2013 CVE Vulnerabilities
6,830 CVEs published in 2013.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2013-2151 | — | — | 0.4% | Jan 21, 2014 | Unquoted Windows search path vulnerability in Red Hat Enterprise Virtualization (RHEV) 3 and 3.2 allows local users to g... |
| CVE-2013-2104 | — | — | 2.1% | Jan 21, 2014 | python-keystoneclient before 0.2.4, as used in OpenStack Keystone (Folsom), does not properly check expiry for PKI token... |
| CVE-2013-1923 | — | — | 1.0% | Jan 21, 2014 | rpc-gssd in nfs-utils before 1.2.8 performs reverse DNS resolution for server names during GSSAPI authentication, which ... |
| CVE-2013-1769 | — | — | 2.4% | Jan 21, 2014 | A certain hashing algorithm in Telepathy Gabble 0.16.x before 0.16.5 and 0.17.x before 0.17.3 allows remote attackers to... |
| CVE-2013-1361 | — | — | 6.4% | Jan 21, 2014 | Untrusted search path vulnerability in Lenovo Thinkpad Bluetooth with Enhanced Data Rate Software 6.4.0.2900 and earlier... |
| CVE-2013-0485 | — | — | 2.4% | Jan 21, 2014 | Unspecified vulnerability in IBM Java SDK 7 before SR4-FP1, 6 before SR13-FP1, 5.0 before SR16-FP1, and 1.4.2 before SR1... |
| CVE-2013-0340 | — | — | 19.4% | Jan 21, 2014 | expat before version 2.4.0 does not properly handle entities expansion unless an application developer uses the XML_SetE... |
| CVE-2013-0339 | — | — | 4.4% | Jan 21, 2014 | libxml2 through 2.9.1 does not properly handle external entities expansion unless an application developer uses the xmlS... |
| CVE-2013-0157 | — | — | 0.4% | Jan 21, 2014 | (a) mount and (b) umount in util-linux 2.14.1, 2.17.2, and probably other versions allow local users to determine the ex... |
| CVE-2013-7219 | — | — | 2.4% | Jan 21, 2014 | SQL injection vulnerability in vote.php in the 2Glux Sexy Polling (com_sexypolling) component before 1.0.9 for Joomla! a... |
| CVE-2013-6922 | — | — | 1.5% | Jan 21, 2014 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Seagate BlackArmor NAS 220 devices with firmware sg200... |
| CVE-2013-4200 | — | — | 2.4% | Jan 21, 2014 | The isURLInPortal method in the URLTool class in in_portal.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x t... |
| CVE-2013-2594 | — | — | 2.6% | Jan 21, 2014 | SQL injection vulnerability in reports/calldiary.php in Hornbill Supportworks ITSM 1.0.0 through 3.4.14 allows remote at... |
| CVE-2013-6872 | — | — | 2.5% | Jan 21, 2014 | SQL injection vulnerability in managetimetracker.php in Collabtive before 1.2 allows remote authenticated users to execu... |
| CVE-2013-6305 | — | — | 0.6% | Jan 21, 2014 | IBM Platform Symphony 5.2 before build 229037 and 6.1.0.1 before build 229073 uses the same credentials encryption key a... |
| CVE-2013-6040 | HIGH | 8.1 | 7.4% | Jan 21, 2014 | MW6 Aztec, DataMatrix, and MaxiCode ActiveX controls before version 4.0 vulnerable to arbitrary code via a crafted HTML ... |
| CVE-2013-5429 | — | — | 0.9% | Jan 21, 2014 | The Risk Based Access functionality in IBM Tivoli Federated Identity Manager (TFIM) 6.2.2 before FP9 and Tivoli Federate... |
| CVE-2013-4030 | — | — | 0.9% | Jan 21, 2014 | Integrated Management Module (IMM) 2 1.00 through 2.00 on IBM System X and Flex System servers supports SSL cipher suite... |
| CVE-2013-6488 | — | — | — | Jan 20, 2014 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-0328. Reason: This candidate is a reservation du... |
| CVE-2013-3606 | — | — | 1.5% | Jan 20, 2014 | The login page in the GoAhead web server on Dell PowerConnect 3348 1.2.1.3, 3524p 2.0.0.48, and 5324 2.0.1.4 switches al... |
| CVE-2013-3595 | — | — | 1.8% | Jan 20, 2014 | The OpenManage web application 2.5 build 1.19 on Dell PowerConnect 3348 1.2.1.3, 3524p 2.0.0.48, and 5324 2.0.1.4 switch... |
| CVE-2013-3594 | — | — | 3.9% | Jan 20, 2014 | The SSH service on Dell PowerConnect 3348 1.2.1.3, 3524p 2.0.0.48, and 5324 2.0.1.4 switches allows remote attackers to ... |
| CVE-2013-2170 | — | — | — | Jan 20, 2014 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2013-2169 | — | — | — | Jan 20, 2014 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2013-7078 | — | — | 1.6% | Jan 19, 2014 | Cross-site scripting (XSS) vulnerability in the errorAction method in the ActionController base class in the Extbase Fra... |
Check if your code is affected by 2013 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now