2013 CVE Vulnerabilities

6,831 CVEs published in 2013.

CVE IDSeverityCVSSDescription
CVE-2013-6805——OpenText Exceed OnDemand (EoD) 8 uses weak encryption for passwords, which makes it easier for (1) remote attackers to d...
CVE-2013-6766——OpenVAS Administrator 1.2 before 1.2.2 and 1.3 before 1.3.2 allows remote attackers to bypass the OAP authentication res...
CVE-2013-6765——OpenVAS Manager 3.0 before 3.0.7 and 4.0 before 4.0.4 allows remote attackers to bypass the OMP authentication restricti...
CVE-2013-6764——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-6795. Reason: This candidate is a duplicate of ...
CVE-2013-6413——Use-after-free vulnerability in UnrealIRCd 3.2.10 before 3.2.10.2 allows remote attackers to cause a denial of service (...
CVE-2013-4432——Mahara before 1.5.13, 1.6.x before 1.6.8, and 1.7.x before 1.7.4 does not properly restrict access to folders, which all...
CVE-2013-4431——Mahara before 1.5.12, 1.6.x before 1.6.7, and 1.7.x before 1.7.3 does not properly prevent access to blocks, which allow...
CVE-2013-4430——Cross-site scripting (XSS) vulnerability in Mahara before 1.5.12, 1.6.x before 1.6.7, and 1.7.x before 1.7.3 allows remo...
CVE-2013-4429——Mahara before 1.5.12, 1.6.x before 1.6.7, and 1.7.x before 1.7.3 does not properly restrict access to artefacts, which a...
CVE-2013-4427——pyxtrlock before 0.2 does not properly check the return values of the (1) xcb_grab_pointer and (2) xcb_grab_keyboard XCB...
CVE-2013-4426——pyxtrlock before 0.1 uses an incorrect variable name, which allows physically proximate attackers to bypass the lock scr...
CVE-2013-4406——The Quick Tabs module 6.x-2.x before 6.x-2.2, 6.x-3.x before 6.x-3.2, and 7.x-3.x before 7.x-3.6 for Drupal does not pro...
CVE-2013-4498——The Spaces OG submodule in the Spaces module 6.x-3.x before 6.x-3.7 for Drupal does not properly delete organic group gr...
CVE-2013-4489——The Grit gem for Ruby, as used in GitLab 5.2 before 5.4.1 and 6.x before 6.2.3, allows remote authenticated users to exe...
CVE-2013-7382——VICIDIAL dialer (aka Asterisk GUI client) 2.8-403a, 2.7, 2.7RC1, and earlier has a hardcoded password of donotedit for t...
CVE-2013-7379——The admin API in the tomato module before 0.0.6 for Node.js does not properly check the access key when it is set to a s...
CVE-2013-4730——Buffer overflow in PCMan's FTP Server 2.0.7 allows remote attackers to execute arbitrary code via a long string in a USE...
CVE-2013-1810——Multiple cross-site scripting (XSS) vulnerabilities in core/summary_api.php in MantisBT 1.2.12 allow remote authenticate...
CVE-2013-0197——Cross-site scripting (XSS) vulnerability in the filter_draw_selection_area2 function in core/filter_api.php in MantisBT ...
CVE-2013-7376——Multiple cross-site request forgery (CSRF) vulnerabilities in OpenX 2.8.10, possibly before revision 82710, allow remote...
CVE-2013-5939——Multiple cross-site scripting (XSS) vulnerabilities in the Guestbook module for PHPCMS allow remote attackers to inject ...
CVE-2013-5655——Directory traversal vulnerability in the FTP server in YingZhi Python Programming Language for iOS 1.9 allows remote att...
CVE-2013-4471——The Identity v3 API in OpenStack Dashboard (Horizon) before 2013.2 does not require the current password when changing p...
CVE-2013-4468——VICIDIAL dialer (aka Asterisk GUI client) 2.8-403a, 2.7, 2.7RC1, and earlier allows remote authenticated users to execut...
CVE-2013-4455——Katello Installer before 0.0.18 uses world-readable permissions for /etc/pki/tls/private/katello-node.key when deploying...

Check if your code is affected by 2013 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now