Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2018-9067

Publication date:
13/07/2018
The Lenovo Help Android app versions earlier than 6.1.2.0327 had insufficient access control for some functions which, if exploited, could have led to exposure of approximately 400 email addresses and 8,500 IMEI.
Severity CVSS v4.0: Pending analysis
Last modification:
03/10/2019

CVE-2018-9070

Publication date:
13/07/2018
For the Lenovo Smart Assistant Android app versions earlier than 12.1.82, an attacker with physical access to the smart speaker can, by pressing a specific button sequence, enter factory test mode and enable a web service intended for testing the device. As with most test modes, this provides extra privileges, including changing settings and running code. Lenovo Smart Assistant is an Amazon Alexa-enabled smart speaker developed by Lenovo.
Severity CVSS v4.0: Pending analysis
Last modification:
03/10/2019

CVE-2017-1367

Publication date:
13/07/2018
IBM Security Identity Governance and Intelligence Virtual Appliance 5.2 through 5.2.3.2 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 126860.
Severity CVSS v4.0: Pending analysis
Last modification:
09/10/2019

CVE-2017-1395

Publication date:
13/07/2018
IBM Security Identity Governance and Intelligence Virtual Appliance 5.2 through 5.2.3.2 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 127341.
Severity CVSS v4.0: Pending analysis
Last modification:
09/10/2019

CVE-2018-14048

Publication date:
13/07/2018
An issue has been found in libpng 1.6.34. It is a SEGV in the function png_free_data in png.c, related to the recommended error handling for png_read_image.
Severity CVSS v4.0: Pending analysis
Last modification:
27/06/2022

CVE-2018-14044

Publication date:
13/07/2018
The RateTransposer::setChannels function in RateTransposer.cpp in libSoundTouch.a in Olli Parviainen SoundTouch 2.0 allows remote attackers to cause a denial of service (assertion failure and application exit), as demonstrated by SoundStretch.
Severity CVSS v4.0: Pending analysis
Last modification:
03/10/2019

CVE-2018-14045

Publication date:
13/07/2018
The FIRFilter::evaluateFilterMulti function in FIRFilter.cpp in libSoundTouch.a in Olli Parviainen SoundTouch 2.0 allows remote attackers to cause a denial of service (assertion failure and application exit), as demonstrated by SoundStretch.
Severity CVSS v4.0: Pending analysis
Last modification:
03/10/2019

CVE-2018-14046

Publication date:
13/07/2018
Exiv2 0.26 has a heap-based buffer over-read in WebPImage::decodeChunks in webpimage.cpp.
Severity CVSS v4.0: Pending analysis
Last modification:
03/10/2019

CVE-2018-14043

Publication date:
13/07/2018
mstdlib (aka the M Standard Library for C) 1.2.0 has incorrect file access control in situations where M_fs_perms_can_access attempts to delete an existing file (that lacks public read/write access) during a copy operation, related to fs/m_fs.c and fs/m_fs_path.c. An attacker could create the file and then would have access to the data.
Severity CVSS v4.0: Pending analysis
Last modification:
03/10/2019

CVE-2018-14040

Publication date:
13/07/2018
In Bootstrap before 4.1.2, XSS is possible in the collapse data-parent attribute.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2018-14041

Publication date:
13/07/2018
In Bootstrap before 4.1.2, XSS is possible in the data-target property of scrollspy.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2018-14042

Publication date:
13/07/2018
In Bootstrap before 4.1.2, XSS is possible in the data-container property of tooltip.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023