2013 CVE Vulnerabilities
6,830 CVEs published in 2013.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2013-6958 | — | — | 1.9% | Dec 13, 2013 | Juniper NetScreen Firewall running ScreenOS 5.4, 6.2, or 6.3, when the Ping of Death screen is disabled, allows remote a... |
| CVE-2013-6957 | — | — | 1.8% | Dec 13, 2013 | Cross-site scripting (XSS) vulnerability in the web administrative component in Juniper IDP allows remote attackers to i... |
| CVE-2013-6956 | — | — | 0.9% | Dec 13, 2013 | Cross-site scripting (XSS) vulnerability in the Secure Access Service Web rewriting feature in Juniper Junos Pulse Secur... |
| CVE-2013-6394 | — | — | 0.4% | Dec 13, 2013 | Percona XtraBackup before 2.1.6 uses a constant string for the initialization vector (IV), which makes it easier for loc... |
| CVE-2013-4569 | — | — | 1.8% | Dec 13, 2013 | The CleanChanges extension for MediaWiki before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.21.3, when "Group chan... |
| CVE-2013-4568 | — | — | 2.1% | Dec 13, 2013 | Incomplete blacklist vulnerability in Sanitizer::checkCss in MediaWiki before 1.19.9, 1.20.x before 1.20.8, and 1.21.x b... |
| CVE-2013-4567 | — | — | 1.3% | Dec 13, 2013 | Incomplete blacklist vulnerability in Sanitizer::checkCss in MediaWiki before 1.19.9, 1.20.x before 1.20.8, and 1.21.x b... |
| CVE-2013-0348 | — | — | 0.5% | Dec 13, 2013 | thttpd.c in sthttpd before 2.26.4-r2 and thttpd 2.25b use world-readable permissions for /var/log/thttpd.log, which allo... |
| CVE-2013-6839 | — | — | 1.3% | Dec 13, 2013 | SQL injection vulnerability in InstantSoft InstantCMS 1.10.3 and earlier allows remote attackers to execute arbitrary SQ... |
| CVE-2013-6005 | — | — | 1.3% | Dec 13, 2013 | Cross-site scripting (XSS) vulnerability in Cybozu Dezie before 8.1.0 allows remote attackers to inject arbitrary web sc... |
| CVE-2013-4988 | — | — | 67.0% | Dec 13, 2013 | Stack-based buffer overflow in IcoFX 2.5 and earlier allows remote attackers to execute arbitrary code via a long idCoun... |
| CVE-2013-5763 | — | — | 0.5% | Dec 12, 2013 | Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.4.0 allows context... |
| CVE-2013-6421 | — | — | 2.0% | Dec 12, 2013 | The unpack_zip function in archive_unpacker.rb in the sprout gem 0.7.246 for Ruby allows context-dependent attackers to ... |
| CVE-2013-6054 | — | — | 2.2% | Dec 12, 2013 | Heap-based buffer overflow in OpenJPEG 1.3 has unspecified impact and remote vectors, a different vulnerability than CVE... |
| CVE-2013-6052 | — | — | 2.2% | Dec 12, 2013 | OpenJPEG 1.3 and earlier allows remote attackers to obtain sensitive information via unspecified vectors that trigger a ... |
| CVE-2013-6045 | — | — | 5.5% | Dec 12, 2013 | Multiple heap-based buffer overflows in OpenJPEG 1.3 and earlier might allow remote attackers to execute arbitrary code ... |
| CVE-2013-4566 | — | — | 2.0% | Dec 12, 2013 | mod_nss 1.0.8 and earlier, when NSSVerifyClient is set to none for the server/vhost context, does not enforce the NSSVer... |
| CVE-2013-4458 | — | — | 4.2% | Dec 12, 2013 | Stack-based buffer overflow in the getaddrinfo function in sysdeps/posix/getaddrinfo.c in GNU C Library (aka glibc or li... |
| CVE-2013-2752 | — | — | 1.0% | Dec 12, 2013 | Cross-site request forgery (CSRF) vulnerability in frontview/lib/np_handler.pl in NETGEAR ReadyNAS RAIDiator before 4.1.... |
| CVE-2013-2751 | — | — | 71.6% | Dec 12, 2013 | Eval injection vulnerability in frontview/lib/np_handler.pl in the FrontView web interface in NETGEAR ReadyNAS RAIDiator... |
| CVE-2013-1978 | — | — | 4.2% | Dec 12, 2013 | Heap-based buffer overflow in the read_xwd_cols function in file-xwd.c in the X Window Dump (XWD) plug-in in GIMP 2.6.9 ... |
| CVE-2013-1913 | — | — | 4.1% | Dec 12, 2013 | Integer overflow in the load_image function in file-xwd.c in the X Window Dump (XWD) plug-in in GIMP 2.6.9 and earlier, ... |
| CVE-2013-1812 | — | — | 2.1% | Dec 12, 2013 | The ruby-openid gem before 2.2.2 for Ruby allows remote OpenID providers to cause a denial of service (CPU consumption) ... |
| CVE-2013-1447 | — | — | 2.5% | Dec 12, 2013 | OpenJPEG 1.3 and earlier allows remote attackers to cause a denial of service (memory consumption or crash) via unspecif... |
| CVE-2013-6986 | — | — | 0.6% | Dec 12, 2013 | The ZippyYum Subway CA Kiosk app 3.4 for iOS uses cleartext storage in SQLite cache databases, which allows attackers to... |
Check if your code is affected by 2013 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now