2013 CVE Vulnerabilities
6,830 CVEs published in 2013.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2013-7305 | — | — | 1.0% | Jan 22, 2014 | fpw.php in e107 through 1.0.4 does not check the user_ban field, which makes it easier for remote attackers to reset pas... |
| CVE-2013-7304 | — | — | 0.6% | Jan 22, 2014 | Check Point Endpoint Security MI Server through R73 3.0.0 HFA2.5 does not configure X.509 certificate validation for cli... |
| CVE-2013-2750 | — | — | 3.2% | Jan 22, 2014 | Cross-site scripting (XSS) vulnerability in e107_plugins/content/handlers/content_preset.php in e107 before 1.0.3 allows... |
| CVE-2013-6746 | — | — | 1.2% | Jan 22, 2014 | Cross-site scripting (XSS) vulnerability in FileNet P8 Platform Documentation Installable Info Center 4.5.1 through 5.2.... |
| CVE-2013-6343 | — | — | 9.7% | Jan 22, 2014 | Multiple buffer overflows in web.c in httpd on the ASUS RT-N56U and RT-AC66U routers with firmware 3.0.0.4.374_979 allow... |
| CVE-2013-5987 | — | — | 0.4% | Jan 21, 2014 | Unspecified vulnerability in NVIDIA graphics driver Release 331, 325, 319, 310, and 304 allows local users to bypass int... |
| CVE-2013-5986 | — | — | 1.8% | Jan 21, 2014 | Unspecified vulnerability in NVIDIA graphics driver Release 331, 325, 319, 310, and 304 has unknown impact and attack ve... |
| CVE-2013-4884 | — | — | 4.3% | Jan 21, 2014 | Cross-site scripting (XSS) vulnerability in McAfee SuperScan 4.0 allows remote attackers to inject arbitrary web script ... |
| CVE-2013-4160 | — | — | 2.8% | Jan 21, 2014 | Little CMS (lcms2) before 2.5, as used in OpenJDK 7 and possibly other products, allows remote attackers to cause a deni... |
| CVE-2013-2152 | — | — | 0.4% | Jan 21, 2014 | Unquoted Windows search path vulnerability in the SPICE service, as used in Red Hat Enterprise Virtualization (RHEV) 3.2... |
| CVE-2013-2151 | — | — | 0.4% | Jan 21, 2014 | Unquoted Windows search path vulnerability in Red Hat Enterprise Virtualization (RHEV) 3 and 3.2 allows local users to g... |
| CVE-2013-2104 | — | — | 2.1% | Jan 21, 2014 | python-keystoneclient before 0.2.4, as used in OpenStack Keystone (Folsom), does not properly check expiry for PKI token... |
| CVE-2013-1923 | — | — | 1.0% | Jan 21, 2014 | rpc-gssd in nfs-utils before 1.2.8 performs reverse DNS resolution for server names during GSSAPI authentication, which ... |
| CVE-2013-1769 | — | — | 2.4% | Jan 21, 2014 | A certain hashing algorithm in Telepathy Gabble 0.16.x before 0.16.5 and 0.17.x before 0.17.3 allows remote attackers to... |
| CVE-2013-1361 | — | — | 6.4% | Jan 21, 2014 | Untrusted search path vulnerability in Lenovo Thinkpad Bluetooth with Enhanced Data Rate Software 6.4.0.2900 and earlier... |
| CVE-2013-0485 | — | — | 2.4% | Jan 21, 2014 | Unspecified vulnerability in IBM Java SDK 7 before SR4-FP1, 6 before SR13-FP1, 5.0 before SR16-FP1, and 1.4.2 before SR1... |
| CVE-2013-0340 | — | — | 19.4% | Jan 21, 2014 | expat before version 2.4.0 does not properly handle entities expansion unless an application developer uses the XML_SetE... |
| CVE-2013-0339 | — | — | 4.4% | Jan 21, 2014 | libxml2 through 2.9.1 does not properly handle external entities expansion unless an application developer uses the xmlS... |
| CVE-2013-0157 | — | — | 0.4% | Jan 21, 2014 | (a) mount and (b) umount in util-linux 2.14.1, 2.17.2, and probably other versions allow local users to determine the ex... |
| CVE-2013-7219 | — | — | 2.4% | Jan 21, 2014 | SQL injection vulnerability in vote.php in the 2Glux Sexy Polling (com_sexypolling) component before 1.0.9 for Joomla! a... |
| CVE-2013-6922 | — | — | 1.5% | Jan 21, 2014 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Seagate BlackArmor NAS 220 devices with firmware sg200... |
| CVE-2013-4200 | — | — | 2.4% | Jan 21, 2014 | The isURLInPortal method in the URLTool class in in_portal.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x t... |
| CVE-2013-2594 | — | — | 2.6% | Jan 21, 2014 | SQL injection vulnerability in reports/calldiary.php in Hornbill Supportworks ITSM 1.0.0 through 3.4.14 allows remote at... |
| CVE-2013-6872 | — | — | 2.5% | Jan 21, 2014 | SQL injection vulnerability in managetimetracker.php in Collabtive before 1.2 allows remote authenticated users to execu... |
| CVE-2013-6305 | — | — | 0.6% | Jan 21, 2014 | IBM Platform Symphony 5.2 before build 229037 and 6.1.0.1 before build 229073 uses the same credentials encryption key a... |
Check if your code is affected by 2013 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now