2013 CVE Vulnerabilities
6,830 CVEs published in 2013.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2013-6883 | — | — | 2.5% | Dec 17, 2013 | Cross-site request forgery (CSRF) vulnerability in CRU Ditto Forensic FieldStation with firmware before 2013Oct15a allow... |
| CVE-2013-6882 | — | — | 3.5% | Dec 17, 2013 | Multiple cross-site scripting (XSS) vulnerabilities in CRU Ditto Forensic FieldStation with firmware 2013Oct15a and earl... |
| CVE-2013-7128 | — | — | 0.3% | Dec 17, 2013 | Valve Bug Reporter in the valve-bugreporter package 2.10+bsos1 in Valve SteamOS Beta stores cleartext credentials in a .... |
| CVE-2013-7127 | — | — | 0.4% | Dec 17, 2013 | Apple Safari 6.0.5 on Mac OS X 10.7.5 and 10.8.5 stores cleartext credentials in LastSession.plist, which allows local u... |
| CVE-2013-6733 | — | — | 1.4% | Dec 17, 2013 | Cross-site scripting (XSS) vulnerability in the Web Application in the Classic Meeting Server in IBM Sametime 7.5.1.2 th... |
| CVE-2013-6721 | — | — | 1.1% | Dec 17, 2013 | Cross-site scripting (XSS) vulnerability in IBM WebSphere Service Registry and Repository (WSRR) 7.5.x before 7.5.0.4 an... |
| CVE-2013-6329 | — | — | 3.2% | Dec 17, 2013 | IBM Global Security Kit (aka GSKit), as used in Content Manager OnDemand 8.5 and 9.0 and other products, allows remote a... |
| CVE-2013-6327 | — | — | 0.9% | Dec 17, 2013 | Cross-site scripting (XSS) vulnerability in the HTTP Option in IBM Sterling Connect:Enterprise 1.3 before 1.3.0.2 iFix 1... |
| CVE-2013-6193 | — | — | 5.9% | Dec 17, 2013 | Unspecified vulnerability on HP LaserJet M1522n and M2727; LaserJet Pro 100, 300, 400, CM1415fnw, CP1*, M121*, M1536dnf,... |
| CVE-2013-6038 | — | — | 2.6% | Dec 17, 2013 | Stack-based buffer overflow in Trimble SketchUp Viewer 13.0.4124 allows remote attackers to execute arbitrary code via a... |
| CVE-2013-2816 | — | — | 0.3% | Dec 17, 2013 | The DNP3 component in Cooper Power Systems SMP 4, 4/DP, and 16 gateways allows physically proximate attackers to cause a... |
| CVE-2013-2814 | — | — | 1.3% | Dec 17, 2013 | Cooper Power Systems Cybectec DNP3 Master OPC Server allows remote attackers to cause a denial of service (unhandled exc... |
| CVE-2013-2813 | — | — | 1.3% | Dec 17, 2013 | The DNP3 component in Cooper Power Systems SMP 4, 4/DP, and 16 gateways allows remote attackers to cause a denial of ser... |
| CVE-2013-6966 | — | — | 2.1% | Dec 17, 2013 | Open redirect vulnerability in Cisco WebEx Training Center allows remote attackers to redirect users to arbitrary web si... |
| CVE-2013-6926 | — | — | 1.5% | Dec 17, 2013 | The integrated HTTPS server in Siemens RuggedCom ROS before 3.12.2 allows remote authenticated users to bypass intended ... |
| CVE-2013-6925 | — | — | 1.9% | Dec 17, 2013 | The integrated HTTPS server in Siemens RuggedCom ROS before 3.12.2 allows remote attackers to hijack web sessions by pre... |
| CVE-2013-6420 | — | — | 34.8% | Dec 17, 2013 | The asn1_time_to_time_t function in ext/openssl/openssl.c in PHP before 5.3.28, 5.4.x before 5.4.23, and 5.5.x before 5.... |
| CVE-2013-6192 | — | — | 1.0% | Dec 17, 2013 | Cross-site request forgery (CSRF) vulnerability in HP Operations Orchestration before 9 allows remote attackers to hijac... |
| CVE-2013-6191 | — | — | 2.5% | Dec 17, 2013 | Cross-site scripting (XSS) vulnerability in HP Operations Orchestration before 9 allows remote attackers to inject arbit... |
| CVE-2013-3140 | — | — | 24.1% | Dec 16, 2013 | Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code via a cr... |
| CVE-2013-6973 | — | — | 2.2% | Dec 14, 2013 | Cisco WebEx Training Center allows remote attackers to discover registration IDs via a crafted URL, aka Bug ID CSCul5712... |
| CVE-2013-6972 | — | — | 2.6% | Dec 14, 2013 | Cisco WebEx Training Center allows remote attackers to discover session numbers, and bypass host approval for audio-conf... |
| CVE-2013-6971 | — | — | 2.1% | Dec 14, 2013 | Open redirect vulnerability in Cisco WebEx Training Center allows remote attackers to redirect users to arbitrary web si... |
| CVE-2013-6970 | — | — | 1.4% | Dec 14, 2013 | Cisco WebEx Meeting Center allows remote attackers to obtain sensitive information by reading verbose error messages wit... |
| CVE-2013-6969 | — | — | 1.8% | Dec 14, 2013 | The training-registration page in Cisco WebEx Training Center allows remote attackers to modify unspecified fields via u... |
Check if your code is affected by 2013 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now