Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2020-35916

Publication date:
31/12/2020
An issue was discovered in the image crate before 0.23.12 for Rust. A Mutable reference has immutable provenance. (In the case of LLVM, the IR may be always correct.)
Severity CVSS v4.0: Pending analysis
Last modification:
06/01/2021

CVE-2020-35917

Publication date:
31/12/2020
An issue was discovered in the pyo3 crate before 0.12.4 for Rust. There is a reference-counting error and use-after-free in From.
Severity CVSS v4.0: Pending analysis
Last modification:
06/01/2021

CVE-2020-35903

Publication date:
31/12/2020
An issue was discovered in the dync crate before 0.5.0 for Rust. VecCopy allows misaligned element access because u8 is not always the type in question.
Severity CVSS v4.0: Pending analysis
Last modification:
06/01/2021

CVE-2020-35905

Publication date:
31/12/2020
An issue was discovered in the futures-util crate before 0.3.7 for Rust. MutexGuard::map can cause a data race for certain closure situations (in safe code).
Severity CVSS v4.0: Pending analysis
Last modification:
06/01/2021

CVE-2020-35919

Publication date:
31/12/2020
An issue was discovered in the net2 crate before 0.2.36 for Rust. It has false expectations about the std::net::SocketAddr memory representation.
Severity CVSS v4.0: Pending analysis
Last modification:
06/01/2021

CVE-2020-35904

Publication date:
31/12/2020
An issue was discovered in the crossbeam-channel crate before 0.4.4 for Rust. It has incorrect expectations about the relationship between the memory allocation and how many iterator elements there are.
Severity CVSS v4.0: Pending analysis
Last modification:
06/01/2021

CVE-2020-35914

Publication date:
31/12/2020
An issue was discovered in the lock_api crate before 0.4.2 for Rust. A data race can occur because of RwLockWriteGuard unsoundness.
Severity CVSS v4.0: Pending analysis
Last modification:
05/01/2021

CVE-2020-35913

Publication date:
31/12/2020
An issue was discovered in the lock_api crate before 0.4.2 for Rust. A data race can occur because of RwLockReadGuard unsoundness.
Severity CVSS v4.0: Pending analysis
Last modification:
05/01/2021

CVE-2020-35912

Publication date:
31/12/2020
An issue was discovered in the lock_api crate before 0.4.2 for Rust. A data race can occur because of MappedRwLockWriteGuard unsoundness.
Severity CVSS v4.0: Pending analysis
Last modification:
05/01/2021

CVE-2020-35911

Publication date:
31/12/2020
An issue was discovered in the lock_api crate before 0.4.2 for Rust. A data race can occur because of MappedRwLockReadGuard unsoundness.
Severity CVSS v4.0: Pending analysis
Last modification:
05/01/2021

CVE-2020-35909

Publication date:
31/12/2020
An issue was discovered in the multihash crate before 0.11.3 for Rust. The from_slice parsing code can panic via unsanitized data from a network server.
Severity CVSS v4.0: Pending analysis
Last modification:
14/01/2021

CVE-2020-35918

Publication date:
31/12/2020
An issue was discovered in the branca crate before 0.10.0 for Rust. Decoding tokens (with invalid base62 data) can panic.
Severity CVSS v4.0: Pending analysis
Last modification:
02/09/2022