Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2020-35926

Publication date:
31/12/2020
An issue was discovered in the nanorand crate before 0.5.1 for Rust. It caused any random number generator (even ChaCha) to return all zeroes because integer truncation was mishandled.
Severity CVSS v4.0: Pending analysis
Last modification:
21/07/2021

CVE-2020-35907

Publication date:
31/12/2020
An issue was discovered in the futures-task crate before 0.3.5 for Rust. futures_task::noop_waker_ref allows a NULL pointer dereference.
Severity CVSS v4.0: Pending analysis
Last modification:
06/01/2021

CVE-2020-35908

Publication date:
31/12/2020
An issue was discovered in the futures-util crate before 0.3.2 for Rust. FuturesUnordered can lead to data corruption because Sync is mishandled.
Severity CVSS v4.0: Pending analysis
Last modification:
06/01/2021

CVE-2020-35906

Publication date:
31/12/2020
An issue was discovered in the futures-task crate before 0.3.6 for Rust. futures_task::waker may cause a use-after-free in a non-static type situation.
Severity CVSS v4.0: Pending analysis
Last modification:
06/01/2021

CVE-2020-35910

Publication date:
31/12/2020
An issue was discovered in the lock_api crate before 0.4.2 for Rust. A data race can occur because of MappedMutexGuard unsoundness.
Severity CVSS v4.0: Pending analysis
Last modification:
06/01/2021

CVE-2020-35915

Publication date:
31/12/2020
An issue was discovered in the futures-intrusive crate before 0.4.0 for Rust. GenericMutexGuard allows cross-thread data races of non-Sync types.
Severity CVSS v4.0: Pending analysis
Last modification:
06/01/2021

CVE-2020-35916

Publication date:
31/12/2020
An issue was discovered in the image crate before 0.23.12 for Rust. A Mutable reference has immutable provenance. (In the case of LLVM, the IR may be always correct.)
Severity CVSS v4.0: Pending analysis
Last modification:
06/01/2021

CVE-2020-35917

Publication date:
31/12/2020
An issue was discovered in the pyo3 crate before 0.12.4 for Rust. There is a reference-counting error and use-after-free in From.
Severity CVSS v4.0: Pending analysis
Last modification:
06/01/2021

CVE-2020-35903

Publication date:
31/12/2020
An issue was discovered in the dync crate before 0.5.0 for Rust. VecCopy allows misaligned element access because u8 is not always the type in question.
Severity CVSS v4.0: Pending analysis
Last modification:
06/01/2021

CVE-2020-35905

Publication date:
31/12/2020
An issue was discovered in the futures-util crate before 0.3.7 for Rust. MutexGuard::map can cause a data race for certain closure situations (in safe code).
Severity CVSS v4.0: Pending analysis
Last modification:
06/01/2021

CVE-2020-35919

Publication date:
31/12/2020
An issue was discovered in the net2 crate before 0.2.36 for Rust. It has false expectations about the std::net::SocketAddr memory representation.
Severity CVSS v4.0: Pending analysis
Last modification:
06/01/2021

CVE-2020-35904

Publication date:
31/12/2020
An issue was discovered in the crossbeam-channel crate before 0.4.4 for Rust. It has incorrect expectations about the relationship between the memory allocation and how many iterator elements there are.
Severity CVSS v4.0: Pending analysis
Last modification:
06/01/2021