2013 CVE Vulnerabilities

6,830 CVEs published in 2013.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2013-2600HIGH7.5MiniUPnPd has information disclosure use of snprintf()
CVE-2013-2075HIGH8.8Multiple buffer overflows in the (1) R5RS char-ready, (2) tcp-accept-ready, and (3) file-select procedures in Chicken th...
CVE-2013-2024HIGH8.8OS command injection vulnerability in the "qs" procedure from the "utils" module in Chicken before 4.9.0.
CVE-2013-2012HIGH7.3autojump before 21.5.8 allows local users to gain privileges via a Trojan horse custom_install directory in the current ...
CVE-2013-1391HIGH7.5Authentication bypass vulnerability in the the web interface in Hunt CCTV, Capture CCTV, Hachi CCTV, NoVus CCTV, and Wel...
CVE-2013-4848HIGH8.8TP-Link TL-WDR4300 version 3.13.31 has multiple CSRF vulnerabilities.
CVE-2013-4855HIGH8.8D-Link DIR-865L has SMB Symlink Traversal due to misconfiguration in the SMB service allowing symbolic links to be creat...
CVE-2013-7333HIGH7.5A vulnerability in version 0.90 of the Open Floodlight SDN controller software could allow an attacker with access to th...
CVE-2013-3703HIGH8.8The controller of the Open Build Service API prior to version 2.4.4 is missing a write permission check, allowing an aut...
CVE-2013-2830HIGH7.8Use-after-free vulnerability in SumatraPDF Reader 2.x before 2.2.1 allows remote attackers to execute arbitrary code via...
CVE-2013-6648HIGH7.5SkRegion::setPath in Skia allows remote attackers to cause a denial of service (crash).
CVE-2013-3632HIGH8.8The Cron service in rpc.php in OpenMediaVault allows remote authenticated users to execute cron jobs as arbitrary users ...
CVE-2013-2597HIGH8.4Stack-based buffer overflow in the acdb_ioctl function in audio_acdb.c in the acdb audio driver for the Linux kernel 2.6...
CVE-2013-6040HIGH8.1MW6 Aztec, DataMatrix, and MaxiCode ActiveX controls before version 4.0 vulnerable to arbitrary code via a crafted HTML ...
CVE-2013-7030HIGH7.3The TFTP service in Cisco Unified Communications Manager (aka CUCM or Unified CM) allows remote attackers to obtain sens...
CVE-2013-5065HIGH7.8NDProxy.sys in the kernel in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges ...
CVE-2013-6282HIGH8.8The (1) get_user and (2) put_user API functions in the Linux kernel before 3.5.5 on the v6k and v7 ARM platforms do not ...
CVE-2013-4588HIGH7Multiple stack-based buffer overflows in net/netfilter/ipvs/ip_vs_ctl.c in the Linux kernel before 2.6.33, when CONFIG_I...
CVE-2013-3918HIGH8.8The InformationCardSigninHelper Class ActiveX control in icardie.dll in Microsoft Windows XP SP2 and SP3, Windows Server...
CVE-2013-4508HIGH7.5lighttpd before 1.4.34, when SNI is enabled, configures weak SSL ciphers, which makes it easier for remote attackers to ...
CVE-2013-3906HIGH7.8GDI+ in Microsoft Windows Vista SP2 and Server 2008 SP2; Office 2003 SP3, 2007 SP3, and 2010 SP1 and SP2; Office Compati...
CVE-2013-3897HIGH8.8Use-after-free vulnerability in the CDisplayPointer class in mshtml.dll in Microsoft Internet Explorer 6 through 11 allo...
CVE-2013-3894HIGH8.1The kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server ...
CVE-2013-3888HIGH8.4dxgkrnl.sys in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7...
CVE-2013-3893HIGH8.8Use-after-free vulnerability in the SetMouseCapture implementation in mshtml.dll in Microsoft Internet Explorer 6 throug...

Check if your code is affected by 2013 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now