Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2018-5919

Publication date:
27/11/2018
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, a use after free issue in WLAN host driver can lead to device reboot.
Severity CVSS v4.0: Pending analysis
Last modification:
21/12/2018

CVE-2018-11918

Publication date:
27/11/2018
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, memory allocated is automatically released by the kernel if the 'probe' function fails with an error code.
Severity CVSS v4.0: Pending analysis
Last modification:
21/12/2018

CVE-2018-11995

Publication date:
27/11/2018
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, a partition name-check variable is not reset for every iteration which may cause improper termination in the META image.
Severity CVSS v4.0: Pending analysis
Last modification:
21/12/2018

CVE-2018-5861

Publication date:
27/11/2018
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, existing checks in place on partition size are incomplete and can lead to heap overwrite vulnerabilities while loading a secure application from the boot loader.
Severity CVSS v4.0: Pending analysis
Last modification:
21/12/2018

CVE-2018-5856

Publication date:
27/11/2018
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, due to a race condition, a Use After Free condition can occur in Audio.
Severity CVSS v4.0: Pending analysis
Last modification:
21/12/2018

CVE-2018-5904

Publication date:
27/11/2018
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, while list traversal in LPM status driver for clean up, use after free vulnerability may occur.
Severity CVSS v4.0: Pending analysis
Last modification:
21/12/2018

CVE-2018-5906

Publication date:
27/11/2018
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, there is a possible buffer overflow in debugfs module due to lack of check in size of input before copying into buffer.
Severity CVSS v4.0: Pending analysis
Last modification:
21/12/2018

CVE-2018-5908

Publication date:
27/11/2018
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, there is a possible buffer overflow in display function due to lack of buffer length validation before copying.
Severity CVSS v4.0: Pending analysis
Last modification:
21/12/2018

CVE-2018-5910

Publication date:
27/11/2018
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, a memory corruption can occur in kernel due to improper check in callers count parameter in display handlers.
Severity CVSS v4.0: Pending analysis
Last modification:
21/12/2018

CVE-2018-19609

Publication date:
27/11/2018
ShowDoc 2.4.1 allows remote attackers to obtain sensitive information by navigating with a modified page_id, as demonstrated by reading note content, or discovering a username in the JSON data at a diff URL.
Severity CVSS v4.0: Pending analysis
Last modification:
21/12/2018

CVE-2018-11943

Publication date:
27/11/2018
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, while processing fastboot flash command, memory leak or unexpected behavior may occur due to processing of unintialized data buffers.
Severity CVSS v4.0: Pending analysis
Last modification:
03/10/2019

CVE-2018-11914

Publication date:
27/11/2018
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, improper access control can lead to device node and executable to be run from /systemrw/ which presents a potential security.
Severity CVSS v4.0: Pending analysis
Last modification:
03/10/2019