2013 CVE Vulnerabilities
6,830 CVEs published in 2013.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2013-4772 | — | — | 4.2% | May 12, 2014 | D-Link DIR-505L SharePort Mobile Companion 1.01 and DIR-826L Wireless N600 Cloud Router 1.02 allows remote attackers to ... |
| CVE-2013-4581 | — | — | 2.1% | May 12, 2014 | GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, Enterprise Edition before 6.2.1 and gitlab-shell before 1.7.8 a... |
| CVE-2013-4580 | — | — | 1.3% | May 12, 2014 | GitLab before 5.4.2, Community Edition before 6.2.4, and Enterprise Edition before 6.2.1, when using a MySQL backend, al... |
| CVE-2013-4577 | — | — | 0.4% | May 12, 2014 | A certain Debian patch for GNU GRUB uses world-readable permissions for grub.cfg, which allows local users to obtain pas... |
| CVE-2013-4574 | — | — | 1.4% | May 12, 2014 | Cross-site scripting (XSS) vulnerability in the TimeMediaHandler extension for MediaWiki before 1.19.10, 1.2x before 1.2... |
| CVE-2013-4571 | — | — | 1.4% | May 12, 2014 | Buffer overflow in php-luasandbox in the Scribuntu extension for MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.... |
| CVE-2013-4570 | — | — | 1.7% | May 12, 2014 | The zend_inline_hash_func function in php-luasandbox in the Scribuntu extension for MediaWiki before 1.19.10, 1.2x befor... |
| CVE-2013-6220 | — | — | 2.5% | May 10, 2014 | Cross-site scripting (XSS) vulnerability in HP Network Node Manager i (NNMi) 9.0, 9.10, and 9.20 allows remote attackers... |
| CVE-2013-5916 | — | — | 2.0% | May 8, 2014 | Cross-site scripting (XSS) vulnerability in falha.php in the Bradesco Gateway plugin 2.0 for Wordpress, as used in the W... |
| CVE-2013-7041 | — | — | 2.5% | May 8, 2014 | The pam_userdb module for Pam uses a case-insensitive method to compare hashed passwords, which makes it easier for atta... |
| CVE-2013-6889 | — | — | 0.5% | May 8, 2014 | GNU Rush 1.7 does not properly drop privileges, which allows local users to read arbitrary files via the --lint option. |
| CVE-2013-6372 | — | — | 0.5% | May 8, 2014 | The Subversion plugin before 1.54 for Jenkins stores credentials using base64 encoding, which allows local users to obta... |
| CVE-2013-4544 | — | — | 0.7% | May 8, 2014 | hw/net/vmxnet3.c in QEMU 2.0.0-rc0, 1.7.1, and earlier allows local guest users to cause a denial of service or possibly... |
| CVE-2013-3571 | — | — | 2.1% | May 8, 2014 | socat 1.2.0.0 before 1.7.2.2 and 2.0.0-b1 before 2.0.0-b6, when used for a listen type address and the fork option is en... |
| CVE-2013-0345 | — | — | 0.4% | May 8, 2014 | varnish 3.0.3 uses world-readable permissions for the /var/log/varnish/ directory and the log files in the directory, wh... |
| CVE-2013-0210 | — | — | 1.9% | May 8, 2014 | The smart proxy Puppet run API in Foreman before 1.2.0 allows remote attackers to execute arbitrary commands via vectors... |
| CVE-2013-0187 | — | — | 1.1% | May 8, 2014 | Foreman before 1.1 allows remote authenticated users to gain privileges via a (1) XMLHttpRequest or (2) AJAX request. |
| CVE-2013-0174 | — | — | 1.7% | May 8, 2014 | The external node classifier (ENC) API in Foreman before 1.1 allows remote attackers to obtain the hashed root password ... |
| CVE-2013-0173 | — | — | 1.1% | May 8, 2014 | Foreman before 1.1 uses a salt of "foreman" to hash root passwords, which makes it easier for attackers to guess the pas... |
| CVE-2013-0171 | — | — | 3.0% | May 8, 2014 | Foreman before 1.1 allows remote attackers to execute arbitrary code via a crafted YAML object to the (1) fact or (2) re... |
| CVE-2013-5016 | — | — | 2.4% | May 8, 2014 | Symantec Critical System Protection (SCSP) before 5.2.9, when installed on an unpatched Windows Server 2003 R2 platform,... |
| CVE-2013-7336 | — | — | 0.3% | May 7, 2014 | The qemuMigrationWaitForSpice function in qemu/qemu_migration.c in libvirt before 1.1.3 does not properly enter a monito... |
| CVE-2013-6726 | — | — | 0.8% | May 7, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in WebProcess.srv in IBM TRIRIGA Application Platform 3.2.x and 3.3.... |
| CVE-2013-7354 | MEDIUM | 6.5 | 2.4% | May 6, 2014 | Multiple integer overflows in libpng before 1.5.14rc03 allow remote attackers to cause a denial of service (crash) via a... |
| CVE-2013-7353 | MEDIUM | 6.5 | 1.9% | May 6, 2014 | Integer overflow in the png_set_unknown_chunks function in libpng/pngset.c in libpng before 1.5.14beta08 allows context-... |
Check if your code is affected by 2013 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now