2013 CVE Vulnerabilities

6,830 CVEs published in 2013.

CVE IDSeverityCVSSDescription
CVE-2013-7375SQL injection vulnerability in includes/classes/Authenticate.class.php in PHP-Fusion 7.02.01 through 7.02.05 allows remo...
CVE-2013-7034The setCookieValue function in _lib/functions.global.inc.php in LiveZilla before 5.1.2.1 allows remote attackers to exec...
CVE-2013-7003Multiple cross-site scripting (XSS) vulnerabilities in LiveZilla before 5.1.2.0 allow remote attackers to inject arbitra...
CVE-2013-6444PyWBEM 0.7 and earlier does not verify that the server hostname matches a domain name in the subject's Common Name (CN) ...
CVE-2013-6418PyWBEM 0.7 and earlier uses a separate connection to validate X.509 certificates, which allows man-in-the-middle attacke...
CVE-2013-4215The IPXPING_COMMAND in contrib/check_ipxping.c in Nagios Plugins 1.4.16 allows local users to gain privileges via a syml...
CVE-2013-3736Cross-site scripting (XSS) vulnerability in the MobileUI (aka RT-Extension-MobileUI) extension before 1.04 in Request Tr...
CVE-2013-1803Multiple SQL injection vulnerabilities in PHP-Fusion before 7.02.06 allow remote attackers to execute arbitrary SQL comm...
CVE-2013-0350tmp_smtp.c in pktstat 1.8.5 allows local users to overwrite arbitrary files via a symlink attack on /tmp/smtp.log.
CVE-2013-7061Products/CMFPlone/CatalogTool.py in Plone 3.3 through 4.3.2 allows remote administrators to bypass restrictions and obta...
CVE-2013-7060Products/CMFPlone/FactoryTool.py in Plone 3.3 through 4.3.2 allows remote attackers to obtain the installation path via ...
CVE-2013-7110Transifex command-line client before 0.10 does not validate X.509 certificates for data transfer connections, which allo...
CVE-2013-2073Transifex command-line client before 0.9 does not validate X.509 certificates, which allows man-in-the-middle attackers ...
CVE-2013-6323Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Application Server (WAS) 7.x bef...
CVE-2013-7374The Ubuntu Date and Time Indicator (aka indicator-datetime) 13.10.0+13.10.x before 13.10.0+13.10.20131023.2-0ubuntu1.1 d...
CVE-2013-4121Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ...
CVE-2013-1807PHP-Fusion before 7.02.06 stores backup files with predictable filenames in an unrestricted directory under the web docu...
CVE-2013-1806Multiple directory traversal vulnerabilities in PHP-Fusion before 7.02.06 allow remote authenticated users to include an...
CVE-2013-1805Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-1806. Reason: This issue was MERGED into CVE-201...
CVE-2013-6990FortiGuard FortiAuthenticator before 3.0 allows remote administrators to gain privileges via the command line interface.
CVE-2013-6445Cumin (aka MRG Management Console), as used in Red Hat Enterprise MRG 2.5, uses the DES-based crypt function to hash pas...
CVE-2013-7373Android before 4.4 does not properly arrange for seeding of the OpenSSL PRNG, which makes it easier for attackers to def...
CVE-2013-7372The engineNextBytes function in classlib/modules/security/src/main/java/common/org/apache/harmony/security/provider/cryp...
CVE-2013-1804Multiple cross-site scripting (XSS) vulnerabilities in PHP-Fusion before 7.02.06 allow remote attackers to inject arbitr...
CVE-2013-7302Session fixation vulnerability in the Ubercart module 6.x-2.x before 6.x-2.13 and 7.x-3.x before 7.x-3.6 for Drupal, whe...

Check if your code is affected by 2013 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now