2013 CVE Vulnerabilities
6,830 CVEs published in 2013.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2013-6890 | — | — | 8.9% | Dec 23, 2013 | denyhosts 2.6 uses an incorrect regular expression when analyzing authentication logs, which allows remote attackers to ... |
| CVE-2013-6449 | — | — | 21.2% | Dec 23, 2013 | The ssl_get_algorithm2 function in ssl/s3_lib.c in OpenSSL before 1.0.2 obtains a certain version number from an incorre... |
| CVE-2013-6439 | — | — | 1.6% | Dec 23, 2013 | Candlepin in Red Hat Subscription Asset Manager 1.0 through 1.3 uses a weak authentication scheme when the configuration... |
| CVE-2013-6422 | — | — | 2.8% | Dec 23, 2013 | The GnuTLS backend in libcurl 7.21.4 through 7.33.0, when disabling digital signature verification (CURLOPT_SSL_VERIFYPE... |
| CVE-2013-5420 | — | — | 0.9% | Dec 23, 2013 | The IMS server before Ifix 6 in IBM Security Access Manager for Enterprise Single Sign-On (ISAM ESSO) 8.2 allows remote ... |
| CVE-2013-4549 | — | — | 3.1% | Dec 23, 2013 | QXmlSimpleReader in Qt before 5.2 allows context-dependent attackers to cause a denial of service (memory consumption) v... |
| CVE-2013-4461 | — | — | 1.9% | Dec 23, 2013 | SQL injection vulnerability in the web interface for cumin in Red Hat Enterprise MRG Grid 2.4 allows remote attackers to... |
| CVE-2013-4414 | — | — | 1.8% | Dec 23, 2013 | Cross-site scripting (XSS) vulnerability in the web interface for cumin in Red Hat Enterprise MRG Grid 2.4 allows remote... |
| CVE-2013-4405 | — | — | 1.0% | Dec 23, 2013 | Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface for cumin in Red Hat Enterprise MRG Grid... |
| CVE-2013-4404 | — | — | 1.9% | Dec 23, 2013 | cumin in Red Hat Enterprise MRG Grid 2.4 does not properly enforce user roles, which allows remote authenticated users t... |
| CVE-2013-2629 | — | — | 1.4% | Dec 23, 2013 | Leed (Light Feed), possibly before 1.5 Stable, allows remote attackers to bypass authorization via vectors related to th... |
| CVE-2013-5973 | — | — | 0.4% | Dec 23, 2013 | VMware ESXi 4.0 through 5.5 and ESX 4.0 and 4.1 allow local users to read or modify arbitrary files by leveraging the Vi... |
| CVE-2013-6745 | — | — | 0.9% | Dec 22, 2013 | Cross-site scripting (XSS) vulnerability in the IMS server before Ifix 6 in IBM Security Access Manager for Enterprise S... |
| CVE-2013-6735 | — | — | 3.6% | Dec 22, 2013 | IBM WebSphere Portal 6.0.0.x through 6.0.0.1, 6.0.1.x through 6.0.1.7, 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1... |
| CVE-2013-6723 | — | — | 1.7% | Dec 22, 2013 | IBM WebSphere Portal 8.0.0.1 before CF09 does not properly handle references in compute="always" Web Content Manager (WC... |
| CVE-2013-6328 | — | — | 1.2% | Dec 22, 2013 | Cross-site scripting (XSS) vulnerability in the Web Content Manager (WCM) UI in IBM WebSphere Portal 6.1.0.x through 6.1... |
| CVE-2013-6316 | — | — | 1.2% | Dec 22, 2013 | IBM WebSphere Portal 7.0.0.x before 7.0.0.2 CF26 and 8.0.0.x before 8.0.0.1 CF09 does not properly handle content-select... |
| CVE-2013-5421 | — | — | 0.9% | Dec 22, 2013 | Cross-site scripting (XSS) vulnerability in the IMS server before Ifix 6 in IBM Security Access Manager for Enterprise S... |
| CVE-2013-4012 | — | — | 1.1% | Dec 22, 2013 | IBM WebSphere Portal 8.0.0.x before 8.0.0.1 CF09, when Content Template Catalog 4.0 is used, does not require administra... |
| CVE-2013-3705 | — | — | 0.3% | Dec 22, 2013 | The VBA32 AntiRootKit component for Novell Client 2 SP3 before IR5 on Windows allows local users to cause a denial of se... |
| CVE-2013-6995 | — | — | — | Dec 21, 2013 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2013-6978 | — | — | 2.1% | Dec 21, 2013 | The disaster recovery system (DRS) component in Cisco Unified Communications Manager (UCM) 9.1(1) and earlier allows rem... |
| CVE-2013-6196 | — | — | 1.8% | Dec 21, 2013 | Cross-site scripting (XSS) vulnerability in HP Autonomy Ultraseek 5 allows remote authenticated users to inject arbitrar... |
| CVE-2013-5413 | — | — | 1.3% | Dec 21, 2013 | IBM Sterling B2B Integrator 5.2 and Sterling File Gateway 2.2 do not invalidate a session upon a logout action, which al... |
| CVE-2013-5411 | — | — | 1.2% | Dec 21, 2013 | IBM Sterling B2B Integrator 5.2 and Sterling File Gateway 2.2 allow remote attackers to inject links and trigger uninten... |
Check if your code is affected by 2013 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now