Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2018-7875

Publication date:
08/03/2018
There is a heap-based buffer over-read in the getString function of util/decompile.c in libming 0.4.8 for CONSTANT8 data. A Crafted input will lead to a denial of service attack.
Severity CVSS v4.0: Pending analysis
Last modification:
04/03/2019

CVE-2018-7877

Publication date:
08/03/2018
There is a heap-based buffer overflow in the getString function of util/decompile.c in libming 0.4.8 for DOUBLE data. A Crafted input will lead to a denial of service attack.
Severity CVSS v4.0: Pending analysis
Last modification:
24/08/2020

CVE-2018-7876

Publication date:
08/03/2018
In libming 0.4.8, a memory exhaustion vulnerability was found in the function parseSWF_ACTIONRECORD in util/parser.c, which allows remote attackers to cause a denial of service via a crafted file.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2018-7870

Publication date:
08/03/2018
An invalid memory address dereference was discovered in getString in util/decompile.c in libming 0.4.8 for CONSTANT16 data. The vulnerability causes a segmentation fault and application crash, which leads to denial of service.
Severity CVSS v4.0: Pending analysis
Last modification:
04/03/2019

CVE-2018-7871

Publication date:
08/03/2018
There is a heap-based buffer over-read in the getName function of util/decompile.c in libming 0.4.8 for CONSTANT16 data. A crafted input will lead to a denial of service or possibly unspecified other impact.
Severity CVSS v4.0: Pending analysis
Last modification:
04/03/2019

CVE-2018-7872

Publication date:
08/03/2018
An invalid memory address dereference was discovered in the function getName in libming 0.4.8 for CONSTANT16 data. The vulnerability causes a segmentation fault and application crash, which leads to denial of service.
Severity CVSS v4.0: Pending analysis
Last modification:
04/03/2019

CVE-2018-7869

Publication date:
08/03/2018
There is a memory leak triggered in the function dcinit of util/decompile.c in libming 0.4.8, which will lead to a denial of service attack.
Severity CVSS v4.0: Pending analysis
Last modification:
03/10/2019

CVE-2018-7873

Publication date:
08/03/2018
There is a heap-based buffer overflow in the getString function of util/decompile.c in libming 0.4.8 for INTEGER data. A Crafted input will lead to a denial of service attack.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2018-7868

Publication date:
08/03/2018
There is a heap-based buffer over-read in the getName function of util/decompile.c in libming 0.4.8 for CONSTANT8 data. A Crafted input will lead to a denial of service attack.
Severity CVSS v4.0: Pending analysis
Last modification:
04/03/2019

CVE-2018-7867

Publication date:
08/03/2018
There is a heap-based buffer overflow in the getString function of util/decompile.c in libming 0.4.8 during a RegisterNumber sprintf. A Crafted input will lead to a denial of service attack.
Severity CVSS v4.0: Pending analysis
Last modification:
24/08/2020

CVE-2018-7866

Publication date:
08/03/2018
A NULL pointer dereference was discovered in newVar3 in util/decompile.c in libming 0.4.8. The vulnerability causes a segmentation fault and application crash, which leads to denial of service.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2018-4838

Publication date:
08/03/2018
A vulnerability has been identified in EN100 Ethernet module IEC 61850 variant (All versions
Severity CVSS v4.0: Pending analysis
Last modification:
03/10/2019