2013 CVE Vulnerabilities

6,831 CVEs published in 2013.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2013-6181——EMC Watch4Net before 6.3 stores cleartext polled-device passwords in the installation repository, which allows local use...
CVE-2013-6006——Cybozu Garoon 3.5 through 3.7 SP2 allows remote attackers to bypass Keitai authentication via a modified user ID in a re...
CVE-2013-1096——Cross-site scripting (XSS) vulnerability in the Roles Based Provisioning Module 4.0.2 before Field Patch D for Novell Id...
CVE-2013-2179——X.Org xdm 1.1.10, 1.1.11, and possibly other versions, when performing authentication using certain implementations of t...
CVE-2013-2030——keystone/middleware/auth_token.py in OpenStack Nova Folsom, Grizzly, and Havana uses an insecure temporary directory for...
CVE-2013-7217——Unspecified vulnerability in Zimbra Collaboration Server 7.2.5 and earlier, and 8.0.x through 8.0.5, has "critical" impa...
CVE-2013-7216——Multiple SQL injection vulnerabilities in Classifieds Creator 2.0 allow remote attackers to execute arbitrary SQL comman...
CVE-2013-6388——Cross-site scripting (XSS) vulnerability in the Color module in Drupal 7.x before 7.24 allows remote attackers to inject...
CVE-2013-6387——Cross-site scripting (XSS) vulnerability in the Image module in Drupal 7.x before 7.24 allows remote authenticated users...
CVE-2013-4554——Xen 3.0.3 through 4.1.x (possibly 4.1.6.1), 4.2.x (possibly 4.2.3), and 4.3.x (possibly 4.3.1) does not properly prevent...
CVE-2013-4553——The XEN_DOMCTL_getmemlist hypercall in Xen 3.4.x through 4.3.x (possibly 4.3.1) does not always obtain the page_alloc_lo...
CVE-2013-4452——Red Hat JBoss Operations Network 3.1.2 uses world-readable permissions for the (1) server and (2) agent configuration fi...
CVE-2013-4358——libavcodec/h264.c in FFmpeg before 0.11.4 allows remote attackers to cause a denial of service (crash) via vectors relat...
CVE-2013-6795——The Updater in Rackspace Openstack Windows Guest Agent for XenServer before 1.2.6.0 allows remote attackers to execute a...
CVE-2013-6403——The admin page in ownCloud before 5.0.13 allows remote attackers to bypass intended access restrictions via unspecified ...
CVE-2013-4550——Bip before 0.8.9, when running as a daemon, writes SSL handshake errors to an unexpected file descriptor that was previo...
CVE-2013-7102——Multiple unrestricted file upload vulnerabilities in (1) media-upload.php, (2) media-upload-lncthumb.php, and (3) media-...
CVE-2013-7081——The (old) Form Content Element component in TYPO3 4.5.0 through 4.5.31, 4.7.0 through 4.7.16, 6.0.0 through 6.0.11, and ...
CVE-2013-7080——The creating record functionality in Extension table administration library (feuser_adminLib.inc) in TYPO3 4.5.0 through...
CVE-2013-7079——Open redirect vulnerability in the OpenID extension in TYPO3 4.5.0 through 4.5.31, 4.7.0 through 4.7.16, 6.0.0 through 6...
CVE-2013-7075——The Content Editing Wizards component in TYPO3 4.5.0 through 4.5.31, 4.7.0 through 4.7.16, 6.0.0 through 6.0.11, and 6.1...
CVE-2013-7073——The Content Editing Wizards component in TYPO3 4.5.0 through 4.5.31, 4.7.0 through 4.7.16, 6.0.0 through 6.0.11, and 6.1...
CVE-2013-7049——Stack-based buffer overflow in fish.cpp in the Fish plugin for ZNC, as used in ZNC for Windows (znc-msvc) 0.206 and earl...
CVE-2013-4424——Multiple cross-site scripting (XSS) vulnerabilities in the GateIn Portal component in Red Hat JBoss Portal 6.1.0 allow r...
CVE-2013-3709——WebYaST 1.3 uses weak permissions for config/initializers/secret_token.rb, which allows local users to gain privileges b...

Check if your code is affected by 2013 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now