2013 CVE Vulnerabilities
6,830 CVEs published in 2013.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2013-6948 | — | — | 1.6% | Feb 22, 2014 | The peerAddresses API in the Belkin WeMo Home Automation firmware before 3949 allows remote attackers to read arbitrary ... |
| CVE-2013-6734 | — | — | 1.0% | Feb 22, 2014 | IBM WebSphere eXtreme Scale Client 7.1 through 8.6.0.4 does not properly isolate the cached data of different users, whi... |
| CVE-2013-6732 | — | — | 1.4% | Feb 22, 2014 | Cross-site scripting (XSS) vulnerability in the server in IBM Cognos Business Intelligence (BI) 8.4.1, 10.1 before IF6, ... |
| CVE-2013-4420 | — | — | 3.3% | Feb 20, 2014 | Multiple directory traversal vulnerabilities in the (1) tar_extract_glob and (2) tar_extract_all functions in libtar 1.2... |
| CVE-2013-6396 | — | — | 0.7% | Feb 18, 2014 | The OpenStack Python client library for Swift (python-swiftclient) 1.0 through 1.9.0 does not verify X.509 certificates ... |
| CVE-2013-7328 | — | — | 1.5% | Feb 18, 2014 | Multiple integer signedness errors in the gdImageCrop function in ext/gd/gd.c in PHP 5.5.x before 5.5.9 allow remote att... |
| CVE-2013-7327 | — | — | 2.7% | Feb 18, 2014 | The gdImageCrop function in ext/gd/gd.c in PHP 5.5.x before 5.5.9 does not check return values, which allows remote atta... |
| CVE-2013-7226 | — | — | 6.7% | Feb 18, 2014 | Integer overflow in the gdImageCrop function in ext/gd/gd.c in PHP 5.5.x before 5.5.9 allows remote attackers to cause a... |
| CVE-2013-6674 | — | — | 7.7% | Feb 17, 2014 | Cross-site scripting (XSS) vulnerability in Mozilla Thunderbird 17.x through 17.0.8, Thunderbird ESR 17.x through 17.0.1... |
| CVE-2013-1070 | — | — | 2.4% | Feb 17, 2014 | Cross-site scripting (XSS) vulnerability in the API in Ubuntu Metal as a Service (MaaS) 1.2 and 1.4 allows remote attack... |
| CVE-2013-1069 | — | — | 0.4% | Feb 17, 2014 | Ubuntu Metal as a Service (MaaS) 1.2 and 1.4 uses world-readable permissions for txlongpoll.yaml, which allows local use... |
| CVE-2013-6167 | — | — | 1.6% | Feb 15, 2014 | Mozilla Firefox through 27 sends HTTP Cookie headers without first validating that they have the required character-set ... |
| CVE-2013-6166 | — | — | 1.9% | Feb 15, 2014 | Google Chrome before 29 sends HTTP Cookie headers without first validating that they have the required character-set res... |
| CVE-2013-4737 | — | — | 1.4% | Feb 15, 2014 | The CONFIG_STRICT_MEMORY_RWX implementation for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Andro... |
| CVE-2013-0346 | — | — | 0.7% | Feb 15, 2014 | Apache Tomcat 7.x uses world-readable permissions for the log directory and its files, which might allow local users to ... |
| CVE-2013-7326 | — | — | 2.1% | Feb 14, 2014 | Cross-site scripting (XSS) vulnerability in vTiger CRM 5.4.0 allows remote attackers to inject arbitrary web script or H... |
| CVE-2013-7032 | — | — | 1.8% | Feb 14, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in the web based operator client in LiveZilla before 5.1.2.1 allow r... |
| CVE-2013-5351 | — | — | 5.0% | Feb 14, 2014 | Heap-based buffer overflow in IrfanView before 4.37 allows remote attackers to execute arbitrary code via the LZW code s... |
| CVE-2013-4499 | — | — | 1.1% | Feb 14, 2014 | Cross-site scripting (XSS) vulnerability in the Bean module 7.x-1.x before 7.x-1.5 for Drupal allows remote attackers to... |
| CVE-2013-6492 | — | — | 4.0% | Feb 14, 2014 | The Piranha Configuration Tool in Piranha 0.8.6 does not properly restrict access to webpages, which allows remote attac... |
| CVE-2013-6441 | — | — | 0.5% | Feb 14, 2014 | The lxc-sshd template (templates/lxc-sshd.in) in LXC before 1.0.0.beta2 uses read-write permissions when mounting /sbin/... |
| CVE-2013-6440 | — | — | 2.8% | Feb 14, 2014 | The (1) BasicParserPool, (2) StaticBasicParserPool, (3) XML Decrypter, and (4) SAML Decrypter in Shibboleth OpenSAML-Jav... |
| CVE-2013-4415 | — | — | 1.7% | Feb 14, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in Spacewalk and Red Hat Network (RHN) Satellite 5.6 allow remote at... |
| CVE-2013-1871 | — | — | 1.6% | Feb 14, 2014 | Cross-site scripting (XSS) vulnerability in account/EditAddress.do in Spacewalk and Red Hat Network (RHN) Satellite 5.6 ... |
| CVE-2013-6743 | — | — | 0.9% | Feb 14, 2014 | Cross-site scripting (XSS) vulnerability in the Meeting Server in IBM Sametime 8.5.2 through 8.5.2.1 and 9.x through 9.0... |
Check if your code is affected by 2013 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now