2013 CVE Vulnerabilities

6,831 CVEs published in 2013.

CVE IDSeverityCVSSDescription
CVE-2013-7353MEDIUM6.5Integer overflow in the png_set_unknown_chunks function in libpng/pngset.c in libpng before 1.5.14beta08 allows context-...
CVE-2013-7375——SQL injection vulnerability in includes/classes/Authenticate.class.php in PHP-Fusion 7.02.01 through 7.02.05 allows remo...
CVE-2013-7034——The setCookieValue function in _lib/functions.global.inc.php in LiveZilla before 5.1.2.1 allows remote attackers to exec...
CVE-2013-7003——Multiple cross-site scripting (XSS) vulnerabilities in LiveZilla before 5.1.2.0 allow remote attackers to inject arbitra...
CVE-2013-6444——PyWBEM 0.7 and earlier does not verify that the server hostname matches a domain name in the subject's Common Name (CN) ...
CVE-2013-6418——PyWBEM 0.7 and earlier uses a separate connection to validate X.509 certificates, which allows man-in-the-middle attacke...
CVE-2013-4215——The IPXPING_COMMAND in contrib/check_ipxping.c in Nagios Plugins 1.4.16 allows local users to gain privileges via a syml...
CVE-2013-3736——Cross-site scripting (XSS) vulnerability in the MobileUI (aka RT-Extension-MobileUI) extension before 1.04 in Request Tr...
CVE-2013-1803——Multiple SQL injection vulnerabilities in PHP-Fusion before 7.02.06 allow remote attackers to execute arbitrary SQL comm...
CVE-2013-0350——tmp_smtp.c in pktstat 1.8.5 allows local users to overwrite arbitrary files via a symlink attack on /tmp/smtp.log.
CVE-2013-7061——Products/CMFPlone/CatalogTool.py in Plone 3.3 through 4.3.2 allows remote administrators to bypass restrictions and obta...
CVE-2013-7060——Products/CMFPlone/FactoryTool.py in Plone 3.3 through 4.3.2 allows remote attackers to obtain the installation path via ...
CVE-2013-7110——Transifex command-line client before 0.10 does not validate X.509 certificates for data transfer connections, which allo...
CVE-2013-2073——Transifex command-line client before 0.9 does not validate X.509 certificates, which allows man-in-the-middle attackers ...
CVE-2013-6323——Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Application Server (WAS) 7.x bef...
CVE-2013-7374——The Ubuntu Date and Time Indicator (aka indicator-datetime) 13.10.0+13.10.x before 13.10.0+13.10.20131023.2-0ubuntu1.1 d...
CVE-2013-4121——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ...
CVE-2013-1807——PHP-Fusion before 7.02.06 stores backup files with predictable filenames in an unrestricted directory under the web docu...
CVE-2013-1806——Multiple directory traversal vulnerabilities in PHP-Fusion before 7.02.06 allow remote authenticated users to include an...
CVE-2013-1805——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-1806. Reason: This issue was MERGED into CVE-201...
CVE-2013-6990——FortiGuard FortiAuthenticator before 3.0 allows remote administrators to gain privileges via the command line interface.
CVE-2013-6445——Cumin (aka MRG Management Console), as used in Red Hat Enterprise MRG 2.5, uses the DES-based crypt function to hash pas...
CVE-2013-7373——Android before 4.4 does not properly arrange for seeding of the OpenSSL PRNG, which makes it easier for attackers to def...
CVE-2013-7372——The engineNextBytes function in classlib/modules/security/src/main/java/common/org/apache/harmony/security/provider/cryp...
CVE-2013-1804——Multiple cross-site scripting (XSS) vulnerabilities in PHP-Fusion before 7.02.06 allow remote attackers to inject arbitr...

Check if your code is affected by 2013 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now