Skip to main content

Year archive

CVEs published in 2013

Archive summary

5,187 CVEs published in 2013 — 896 Critical, 859 High, 2,914 Medium, 517 Low, 1 Unrated.

CVE-2013-6389

Published Dec 7, 2013

Open redirect vulnerability in the Overlay module in Drupal 7.x before 7.24 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspe…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6386

Published Dec 7, 2013

Drupal 6.x before 6.29 and 7.x before 7.24 uses the PHP mt_rand function to generate random numbers, which uses predictable seeds and allows remote attackers to predict security s…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6385

Published Dec 7, 2013

The form API in Drupal 6.x before 6.29 and 7.x before 7.24, when used with unspecified third-party modules, performs form validation even when CSRF validation has failed, which mi…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-0859

Published Dec 7, 2013

The add_doubles_metadata function in libavcodec/tiff.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via a negative or zero count value in a TIFF imag…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2013-0858

Published Dec 7, 2013

The atrac3_decode_init function in libavcodec/atrac3.c in FFmpeg before 1.0.4 allows remote attackers to have an unspecified impact via ATRAC3 data with the joint stereo coding mo…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2013-0857

Published Dec 7, 2013

The decode_frame_ilbm function in libavcodec/iff.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via a crafted height value in IFF PBM/ILBM bitmap dat…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2013-0856

Published Dec 7, 2013

The lpc_prediction function in libavcodec/alac.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via crafted Apple Lossless Audio Codec (ALAC) data, rel…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2013-0855

Published Dec 7, 2013

Integer overflow in the alac_decode_close function in libavcodec/alac.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via a large number of samples pe…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2013-0854

Published Dec 7, 2013

The mjpeg_decode_scan_progressive_ac function in libavcodec/mjpegdec.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via crafted MJPEG data.

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2013-0853

Published Dec 7, 2013

The wavpack_decode_frame function in libavcodec/wavpack.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via crafted WavPack data, which triggers an ou…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2013-0852

Published Dec 7, 2013

The parse_picture_segment function in libavcodec/pgssubdec.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via crafted RLE data, which triggers an out…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2013-0851

Published Dec 7, 2013

The decode_frame function in libavcodec/eamad.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via crafted Electronic Arts Madcow video data, which tri…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2013-0850

Published Dec 7, 2013

The decode_slice_header function in libavcodec/h264.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via crafted H.264 data, which triggers an out-of-b…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2013-0849

Published Dec 7, 2013

The roq_decode_init function in libavcodec/roqvideodec.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via a crafted (1) width or (2) height dimension…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2013-0848

Published Dec 7, 2013

The decode_init function in libavcodec/huffyuv.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via a crafted width in huffyuv data with the predictor…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2013-0847

Published Dec 7, 2013

The ff_id3v2_parse function in libavformat/id3v2.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via ID3v2 header data, which triggers an out-of-bound…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2013-0846

Published Dec 7, 2013

Array index error in the qdm2_decode_super_block function in libavcodec/qdm2.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via crafted QDM2 data, wh…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2013-0845

Published Dec 7, 2013

libavcodec/alsdec.c in FFmpeg before 1.0.4 allows remote attackers to have an unspecified impact via a crafted block length, which triggers an out-of-bounds write.

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2013-0844

Published Dec 7, 2013

Off-by-one error in the adpcm_decode_frame function in libavcodec/adpcm.c in FFmpeg before 1.0.4 allows remote attackers to have an unspecified impact via crafted DK4 data, which…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-6612

Published Dec 7, 2013

The (1) UpdateRequestHandler for XSLT or (2) XPathEntityProcessor in Apache Solr before 4.1 allows remote attackers to have an unspecified impact via XML data containing an extern…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2013-6409

Published Dec 7, 2013

Debian adequate before 0.8.1, when run by root with the --user option, allows local users to hijack the tty and possibly gain privileges via the TIOCSTI ioctl.

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6408

Published Dec 7, 2013

The DocumentAnalysisRequestHandler in Apache Solr before 4.3.1 does not properly use the EmptyEntityResolver, which allows remote attackers to have an unspecified impact via XML d…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6407

Published Dec 7, 2013

The UpdateRequestHandler for XML in Apache Solr before 4.1 allows remote attackers to have an unspecified impact via XML data containing an external entity declaration in conjunct…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6397

Published Dec 7, 2013

Directory traversal vulnerability in SolrResourceLoader in Apache Solr before 4.6 allows remote attackers to read arbitrary files via a .. (dot dot) or full pathname in the tr par…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 376-400 of 5,187 CVEsPage 16 of 208