2013 CVE Vulnerabilities

6,831 CVEs published in 2013.

CVE IDSeverityCVSSDescription
CVE-2013-7386——Format string vulnerability in the PROJECT::write_account_file function in client/cs_account.cpp in BOINC, possibly 7.2....
CVE-2013-6470——The default configuration in the standalone controller quickstack manifest in openstack-foreman-installer, as used in Re...
CVE-2013-6433——The default configuration in the Red Hat openstack-neutron package before 2013.2.3-7 does not properly set a configurati...
CVE-2013-4596——The Node Access Keys module 7.x-1.x before 7.x-1.1 for Drupal does not properly check permissions, which allows remote a...
CVE-2013-3476——Cross-site request forgery (CSRF) vulnerability in the WordPress Related Posts plugin before 2.6.2 for WordPress allows ...
CVE-2013-3258——Cross-site request forgery (CSRF) vulnerability in he Digg Digg plugin before 5.3.5 for WordPress allows remote attacker...
CVE-2013-3257——Cross-site request forgery (CSRF) vulnerability in the Related Posts plugin before 2.7.2 for WordPress allows remote att...
CVE-2013-2710——Cross-site request forgery (CSRF) vulnerability in the Contextual Related Posts plugin before 1.8.7 for WordPress allows...
CVE-2013-2298——Multiple stack-based buffer overflows in the XML parser in BOINC 7.x allow attackers to have unspecified impact via a cr...
CVE-2013-2019——Stack-based buffer overflow in BOINC 6.10.58 and 6.12.34 allows remote attackers to have unspecified impact via multiple...
CVE-2013-2014——OpenStack Identity (Keystone) before 2013.1 allows remote attackers to cause a denial of service (memory consumption and...
CVE-2013-1818——maintenance/mwdoc-filter.php in MediaWiki before 1.20.3 allows remote attackers to read arbitrary files via unspecified ...
CVE-2013-1412——DataLife Engine (DLE) 9.7 allows remote attackers to execute arbitrary PHP code via the catlist[] parameter to engine/pr...
CVE-2013-1397——Symfony 2.0.x before 2.0.22, 2.1.x before 2.1.7, and 2.2.x remote attackers to execute arbitrary PHP code via a serializ...
CVE-2013-1348——The Yaml::parse function in Symfony 2.0.x before 2.0.22 remote attackers to execute arbitrary PHP code via a PHP file, a...
CVE-2013-6744——The Stored Procedure infrastructure in IBM DB2 9.5, 9.7 before FP9a, 10.1 before FP3a, and 10.5 before FP3a on Windows a...
CVE-2013-6788——The Bitrix e-Store module before 14.0.1 for Bitrix Site Manager uses sequential values for the BITRIX_SM_SALE_UID cookie...
CVE-2013-5919——Suricata before 1.4.6 allows remote attackers to cause a denial of service (crash) via a malformed SSL record.
CVE-2013-4143——The (1) checkPasswd and (2) checkGroupXlockPasswds functions in xlockmore before 5.43 do not properly handle when a NULL...
CVE-2013-4178——The Google Authenticator login module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.4 for Drupal allows remote attacke...
CVE-2013-4177——The Google Authenticator login module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.4 for Drupal does not properly ide...
CVE-2013-2193——Apache HBase 0.92.x before 0.92.3 and 0.94.x before 0.94.9, when the Kerberos features are enabled, allows man-in-the-mi...
CVE-2013-0199——The default LDAP ACIs in FreeIPA 3.0 before 3.1.2 do not restrict access to the (1) ipaNTTrustAuthIncoming and (2) ipaNT...
CVE-2013-5036——The Square Squash allows remote attackers to execute arbitrary code via a YAML document in the (1) namespace parameter t...
CVE-2013-4598——The Groups, Communities and Co (GCC) module 7.x-1.x before 7.x-1.1 for Drupal does not properly check permission, which ...

Check if your code is affected by 2013 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now