Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2016-4547

Publication date:
13/02/2017
Samsung devices with Android KK(4.4), L(5.0/5.1), or M(6.0) allow attackers to cause a denial of service (system crash) via a crafted system call to TvoutService_C.
Severity CVSS v4.0: Pending analysis
Last modification:
20/04/2025

CVE-2016-8659

Publication date:
13/02/2017
Bubblewrap before 0.1.3 sets the PR_SET_DUMPABLE flag, which might allow local users to gain privileges by attaching to the process, as demonstrated by sending commands to a PrivSep socket.
Severity CVSS v4.0: Pending analysis
Last modification:
20/04/2025

CVE-2016-3995

Publication date:
13/02/2017
The timing attack protection in Rijndael::Enc::ProcessAndXorBlock and Rijndael::Dec::ProcessAndXorBlock in Crypto++ (aka cryptopp) before 5.6.4 may be optimized out by the compiler, which allows attackers to conduct timing attacks.
Severity CVSS v4.0: Pending analysis
Last modification:
20/04/2025

CVE-2016-5100

Publication date:
13/02/2017
Froxlor before 0.9.35 uses the PHP rand function for random number generation, which makes it easier for remote attackers to guess the password reset token by predicting a value.
Severity CVSS v4.0: Pending analysis
Last modification:
20/04/2025

CVE-2015-8771

Publication date:
13/02/2017
The generate_smb_nt_hash function in include/functions.inc in GOsa allows remote attackers to execute arbitrary commands via a crafted password.
Severity CVSS v4.0: Pending analysis
Last modification:
20/04/2025

CVE-2016-6129

Publication date:
13/02/2017
The rsa_verify_hash_ex function in rsa_verify_hash.c in LibTomCrypt, as used in OP-TEE before 2.2.0, does not validate that the message length is equal to the ASN.1 encoded data length, which makes it easier for remote attackers to forge RSA signatures or public certificates by leveraging a Bleichenbacher signature forgery attack.
Severity CVSS v4.0: Pending analysis
Last modification:
20/04/2025

CVE-2014-9760

Publication date:
13/02/2017
Cross-site scripting (XSS) vulnerability in the displayLogin function in html/index.php in GOsa allows remote attackers to inject arbitrary web script or HTML via the username.
Severity CVSS v4.0: Pending analysis
Last modification:
20/04/2025

CVE-2015-8750

Publication date:
13/02/2017
libdwarf 20151114 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a debug_abbrev section marked NOBITS in an ELF file.
Severity CVSS v4.0: Pending analysis
Last modification:
20/04/2025

CVE-2016-2568

Publication date:
13/02/2017
pkexec, when used with --user nonpriv, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer.
Severity CVSS v4.0: Pending analysis
Last modification:
20/04/2025

CVE-2016-2788

Publication date:
13/02/2017
MCollective 2.7.0 and 2.8.x before 2.8.9, as used in Puppet Enterprise, allows remote attackers to execute arbitrary code via vectors related to the mco ping command.
Severity CVSS v4.0: Pending analysis
Last modification:
20/04/2025

CVE-2016-8859

Publication date:
13/02/2017
Multiple integer overflows in the TRE library and musl libc allow attackers to cause memory corruption via a large number of (1) states or (2) tags, which triggers an out-of-bounds write.
Severity CVSS v4.0: Pending analysis
Last modification:
20/04/2025

CVE-2016-2787

Publication date:
13/02/2017
The Puppet Communications Protocol in Puppet Enterprise 2015.3.x before 2015.3.3 does not properly validate certificates for the broker node, which allows remote non-whitelisted hosts to prevent runs from triggering via unspecified vectors.
Severity CVSS v4.0: Pending analysis
Last modification:
20/04/2025