Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2017-16913

Publication date:
31/01/2018
The "stub_recv_cmd_submit()" function (drivers/usb/usbip/stub_rx.c) in the Linux Kernel before version 4.14.8, 4.9.71, and 4.4.114 when handling CMD_SUBMIT packets allows attackers to cause a denial of service (arbitrary memory allocation) via a specially crafted USB over IP packet.
Severity CVSS v4.0: Pending analysis
Last modification:
24/08/2018

CVE-2017-16914

Publication date:
31/01/2018
The "stub_send_ret_submit()" function (drivers/usb/usbip/stub_tx.c) in the Linux Kernel before version 4.14.8, 4.9.71, 4.1.49, and 4.4.107 allows attackers to cause a denial of service (NULL pointer dereference) via a specially crafted USB over IP packet.
Severity CVSS v4.0: Pending analysis
Last modification:
24/08/2018

CVE-2018-6374

Publication date:
31/01/2018
The GUI component (aka PulseUI) in Pulse Secure Desktop Linux clients before PULSE5.2R9.2 and 5.3.x before PULSE5.3R4.2 does not perform strict SSL Certificate Validation. This can lead to the manipulation of the Pulse Connection set.
Severity CVSS v4.0: Pending analysis
Last modification:
24/02/2018

CVE-2017-16928

Publication date:
31/01/2018
The arq_updater binary in Arq 5.10 and earlier for Mac allows local users to write to arbitrary files and consequently gain root privileges via a crafted update URL, as demonstrated by file:///tmp/blah/Arq.zip.
Severity CVSS v4.0: Pending analysis
Last modification:
08/09/2021

CVE-2017-16945

Publication date:
31/01/2018
The standardrestorer binary in Arq 5.10 and earlier for Mac allows local users to write to arbitrary files and consequently gain root privileges via a crafted restore path.
Severity CVSS v4.0: Pending analysis
Last modification:
08/09/2021

CVE-2017-15654

Publication date:
31/01/2018
Highly predictable session tokens in the HTTPd server in all current versions (
Severity CVSS v4.0: Pending analysis
Last modification:
03/10/2019

CVE-2017-15656

Publication date:
31/01/2018
Password are stored in plaintext in nvram in the HTTPd server in all current versions (
Severity CVSS v4.0: Pending analysis
Last modification:
03/10/2019

CVE-2018-6479

Publication date:
31/01/2018
An issue was discovered on Netwave IP Camera devices. An unauthenticated attacker can crash a device by sending a POST request with a huge body size to the / URI.
Severity CVSS v4.0: Pending analysis
Last modification:
13/09/2021

CVE-2017-18043

Publication date:
31/01/2018
Integer overflow in the macro ROUND_UP (n, d) in Quick Emulator (Qemu) allows a user to cause a denial of service (Qemu process crash).
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2017-15653

Publication date:
31/01/2018
Improper administrator IP validation after his login in the HTTPd server in all current versions (
Severity CVSS v4.0: Pending analysis
Last modification:
27/02/2018

CVE-2018-6480

Publication date:
31/01/2018
A type confusion issue was discovered in CCN-lite 2, leading to a memory access violation and a failure of the nonce feature (which, for example, helped with loop prevention). ccnl_fwd_handleInterest assumes that the union member s is of type ccnl_pktdetail_ndntlv_s. However, if the type is in fact struct ccnl_pktdetail_ccntlv_s or struct ccnl_pktdetail_iottlv_s, the memory at that point is either uninitialised or points to data that is not a nonce, which renders the code using the local variable nonce pointless. A later nonce check is insufficient.
Severity CVSS v4.0: Pending analysis
Last modification:
21/02/2018

CVE-2017-15655

Publication date:
31/01/2018
Multiple buffer overflow vulnerabilities exist in the HTTPd server in Asus asuswrt version
Severity CVSS v4.0: Pending analysis
Last modification:
21/02/2018