2013 CVE Vulnerabilities
6,830 CVEs published in 2013.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2013-6462 | — | — | 10.3% | Jan 9, 2014 | Stack-based buffer overflow in the bdfReadCharacters function in bitmap/bdfread.c in X.Org libXfont 1.1 through 1.4.6 al... |
| CVE-2013-7283 | — | — | 1.6% | Jan 9, 2014 | Race condition in the libreswan.spec files for Red Hat Enterprise Linux (RHEL) and Fedora packages in libreswan 3.6 has ... |
| CVE-2013-7174 | — | — | 2.1% | Jan 9, 2014 | Absolute path traversal vulnerability in cgi-bin/jc.cgi in QNAP QTS before 4.1.0 allows remote attackers to read arbitra... |
| CVE-2013-6955 | — | — | 84.6% | Jan 9, 2014 | webman/imageSelector.cgi in Synology DiskStation Manager (DSM) 4.0 before 4.0-2259, 4.2 before 4.2-3243, and 4.3 before ... |
| CVE-2013-4353 | — | — | 11.9% | Jan 9, 2014 | The ssl3_take_mac function in ssl/s3_both.c in OpenSSL 1.0.1 before 1.0.1f allows remote TLS servers to cause a denial o... |
| CVE-2013-6997 | — | — | 1.3% | Jan 9, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in Open-Xchange (OX) AppSuite 7.4.0 and earlier allow remote attacke... |
| CVE-2013-5359 | — | — | 2.3% | Jan 9, 2014 | Stack-based buffer overflow in Picasa3.exe in Google Picasa before 3.9.0 Build 137.69 might allow remote attackers to ex... |
| CVE-2013-5358 | — | — | 1.3% | Jan 9, 2014 | Picasa3.exe in Google Picasa before 3.9.0 Build 137.69 allows remote attackers to trigger memory corruption via a crafte... |
| CVE-2013-5357 | — | — | 2.3% | Jan 9, 2014 | Integer overflow in Picasa3.exe in Google Picasa before 3.9.0 Build 137.69 allows remote attackers to execute arbitrary ... |
| CVE-2013-5349 | — | — | 2.3% | Jan 9, 2014 | Integer underflow in Picasa3.exe in Google Picasa before 3.9.0 Build 137.69 allows remote attackers to execute arbitrary... |
| CVE-2013-6982 | — | — | 2.8% | Jan 8, 2014 | The BGP implementation in Cisco NX-OS 6.2(2a) and earlier does not properly handle the interaction of UPDATE messages wi... |
| CVE-2013-7281 | — | — | 0.5% | Jan 8, 2014 | The dgram_recvmsg function in net/ieee802154/dgram.c in the Linux kernel before 3.12.4 updates a certain length value wi... |
| CVE-2013-7280 | — | — | 5.8% | Jan 8, 2014 | Buffer overflow in HansoTools Hanso Player 2.1.0, 2.5.0, and earlier allows remote attackers to cause a denial of servic... |
| CVE-2013-7279 | — | — | 2.0% | Jan 8, 2014 | Cross-site scripting (XSS) vulnerability in views/video-management/preview_video.php in the S3 Video plugin before 0.983... |
| CVE-2013-7278 | — | — | 2.6% | Jan 8, 2014 | SQL injection vulnerability in Naxtech CMS Afroditi 1.0 allows remote attackers to execute arbitrary SQL commands via th... |
| CVE-2013-7277 | — | — | 1.7% | Jan 8, 2014 | Multiple cross-site scripting (XSS) vulnerabilities in Andy's PHP Knowledgebase (Aphpkb) before 0.95.8 allow remote atta... |
| CVE-2013-7276 | — | — | 2.4% | Jan 8, 2014 | Cross-site scripting (XSS) vulnerability in inc/raf_form.php in the Recommend to a friend plugin 2.0.2 for WordPress all... |
| CVE-2013-7275 | — | — | 1.9% | Jan 8, 2014 | Cross-site scripting (XSS) vulnerability in misc.php in MyBB (aka MyBulletinBoard) before 1.6.12 allows remote attackers... |
| CVE-2013-7274 | — | — | 1.5% | Jan 8, 2014 | Cross-site scripting (XSS) vulnerability in Wallpaper Script 3.5.0082 allows remote authenticated users to inject arbitr... |
| CVE-2013-7097 | — | — | 3.6% | Jan 8, 2014 | Directory traversal vulnerability in 7 Media Web Solutions eduTrac before 1.1.2 allows remote attackers to read arbitrar... |
| CVE-2013-6436 | — | — | 0.4% | Jan 7, 2014 | The lxcDomainGetMemoryParameters method in lxc/lxc_driver.c in libvirt 1.0.5 through 1.2.0 does not properly check the s... |
| CVE-2013-6480 | — | — | 2.1% | Jan 7, 2014 | Libcloud 0.12.3 through 0.13.2 does not set the scrub_data parameter for the destroy DigitalOcean API, which allows loca... |
| CVE-2013-6419 | — | — | 1.8% | Jan 7, 2014 | Interaction error in OpenStack Nova and Neutron before Havana 2013.2.1 and icehouse-1 does not validate the instance ID ... |
| CVE-2013-4969 | — | — | 0.4% | Jan 7, 2014 | Puppet before 3.3.3 and 3.4 before 3.4.1 and Puppet Enterprise (PE) before 2.8.4 and 3.1 before 3.1.1 allows local users... |
| CVE-2013-6888 | — | — | 4.1% | Jan 7, 2014 | Uscan in devscripts before 2.13.9 allows remote attackers to execute arbitrary code via a crafted tarball. |
Check if your code is affected by 2013 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now