Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2019-6460

Publication date:
16/01/2019
An issue was discovered in GNU Recutils 1.8. There is a NULL pointer dereference in the function rec_field_set_name() in the file rec-field.c in librec.a.
Severity CVSS v4.0: Pending analysis
Last modification:
17/01/2019

CVE-2019-6456

Publication date:
16/01/2019
An issue was discovered in GNU Recutils 1.8. There is a NULL pointer dereference in the function rec_fex_size() in the file rec-fex.c of librec.a.
Severity CVSS v4.0: Pending analysis
Last modification:
17/01/2019

CVE-2019-6455

Publication date:
16/01/2019
An issue was discovered in GNU Recutils 1.8. There is a double-free problem in the function rec_mset_elem_destroy() in the file rec-mset.c.
Severity CVSS v4.0: Pending analysis
Last modification:
17/01/2019

CVE-2019-6461

Publication date:
16/01/2019
An issue was discovered in cairo 1.16.0. There is an assertion problem in the function _cairo_arc_in_direction in the file cairo-arc.c.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2019-6462

Publication date:
16/01/2019
An issue was discovered in cairo 1.16.0. There is an infinite loop in the function _arc_error_normalized in the file cairo-arc.c, related to _arc_max_angle_for_tolerance_normalized.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2019-6457

Publication date:
16/01/2019
An issue was discovered in GNU Recutils 1.8. There is a memory leak in rec_aggregate_reg_new in rec-aggregate.c in librec.a.
Severity CVSS v4.0: Pending analysis
Last modification:
24/08/2020

CVE-2019-6458

Publication date:
16/01/2019
An issue was discovered in GNU Recutils 1.8. There is a memory leak in rec_buf_new in rec-buf.c when called from rec_parse_rset in rec-parser.c in librec.a.
Severity CVSS v4.0: Pending analysis
Last modification:
24/08/2020

CVE-2019-6459

Publication date:
16/01/2019
An issue was discovered in GNU Recutils 1.8. There is a memory leak in rec_extract_type in rec-utils.c in librec.a.
Severity CVSS v4.0: Pending analysis
Last modification:
24/08/2020

CVE-2015-9279

Publication date:
16/01/2019
MailEnable before 8.60 allows Stored XSS via malformed use of "" character in the body of an e-mail message.
Severity CVSS v4.0: Pending analysis
Last modification:
17/01/2019

CVE-2015-9277

Publication date:
16/01/2019
MailEnable before 8.60 allows Directory Traversal for reading the messages of other users, uploading files, and deleting files because "/../" and "/.. /" are mishandled.
Severity CVSS v4.0: Pending analysis
Last modification:
17/01/2019

CVE-2015-9278

Publication date:
16/01/2019
MailEnable before 8.60 allows Privilege Escalation because admin accounts could be created as a consequence of %0A mishandling in AUTH.TAB after a password-change request.
Severity CVSS v4.0: Pending analysis
Last modification:
01/02/2019

CVE-2015-9276

Publication date:
16/01/2019
SmarterTools SmarterMail before 13.3.5535 was vulnerable to stored XSS by bypassing the anti-XSS mechanisms. It was possible to run JavaScript code when a victim user opens or replies to the attacker's email, which contained a malicious payload. Therefore, users' passwords could be reset by using an XSS attack, as the password reset page did not need the current password.
Severity CVSS v4.0: Pending analysis
Last modification:
24/01/2019