Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2012-5521

Publication date:
25/11/2019
quagga (ospf6d) 0.99.21 has a DoS flaw in the way the ospf6d daemon performs routes removal
Severity CVSS v4.0: Pending analysis
Last modification:
18/08/2020

CVE-2012-5527

Publication date:
25/11/2019
Claws Mail vCalendar plugin: credentials exposed on interface
Severity CVSS v4.0: Pending analysis
Last modification:
11/12/2019

CVE-2012-5518

Publication date:
25/11/2019
vdsm: certificate generation upon node creation allowing vdsm to start and serve requests from anyone who has a matching key (and certificate)
Severity CVSS v4.0: Pending analysis
Last modification:
09/12/2019

CVE-2012-5582

Publication date:
25/11/2019
opendnssec misuses libcurl API
Severity CVSS v4.0: Pending analysis
Last modification:
09/12/2019

CVE-2012-5630

Publication date:
25/11/2019
libuser 0.56 and 0.57 has a TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees.
Severity CVSS v4.0: Pending analysis
Last modification:
04/12/2019

CVE-2012-5535

Publication date:
25/11/2019
gnome-system-log polkit policy allows arbitrary files on the system to be read
Severity CVSS v4.0: Pending analysis
Last modification:
09/12/2019

CVE-2012-5617

Publication date:
25/11/2019
gksu-polkit: permissive PolicyKit policy configuration file allows privilege escalation
Severity CVSS v4.0: Pending analysis
Last modification:
02/06/2021

CVE-2019-10207

Publication date:
25/11/2019
A flaw was found in the Linux kernel's Bluetooth implementation of UART, all versions kernel 3.x.x before 4.18.0 and kernel 5.x.x. An attacker with local access and write permissions to the Bluetooth hardware could use this flaw to issue a specially crafted ioctl function call and cause the system to crash.
Severity CVSS v4.0: Pending analysis
Last modification:
12/02/2023

CVE-2012-5578

Publication date:
25/11/2019
Python keyring has insecure permissions on new databases allowing world-readable files to be created
Severity CVSS v4.0: Pending analysis
Last modification:
04/12/2019

CVE-2019-14822

Publication date:
25/11/2019
A flaw was discovered in ibus in versions before 1.5.22 that allows any unprivileged user to monitor and send method calls to the ibus bus of another user due to a misconfiguration in the DBus server setup. A local attacker may use this flaw to intercept all keystrokes of a victim user who is using the graphical interface, change the input method engine, or modify other input related configurations of the victim user.
Severity CVSS v4.0: Pending analysis
Last modification:
07/06/2022

CVE-2019-14815

Publication date:
25/11/2019
A vulnerability was found in Linux Kernel, where a Heap Overflow was found in mwifiex_set_wmm_params() function of Marvell Wifi Driver.
Severity CVSS v4.0: Pending analysis
Last modification:
13/07/2023

CVE-2019-14891

Publication date:
25/11/2019
A flaw was found in cri-o, as a result of all pod-related processes being placed in the same memory cgroup. This can result in container management (conmon) processes being killed if a workload process triggers an out-of-memory (OOM) condition for the cgroup. An attacker could abuse this flaw to get host network access on an cri-o host.
Severity CVSS v4.0: Pending analysis
Last modification:
28/02/2020