2013 CVE Vulnerabilities
6,830 CVEs published in 2013.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2013-5350 | — | — | 1.5% | Jan 24, 2014 | The "Remember me" feature in the opSecurityUser::getRememberLoginCookie function in lib/user/opSecurityUser.class.php in... |
| CVE-2013-7175 | — | — | 1.3% | Jan 24, 2014 | Multiple SQL injection vulnerabilities in Avanset Visual CertExam Manager 3.3 and earlier allow remote authenticated use... |
| CVE-2013-6030 | — | — | 2.9% | Jan 24, 2014 | Directory traversal vulnerability on the Emerson Network Power Avocent MergePoint Unity 2016 (aka MPU2016) KVM switch wi... |
| CVE-2013-5669 | — | — | 2.2% | Jan 24, 2014 | The Thecus NAS server N8800 with firmware 5.03.01 uses cleartext credentials for administrative authentication, which al... |
| CVE-2013-5668 | — | — | 2.1% | Jan 24, 2014 | The ADS/NT Support page on the Thecus NAS server N8800 with firmware 5.03.01 allows remote attackers to discover the adm... |
| CVE-2013-5667 | — | — | 4.2% | Jan 24, 2014 | The Thecus NAS server N8800 with firmware 5.03.01 allows remote attackers to execute arbitrary commands via a get_userid... |
| CVE-2013-7315 | — | — | 3.4% | Jan 23, 2014 | The Spring MVC in Spring Framework before 3.2.4 and 4.0.0.M1 through 4.0.0.M2 does not disable external entity resolutio... |
| CVE-2013-7048 | — | — | 0.5% | Jan 23, 2014 | OpenStack Compute (Nova) Grizzly 2013.1.4, Havana 2013.2.1, and earlier uses world-writable and world-readable permissio... |
| CVE-2013-6934 | — | — | 28.2% | Jan 23, 2014 | The parseRTSPRequestString function in Live Networks Live555 Streaming Media 2013.11.26, as used in VideoLAN VLC Media P... |
| CVE-2013-6933 | — | — | 17.4% | Jan 23, 2014 | The parseRTSPRequestString function in Live Networks Live555 Streaming Media 2011.08.13 through 2013.11.25, as used in V... |
| CVE-2013-4152 | — | — | 26.3% | Jan 23, 2014 | The Spring OXM wrapper in Spring Framework before 3.2.4 and 4.0.0.M1, when using the JAXB marshaller, does not disable e... |
| CVE-2013-5371 | — | — | 0.4% | Jan 23, 2014 | The client in IBM Tivoli Storage Manager (TSM) 6.3.1 and 6.4.0 on Windows does not preserve permissions of Resilient Fil... |
| CVE-2013-7314 | — | — | 1.6% | Jan 23, 2014 | The OSPF implementation on NEC IP38X, IX1000, IX2000, and IX3000 routers does not consider the possibility of duplicate ... |
| CVE-2013-7313 | — | — | 1.1% | Jan 23, 2014 | The OSPF implementation in Juniper Junos through 13.x, JunosE, and ScreenOS through 6.3.x does not consider the possibil... |
| CVE-2013-7312 | — | — | 1.1% | Jan 23, 2014 | The OSPF implementation on Enterasys switches and routers does not consider the possibility of duplicate Link State ID v... |
| CVE-2013-7311 | — | — | 0.6% | Jan 23, 2014 | The OSPF implementation in Check Point Gaia OS R75.X and R76 and IPSO OS 6.2 R75.X and R76 does not consider the possibi... |
| CVE-2013-7310 | — | — | 0.8% | Jan 23, 2014 | The OSPF implementation on Yamaha routers does not consider the possibility of duplicate Link State ID values in Link St... |
| CVE-2013-7309 | — | — | 1.1% | Jan 23, 2014 | The OSPF implementation in Extreme Networks EXOS does not consider the possibility of duplicate Link State ID values in ... |
| CVE-2013-7308 | — | — | 0.6% | Jan 23, 2014 | The OSPF implementation on the D-Link DES-3810-28 switch with firmware R2.20.B017 does not consider the possibility of d... |
| CVE-2013-7307 | — | — | 0.9% | Jan 23, 2014 | The OSPF implementation on the Brocade Vyatta vRouter with software before 6.6R1 does not consider the possibility of du... |
| CVE-2013-7306 | — | — | 0.8% | Jan 23, 2014 | The OSPF implementation on Brocade routers does not consider the possibility of duplicate Link State ID values in Link S... |
| CVE-2013-6443 | — | — | 0.6% | Jan 23, 2014 | CloudForms 3.0 Management Engine before 5.2.1.6 allows remote attackers to bypass the Ruby on Rails protect_from_forgery... |
| CVE-2013-6448 | — | — | 1.4% | Jan 23, 2014 | The InterfaceGenerator handler in JBoss Seam Remoting in JBoss Seam 2 framework 2.3.1 and earlier, as used in JBoss Web ... |
| CVE-2013-6447 | — | — | 2.7% | Jan 23, 2014 | Multiple XML External Entity (XXE) vulnerabilities in the (1) ExecutionHandler, (2) PollHandler, and (3) SubscriptionHan... |
| CVE-2013-6412 | — | — | 0.4% | Jan 23, 2014 | The transform_save function in transform.c in Augeas 1.0.0 through 1.1.0 does not properly calculate the permission valu... |
Check if your code is affected by 2013 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now