Skip to main content

Year archive

CVEs published in 2013

Archive summary

5,187 CVEs published in 2013 — 896 Critical, 859 High, 2,914 Medium, 517 Low, 1 Unrated.

CVE-2013-1090

Published Dec 6, 2013

The SUSE horde5 package before 5.0.2-2.4.1 sets incorrect ownership for certain configuration files and directories including /etc/apache2/vhosts.d, which allows local wwwrun user…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2013-6804

Published Dec 5, 2013

Cross-site scripting (XSS) vulnerability in the Search module before 1.1.1 for Jamroom allows remote attackers to inject arbitrary web script or HTML via the search_string paramet…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6787

Published Dec 5, 2013

SQL injection vulnerability in the check_user_password function in main/auth/profile.php in Chamilo LMS 1.9.6 and earlier, when using the non-encrypted passwords mode set at insta…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6395

Published Dec 5, 2013

Cross-site scripting (XSS) vulnerability in header.php in Ganglia Web 3.5.8 and 3.5.10 allows remote attackers to inject arbitrary web script or HTML via the host_regex parameter…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6341

Published Dec 5, 2013

SQL injection vulnerability in Dokeos 2.2 RC2 and earlier allows remote attackers to execute arbitrary SQL commands via the language parameter to index.php.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2013-6267

Published Dec 5, 2013

Multiple cross-site scripting (XSS) vulnerabilities in Claroline before 1.11.9 allow remote attackers to inject arbitrary web script or HTML via the (1) box parameter to messaging…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-5108

Published Dec 5, 2013

Multiple cross-site scripting (XSS) vulnerabilities in the xn function in RockMongo 1.1.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) db…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-3921

Published Dec 5, 2013

Directory traversal vulnerability in Easytime Studio Easy File Manager 1.1 for iOS allows remote attackers to read arbitrary files via a ..%2f (encoded dot dot slash) to the defau…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6915

Published Dec 5, 2013

Cross-site scripting (XSS) vulnerability in the system-administration component in Cybozu Garoon before 3.7.2 allows remote authenticated users to inject arbitrary web script or H…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2013-6914

Published Dec 5, 2013

Cross-site scripting (XSS) vulnerability in a calendar component in Cybozu Garoon before 3.7.2 allows remote authenticated users to inject arbitrary web script or HTML via unspeci…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2013-6913

Published Dec 5, 2013

Cross-site scripting (XSS) vulnerability in a search component in Cybozu Garoon before 3.7.2, when Internet Explorer is used, allows remote authenticated users to inject arbitrary…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2013-6912

Published Dec 5, 2013

Cross-site scripting (XSS) vulnerability in a calendar component in Cybozu Garoon before 3.7.2, when Internet Explorer 6 through 9 is used, allows remote authenticated users to in…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2013-6910

Published Dec 5, 2013

Cross-site scripting (XSS) vulnerability in Ajax components in Cybozu Garoon before 3.7.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6909

Published Dec 5, 2013

Cross-site scripting (XSS) vulnerability in a report component in Cybozu Garoon before 3.7.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6908

Published Dec 5, 2013

Cross-site scripting (XSS) vulnerability in a mail component in Cybozu Garoon 3.x before 3.7.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vecto…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6907

Published Dec 5, 2013

Cross-site scripting (XSS) vulnerability in a mail component in Cybozu Garoon 2.x and 3.x before 3.7.0 allows remote attackers to inject arbitrary web script or HTML via unspecifi…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6906

Published Dec 5, 2013

Cross-site scripting (XSS) vulnerability in a mail component in Cybozu Garoon before 3.7.0, when Internet Explorer 6 through 8 is used, allows remote attackers to inject arbitrary…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6902

Published Dec 5, 2013

Cross-site scripting (XSS) vulnerability in the Space function in Cybozu Garoon before 3.7.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 426-450 of 5,187 CVEsPage 18 of 208