2013 CVE Vulnerabilities
6,830 CVEs published in 2013.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2013-7195 | — | — | 1.2% | Apr 18, 2014 | PHPFox 3.7.3 and 3.7.4 allows remote authenticated users to bypass intended "Only Me" restrictions and "like" a publicat... |
| CVE-2013-4279 | — | — | 1.8% | Apr 18, 2014 | imapsync 1.564 and earlier performs a release check by default, which sends sensitive information (imapsync, operating s... |
| CVE-2013-7369 | — | — | 1.3% | Apr 18, 2014 | SQL injection vulnerability in an unspecified DLL in the FSDBCom ActiveX control in F-Secure Anti-Virus for Microsoft Ex... |
| CVE-2013-4290 | — | — | 3.0% | Apr 18, 2014 | Stack-based buffer overflow in OpenJPEG before 1.5.2 allows remote attackers to have unspecified impact via unknown vect... |
| CVE-2013-4289 | — | — | 2.7% | Apr 18, 2014 | Multiple integer overflows in lib/openjp3d/jp3d.c in OpenJPEG before 1.5.2 allow remote attackers to have unspecified im... |
| CVE-2013-2143 | — | — | 48.2% | Apr 17, 2014 | The users controller in Katello 1.5.0-14 and earlier, and Red Hat Satellite, does not check authorization for the update... |
| CVE-2013-4694 | — | — | 17.2% | Apr 16, 2014 | Stack-based buffer overflow in gen_jumpex.dll in Winamp before 5.64 Build 3418 allows remote attackers to cause a denial... |
| CVE-2013-1764 | — | — | 0.4% | Apr 16, 2014 | The Zypper (aka zypp) backend in PackageKit before 0.8.8 allows local users to downgrade packages via the "install updat... |
| CVE-2013-4768 | — | — | 1.3% | Apr 16, 2014 | The web services APIs in Eucalyptus 2.0 through 3.4.1 allow remote attackers to cause a denial of service via vectors re... |
| CVE-2013-6456 | — | — | 0.6% | Apr 15, 2014 | The LXC driver (lxc/lxc_driver.c) in libvirt 1.0.1 through 1.2.1 allows local users to (1) delete arbitrary host devices... |
| CVE-2013-7368 | — | — | 3.2% | Apr 15, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in Gnew 2013.1 allow remote attackers to inject arbitrary web script... |
| CVE-2013-5705 | — | — | 2.6% | Apr 15, 2014 | apache2/modsecurity.c in ModSecurity before 2.7.6 allows remote attackers to bypass rules by using chunked transfer codi... |
| CVE-2013-5704 | — | — | 60.2% | Apr 15, 2014 | The mod_headers module in the Apache HTTP Server 2.2.22 allows remote attackers to bypass "RequestHeader unset" directiv... |
| CVE-2013-6216 | — | — | 0.5% | Apr 12, 2014 | Unspecified vulnerability in HP Array Configuration Utility, Array Diagnostics Utility, ProLiant Array Diagnostics, and ... |
| CVE-2013-2828 | — | — | 0.3% | Apr 12, 2014 | The DNP Master Driver in the OSIsoft PI Interface before 3.1.2.54 for DNP3 allows physically proximate attackers to caus... |
| CVE-2013-2809 | — | — | 1.5% | Apr 12, 2014 | The DNP Master Driver in the OSIsoft PI Interface before 3.1.2.54 for DNP3 allows remote attackers to cause a denial of ... |
| CVE-2013-6369 | — | — | 3.4% | Apr 11, 2014 | Stack-based buffer overflow in the jbg_dec_in function in libjbig/jbig.c in JBIG-KIT before 2.1 allows remote attackers ... |
| CVE-2013-4795 | — | — | 1.4% | Apr 11, 2014 | Cross-site scripting (XSS) vulnerability in the Submitters list in Review Board 1.6.x before 1.6.18 and 1.7.x before 1.7... |
| CVE-2013-2708 | — | — | 1.0% | Apr 11, 2014 | Cross-site request forgery (CSRF) vulnerability in the Content Slide plugin 1.4.2 for WordPress allows remote attackers ... |
| CVE-2013-2706 | — | — | 1.0% | Apr 11, 2014 | Cross-site request forgery (CSRF) vulnerability in the Stream Video Player plugin 1.4.0 for WordPress allows remote atta... |
| CVE-2013-7367 | — | — | 1.5% | Apr 10, 2014 | SAP Enterprise Portal does not properly restrict access to the Federation configuration pages, which allows remote attac... |
| CVE-2013-7366 | — | — | 1.7% | Apr 10, 2014 | The SAP Software Deployment Manager (SDM), in certain unspecified conditions, allows remote attackers to cause a denial ... |
| CVE-2013-7365 | — | — | 1.3% | Apr 10, 2014 | Cross-site scripting (XSS) vulnerability in SAP Enterprise Portal allows remote attackers to inject arbitrary web script... |
| CVE-2013-7364 | — | — | 1.5% | Apr 10, 2014 | An unspecified J2EE core service in the J2EE Engine in SAP NetWeaver does not properly restrict access, which allows rem... |
| CVE-2013-7363 | — | — | 1.5% | Apr 10, 2014 | Unspecified vulnerability in the Diagnostics (SMD) agent in SAP Solution Manager allows remote attackers to obtain sensi... |
Check if your code is affected by 2013 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now