | Feb 11, 2014 | Multiple SQL injection vulnerabilities in Exponent CMS before 2.2.0 release candidate 1 allow remote attackers to execut... |
Check if your code is affected by 2013 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now