Skip to main content

Year archive

CVEs published in 2013

Archive summary

5,187 CVEs published in 2013 — 896 Critical, 859 High, 2,914 Medium, 517 Low, 1 Unrated.

CVE-2013-6050

Published Dec 7, 2013

Integer overflow in Links before 2.8 allows remote attackers to cause a denial of service (crash) via crafted HTML tables.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-4558

Published Dec 7, 2013

The get_parent_resource function in repos.c in mod_dav_svn Apache HTTPD server module in Subversion 1.7.11 through 1.7.13 and 1.8.1 through 1.8.4, when built with assertions enabl…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2013-4505

Published Dec 7, 2013

The is_this_legal function in mod_dontdothat for Apache Subversion 1.4.0 through 1.7.13 and 1.8.0 through 1.8.4 allows remote attackers to bypass intended access restrictions and…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2013-4479

Published Dec 7, 2013

lib/sup/message_chunks.rb in Sup before 0.13.2.1 and 0.14.x before 0.14.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the content_type of a…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-4478

Published Dec 7, 2013

Sup before 0.13.2.1 and 0.14.x before 0.14.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the filename of an email attachment.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-4446

Published Dec 7, 2013

The _json_decode function in plugins/context_reaction_block.inc in the Context module 6.x-2.x before 6.x-3.2 and 7.x-3.x before 7.x-3.0 for Drupal, when using a version of PHP tha…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-4445

Published Dec 7, 2013

The json rendering functionality in the Context module 6.x-2.x before 6.x-3.2 and 7.x-3.x before 7.x-3.0 for Drupal uses Drupal's token scheme to restrict access to blocks, which…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-4212

Published Dec 7, 2013

Certain getText methods in the ActionSupport controller in Apache Roller before 5.0.2 allow remote attackers to execute arbitrary OGNL expressions via the first or second paramete…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-4171

Published Dec 7, 2013

Multiple cross-site scripting (XSS) vulnerabilities in Apache Roller before 5.0.2 allow remote attackers to inject arbitrary web script or HTML via vectors related to the search r…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6707

Published Dec 7, 2013

Memory leak in the connection-manager implementation in Cisco Adaptive Security Appliance (ASA) Software 9.1(.3) and earlier allows remote attackers to cause a denial of service (…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-5455

Published Dec 7, 2013

IBM SmartCloud Provisioning 2.1 before FP3 IF0001 allows remote authenticated users to modify virtual-system deployment via deployer.virtualsystems CLI commands, as demonstrated b…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6999

Published Dec 7, 2013

The IsHandleEntrySecure function in win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2008 SP2 does not properly validate the tagPROCESSINFO pW32Job field, which a…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6920

Published Dec 7, 2013

Siemens SINAMICS S/G controllers with firmware before 4.6.11 do not require authentication for FTP and TELNET sessions, which allows remote attackers to bypass intended access res…

CVSS 10.0 · Critical

CVE-2013-6640

Published Dec 7, 2013

The DehoistArrayIndex function in hydrogen-dehoist.cc (aka hydrogen.cc) in Google V8 before 3.22.24.7, as used in Google Chrome before 31.0.1650.63, allows remote attackers to cau…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2013-6639

Published Dec 7, 2013

The DehoistArrayIndex function in hydrogen-dehoist.cc (aka hydrogen.cc) in Google V8 before 3.22.24.7, as used in Google Chrome before 31.0.1650.63, allows remote attackers to cau…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2013-6638

Published Dec 7, 2013

Multiple buffer overflows in runtime.cc in Google V8 before 3.22.24.7, as used in Google Chrome before 31.0.1650.63, allow remote attackers to cause a denial of service or possibl…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2013-6637

Published Dec 7, 2013

Multiple unspecified vulnerabilities in Google Chrome before 31.0.1650.63 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2013-6636

Published Dec 7, 2013

The FrameLoader::notifyIfInitialDocumentAccessed function in core/loader/FrameLoader.cpp in Blink, as used in Google Chrome before 31.0.1650.63, makes an incorrect check for an em…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2013-6635

Published Dec 7, 2013

Use-after-free vulnerability in the editing implementation in Blink, as used in Google Chrome before 31.0.1650.63, allows remote attackers to cause a denial of service or possibly…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6634

Published Dec 7, 2013

The OneClickSigninHelper::ShowInfoBarIfPossible function in browser/ui/sync/one_click_signin_helper.cc in Google Chrome before 31.0.1650.63 uses an incorrect URL during realm vali…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6416

Published Dec 7, 2013

Cross-site scripting (XSS) vulnerability in the simple_format helper in actionpack/lib/action_view/helpers/text_helper.rb in Ruby on Rails 4.x before 4.0.2 allows remote attackers…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-4492

Published Dec 7, 2013

Cross-site scripting (XSS) vulnerability in exceptions.rb in the i18n gem before 0.6.6 for Ruby allows remote attackers to inject arbitrary web script or HTML via a crafted I18n::…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 401-425 of 5,187 CVEsPage 17 of 208