2013 CVE Vulnerabilities
6,830 CVEs published in 2013.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2013-6387 | — | — | 1.4% | Dec 24, 2013 | Cross-site scripting (XSS) vulnerability in the Image module in Drupal 7.x before 7.24 allows remote authenticated users... |
| CVE-2013-4554 | — | — | 0.6% | Dec 24, 2013 | Xen 3.0.3 through 4.1.x (possibly 4.1.6.1), 4.2.x (possibly 4.2.3), and 4.3.x (possibly 4.3.1) does not properly prevent... |
| CVE-2013-4553 | — | — | 0.6% | Dec 24, 2013 | The XEN_DOMCTL_getmemlist hypercall in Xen 3.4.x through 4.3.x (possibly 4.3.1) does not always obtain the page_alloc_lo... |
| CVE-2013-4452 | — | — | 0.4% | Dec 24, 2013 | Red Hat JBoss Operations Network 3.1.2 uses world-readable permissions for the (1) server and (2) agent configuration fi... |
| CVE-2013-4358 | — | — | 1.3% | Dec 24, 2013 | libavcodec/h264.c in FFmpeg before 0.11.4 allows remote attackers to cause a denial of service (crash) via vectors relat... |
| CVE-2013-6795 | — | — | 5.3% | Dec 24, 2013 | The Updater in Rackspace Openstack Windows Guest Agent for XenServer before 1.2.6.0 allows remote attackers to execute a... |
| CVE-2013-6403 | — | — | 2.1% | Dec 24, 2013 | The admin page in ownCloud before 5.0.13 allows remote attackers to bypass intended access restrictions via unspecified ... |
| CVE-2013-4550 | — | — | 2.2% | Dec 24, 2013 | Bip before 0.8.9, when running as a daemon, writes SSL handshake errors to an unexpected file descriptor that was previo... |
| CVE-2013-7102 | — | — | 14.8% | Dec 23, 2013 | Multiple unrestricted file upload vulnerabilities in (1) media-upload.php, (2) media-upload-lncthumb.php, and (3) media-... |
| CVE-2013-7081 | — | — | 1.0% | Dec 23, 2013 | The (old) Form Content Element component in TYPO3 4.5.0 through 4.5.31, 4.7.0 through 4.7.16, 6.0.0 through 6.0.11, and ... |
| CVE-2013-7080 | — | — | 1.2% | Dec 23, 2013 | The creating record functionality in Extension table administration library (feuser_adminLib.inc) in TYPO3 4.5.0 through... |
| CVE-2013-7079 | — | — | 1.2% | Dec 23, 2013 | Open redirect vulnerability in the OpenID extension in TYPO3 4.5.0 through 4.5.31, 4.7.0 through 4.7.16, 6.0.0 through 6... |
| CVE-2013-7075 | — | — | 1.3% | Dec 23, 2013 | The Content Editing Wizards component in TYPO3 4.5.0 through 4.5.31, 4.7.0 through 4.7.16, 6.0.0 through 6.0.11, and 6.1... |
| CVE-2013-7073 | — | — | 1.3% | Dec 23, 2013 | The Content Editing Wizards component in TYPO3 4.5.0 through 4.5.31, 4.7.0 through 4.7.16, 6.0.0 through 6.0.11, and 6.1... |
| CVE-2013-7049 | — | — | 1.7% | Dec 23, 2013 | Stack-based buffer overflow in fish.cpp in the Fish plugin for ZNC, as used in ZNC for Windows (znc-msvc) 0.206 and earl... |
| CVE-2013-4424 | — | — | 1.0% | Dec 23, 2013 | Multiple cross-site scripting (XSS) vulnerabilities in the GateIn Portal component in Red Hat JBoss Portal 6.1.0 allow r... |
| CVE-2013-3709 | — | — | 0.5% | Dec 23, 2013 | WebYaST 1.3 uses weak permissions for config/initializers/secret_token.rb, which allows local users to gain privileges b... |
| CVE-2013-6979 | — | — | 3.6% | Dec 23, 2013 | The VTY authentication implementation in Cisco IOS XE 03.02.xxSE and 03.03.xxSE incorrectly relies on the Linux-IOS inte... |
| CVE-2013-6890 | — | — | 8.9% | Dec 23, 2013 | denyhosts 2.6 uses an incorrect regular expression when analyzing authentication logs, which allows remote attackers to ... |
| CVE-2013-6449 | — | — | 21.2% | Dec 23, 2013 | The ssl_get_algorithm2 function in ssl/s3_lib.c in OpenSSL before 1.0.2 obtains a certain version number from an incorre... |
| CVE-2013-6439 | — | — | 1.6% | Dec 23, 2013 | Candlepin in Red Hat Subscription Asset Manager 1.0 through 1.3 uses a weak authentication scheme when the configuration... |
| CVE-2013-6422 | — | — | 2.8% | Dec 23, 2013 | The GnuTLS backend in libcurl 7.21.4 through 7.33.0, when disabling digital signature verification (CURLOPT_SSL_VERIFYPE... |
| CVE-2013-5420 | — | — | 0.9% | Dec 23, 2013 | The IMS server before Ifix 6 in IBM Security Access Manager for Enterprise Single Sign-On (ISAM ESSO) 8.2 allows remote ... |
| CVE-2013-4549 | — | — | 3.1% | Dec 23, 2013 | QXmlSimpleReader in Qt before 5.2 allows context-dependent attackers to cause a denial of service (memory consumption) v... |
| CVE-2013-4461 | — | — | 1.9% | Dec 23, 2013 | SQL injection vulnerability in the web interface for cumin in Red Hat Enterprise MRG Grid 2.4 allows remote attackers to... |
Check if your code is affected by 2013 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now