2013 CVE Vulnerabilities
6,830 CVEs published in 2013.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2013-6006 | — | — | 2.0% | Dec 28, 2013 | Cybozu Garoon 3.5 through 3.7 SP2 allows remote attackers to bypass Keitai authentication via a modified user ID in a re... |
| CVE-2013-1096 | — | — | 2.0% | Dec 28, 2013 | Cross-site scripting (XSS) vulnerability in the Roles Based Provisioning Module 4.0.2 before Field Patch D for Novell Id... |
| CVE-2013-2179 | — | — | 2.4% | Dec 27, 2013 | X.Org xdm 1.1.10, 1.1.11, and possibly other versions, when performing authentication using certain implementations of t... |
| CVE-2013-2030 | — | — | 0.2% | Dec 27, 2013 | keystone/middleware/auth_token.py in OpenStack Nova Folsom, Grizzly, and Havana uses an insecure temporary directory for... |
| CVE-2013-7217 | — | — | 2.9% | Dec 26, 2013 | Unspecified vulnerability in Zimbra Collaboration Server 7.2.5 and earlier, and 8.0.x through 8.0.5, has "critical" impa... |
| CVE-2013-7216 | — | — | 1.3% | Dec 24, 2013 | Multiple SQL injection vulnerabilities in Classifieds Creator 2.0 allow remote attackers to execute arbitrary SQL comman... |
| CVE-2013-6388 | — | — | 1.8% | Dec 24, 2013 | Cross-site scripting (XSS) vulnerability in the Color module in Drupal 7.x before 7.24 allows remote attackers to inject... |
| CVE-2013-6387 | — | — | 1.4% | Dec 24, 2013 | Cross-site scripting (XSS) vulnerability in the Image module in Drupal 7.x before 7.24 allows remote authenticated users... |
| CVE-2013-4554 | — | — | 0.6% | Dec 24, 2013 | Xen 3.0.3 through 4.1.x (possibly 4.1.6.1), 4.2.x (possibly 4.2.3), and 4.3.x (possibly 4.3.1) does not properly prevent... |
| CVE-2013-4553 | — | — | 0.6% | Dec 24, 2013 | The XEN_DOMCTL_getmemlist hypercall in Xen 3.4.x through 4.3.x (possibly 4.3.1) does not always obtain the page_alloc_lo... |
| CVE-2013-4452 | — | — | 0.4% | Dec 24, 2013 | Red Hat JBoss Operations Network 3.1.2 uses world-readable permissions for the (1) server and (2) agent configuration fi... |
| CVE-2013-4358 | — | — | 1.3% | Dec 24, 2013 | libavcodec/h264.c in FFmpeg before 0.11.4 allows remote attackers to cause a denial of service (crash) via vectors relat... |
| CVE-2013-6795 | — | — | 5.3% | Dec 24, 2013 | The Updater in Rackspace Openstack Windows Guest Agent for XenServer before 1.2.6.0 allows remote attackers to execute a... |
| CVE-2013-6403 | — | — | 2.1% | Dec 24, 2013 | The admin page in ownCloud before 5.0.13 allows remote attackers to bypass intended access restrictions via unspecified ... |
| CVE-2013-4550 | — | — | 2.2% | Dec 24, 2013 | Bip before 0.8.9, when running as a daemon, writes SSL handshake errors to an unexpected file descriptor that was previo... |
| CVE-2013-7102 | — | — | 14.8% | Dec 23, 2013 | Multiple unrestricted file upload vulnerabilities in (1) media-upload.php, (2) media-upload-lncthumb.php, and (3) media-... |
| CVE-2013-7081 | — | — | 1.0% | Dec 23, 2013 | The (old) Form Content Element component in TYPO3 4.5.0 through 4.5.31, 4.7.0 through 4.7.16, 6.0.0 through 6.0.11, and ... |
| CVE-2013-7080 | — | — | 1.2% | Dec 23, 2013 | The creating record functionality in Extension table administration library (feuser_adminLib.inc) in TYPO3 4.5.0 through... |
| CVE-2013-7079 | — | — | 1.2% | Dec 23, 2013 | Open redirect vulnerability in the OpenID extension in TYPO3 4.5.0 through 4.5.31, 4.7.0 through 4.7.16, 6.0.0 through 6... |
| CVE-2013-7075 | — | — | 1.3% | Dec 23, 2013 | The Content Editing Wizards component in TYPO3 4.5.0 through 4.5.31, 4.7.0 through 4.7.16, 6.0.0 through 6.0.11, and 6.1... |
| CVE-2013-7073 | — | — | 1.3% | Dec 23, 2013 | The Content Editing Wizards component in TYPO3 4.5.0 through 4.5.31, 4.7.0 through 4.7.16, 6.0.0 through 6.0.11, and 6.1... |
| CVE-2013-7049 | — | — | 1.7% | Dec 23, 2013 | Stack-based buffer overflow in fish.cpp in the Fish plugin for ZNC, as used in ZNC for Windows (znc-msvc) 0.206 and earl... |
| CVE-2013-4424 | — | — | 1.0% | Dec 23, 2013 | Multiple cross-site scripting (XSS) vulnerabilities in the GateIn Portal component in Red Hat JBoss Portal 6.1.0 allow r... |
| CVE-2013-3709 | — | — | 0.5% | Dec 23, 2013 | WebYaST 1.3 uses weak permissions for config/initializers/secret_token.rb, which allows local users to gain privileges b... |
| CVE-2013-6979 | — | — | 3.6% | Dec 23, 2013 | The VTY authentication implementation in Cisco IOS XE 03.02.xxSE and 03.03.xxSE incorrectly relies on the Linux-IOS inte... |
Check if your code is affected by 2013 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now