2013 CVE Vulnerabilities

6,831 CVEs published in 2013.

CVE IDSeverityCVSSDescription
CVE-2013-7196——static/ajax.php in PHPFox 3.7.3, 3.7.4, and 3.7.5 allows remote authenticated users to bypass intended "Only Me" restric...
CVE-2013-7195——PHPFox 3.7.3 and 3.7.4 allows remote authenticated users to bypass intended "Only Me" restrictions and "like" a publicat...
CVE-2013-4279——imapsync 1.564 and earlier performs a release check by default, which sends sensitive information (imapsync, operating s...
CVE-2013-7369——SQL injection vulnerability in an unspecified DLL in the FSDBCom ActiveX control in F-Secure Anti-Virus for Microsoft Ex...
CVE-2013-4290——Stack-based buffer overflow in OpenJPEG before 1.5.2 allows remote attackers to have unspecified impact via unknown vect...
CVE-2013-4289——Multiple integer overflows in lib/openjp3d/jp3d.c in OpenJPEG before 1.5.2 allow remote attackers to have unspecified im...
CVE-2013-2143——The users controller in Katello 1.5.0-14 and earlier, and Red Hat Satellite, does not check authorization for the update...
CVE-2013-4694——Stack-based buffer overflow in gen_jumpex.dll in Winamp before 5.64 Build 3418 allows remote attackers to cause a denial...
CVE-2013-1764——The Zypper (aka zypp) backend in PackageKit before 0.8.8 allows local users to downgrade packages via the "install updat...
CVE-2013-4768——The web services APIs in Eucalyptus 2.0 through 3.4.1 allow remote attackers to cause a denial of service via vectors re...
CVE-2013-6456——The LXC driver (lxc/lxc_driver.c) in libvirt 1.0.1 through 1.2.1 allows local users to (1) delete arbitrary host devices...
CVE-2013-7368——Multiple cross-site scripting (XSS) vulnerabilities in Gnew 2013.1 allow remote attackers to inject arbitrary web script...
CVE-2013-5705——apache2/modsecurity.c in ModSecurity before 2.7.6 allows remote attackers to bypass rules by using chunked transfer codi...
CVE-2013-5704——The mod_headers module in the Apache HTTP Server 2.2.22 allows remote attackers to bypass "RequestHeader unset" directiv...
CVE-2013-6216——Unspecified vulnerability in HP Array Configuration Utility, Array Diagnostics Utility, ProLiant Array Diagnostics, and ...
CVE-2013-2828——The DNP Master Driver in the OSIsoft PI Interface before 3.1.2.54 for DNP3 allows physically proximate attackers to caus...
CVE-2013-2809——The DNP Master Driver in the OSIsoft PI Interface before 3.1.2.54 for DNP3 allows remote attackers to cause a denial of ...
CVE-2013-6369——Stack-based buffer overflow in the jbg_dec_in function in libjbig/jbig.c in JBIG-KIT before 2.1 allows remote attackers ...
CVE-2013-4795——Cross-site scripting (XSS) vulnerability in the Submitters list in Review Board 1.6.x before 1.6.18 and 1.7.x before 1.7...
CVE-2013-2708——Cross-site request forgery (CSRF) vulnerability in the Content Slide plugin 1.4.2 for WordPress allows remote attackers ...
CVE-2013-2706——Cross-site request forgery (CSRF) vulnerability in the Stream Video Player plugin 1.4.0 for WordPress allows remote atta...
CVE-2013-7367——SAP Enterprise Portal does not properly restrict access to the Federation configuration pages, which allows remote attac...
CVE-2013-7366——The SAP Software Deployment Manager (SDM), in certain unspecified conditions, allows remote attackers to cause a denial ...
CVE-2013-7365——Cross-site scripting (XSS) vulnerability in SAP Enterprise Portal allows remote attackers to inject arbitrary web script...
CVE-2013-7364——An unspecified J2EE core service in the J2EE Engine in SAP NetWeaver does not properly restrict access, which allows rem...

Check if your code is affected by 2013 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now