Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2019-20828

Publication date:
04/06/2020
An issue was discovered in Foxit Reader and PhantomPDF before 9.6. It has a buffer overflow because a looping correction does not occur after JavaScript updates Field APs.
Severity CVSS v4.0: Pending analysis
Last modification:
05/06/2020

CVE-2019-20830

Publication date:
04/06/2020
An issue was discovered in Foxit Reader and PhantomPDF before 9.6. It has an out-of-bounds write when Internet Explorer is used.
Severity CVSS v4.0: Pending analysis
Last modification:
05/06/2020

CVE-2019-20829

Publication date:
04/06/2020
An issue was discovered in Foxit Reader and PhantomPDF before 9.6. It has a NULL pointer dereference via FXSYS_wcslen in an Epub file.
Severity CVSS v4.0: Pending analysis
Last modification:
05/06/2020

CVE-2018-21243

Publication date:
04/06/2020
An issue was discovered in Foxit PhantomPDF before 8.3.6. It has COM object mishandling when Microsoft Word is used.
Severity CVSS v4.0: Pending analysis
Last modification:
11/06/2020

CVE-2018-21244

Publication date:
04/06/2020
An issue was discovered in Foxit PhantomPDF before 8.3.6. It allows arbitrary application execution via an embedded executable file in a PDF portfolio, aka FG-VD-18-029.
Severity CVSS v4.0: Pending analysis
Last modification:
09/06/2020

CVE-2018-21242

Publication date:
04/06/2020
An issue was discovered in Foxit PhantomPDF before 8.3.6. It allows Remote Code Execution via a GoToE or GoToR action.
Severity CVSS v4.0: Pending analysis
Last modification:
09/06/2020

CVE-2018-21239

Publication date:
04/06/2020
An issue was discovered in Foxit Reader and PhantomPDF before 9.2. It allows NTLM credential theft via a GoToE or GoToR action.
Severity CVSS v4.0: Pending analysis
Last modification:
09/06/2020

CVE-2018-21240

Publication date:
04/06/2020
An issue was discovered in Foxit Reader and PhantomPDF before 9.2. It allows memory consumption via an ArrayBuffer(0xfffffffe) call.
Severity CVSS v4.0: Pending analysis
Last modification:
09/06/2020

CVE-2018-21241

Publication date:
04/06/2020
An issue was discovered in Foxit PhantomPDF before 8.3.6. It has an untrusted search path that allows a DLL to execute remote code.
Severity CVSS v4.0: Pending analysis
Last modification:
09/06/2020

CVE-2018-21236

Publication date:
04/06/2020
An issue was discovered in Foxit Reader before 2.4.4. It has a NULL pointer dereference.
Severity CVSS v4.0: Pending analysis
Last modification:
09/06/2020

CVE-2018-21237

Publication date:
04/06/2020
An issue was discovered in Foxit PhantomPDF before 8.3.7. It allows NTLM credential theft via a GoToE or GoToR action.
Severity CVSS v4.0: Pending analysis
Last modification:
09/06/2020

CVE-2018-21235

Publication date:
04/06/2020
An issue was discovered in Foxit E-mail advertising system before September 2018. It allows authentication bypass and information disclosure, related to Interspire Email Marketer.
Severity CVSS v4.0: Pending analysis
Last modification:
09/06/2020