Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2014-0241

Publication date:
13/12/2019
rubygem-hammer_cli_foreman: File /etc/hammer/cli.modules.d/foreman.yml world readable
Severity CVSS v4.0: Pending analysis
Last modification:
18/12/2019

CVE-2019-18838

Publication date:
13/12/2019
An issue was discovered in Envoy 1.12.0. Upon receipt of a malformed HTTP request without a Host header, it sends an internally generated "Invalid request" response. This internally generated response is dispatched through the configured encoder filter chain before being sent to the client. An encoder filter that invokes route manager APIs that access a request's Host header causes a NULL pointer dereference, resulting in abnormal termination of the Envoy process.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2014-0212

Publication date:
13/12/2019
qpid-cpp: ACL policies only loaded if the acl-file option specified enabling DoS by consuming all available file descriptors
Severity CVSS v4.0: Pending analysis
Last modification:
19/12/2019

CVE-2014-0175

Publication date:
13/12/2019
mcollective has a default password set at install
Severity CVSS v4.0: Pending analysis
Last modification:
13/02/2023

CVE-2014-0197

Publication date:
13/12/2019
CFME: CSRF protection vulnerability via permissive check of the referrer header
Severity CVSS v4.0: Pending analysis
Last modification:
13/02/2023

CVE-2019-19782

Publication date:
13/12/2019
The FTP client in AceaXe Plus 1.0 allows a buffer overflow via a long EHLO response from an FTP server.
Severity CVSS v4.0: Pending analysis
Last modification:
16/12/2019

CVE-2019-19777

Publication date:
13/12/2019
stb_image.h (aka the stb image loader) 2.23, as used in libsixel and other products, has a heap-based buffer over-read in stbi__load_main.
Severity CVSS v4.0: Pending analysis
Last modification:
18/12/2019

CVE-2019-19778

Publication date:
13/12/2019
An issue was discovered in libsixel 1.8.2. There is a heap-based buffer over-read in the function load_sixel at loader.c.
Severity CVSS v4.0: Pending analysis
Last modification:
19/12/2019

CVE-2019-16777

Publication date:
13/12/2019
Versions of the npm CLI prior to 6.13.4 are vulnerable to an Arbitrary File Overwrite. It fails to prevent existing globally-installed binaries to be overwritten by other package installations. For example, if a package was installed globally and created a serve binary, any subsequent installs of packages that also create a serve binary would overwrite the previous serve binary. This behavior is still allowed in local installations and also through install scripts. This vulnerability bypasses a user using the --ignore-scripts install option.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2019-16775

Publication date:
13/12/2019
Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It is possible for packages to create symlinks to files outside of thenode_modules folder through the bin field upon installation. A properly constructed entry in the package.json bin field would allow a package publisher to create a symlink pointing to arbitrary files on a user's system when the package is installed. This behavior is still possible through install scripts. This vulnerability bypasses a user using the --ignore-scripts install option.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2019-16776

Publication date:
13/12/2019
Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It fails to prevent access to folders outside of the intended node_modules folder through the bin field. A properly constructed entry in the package.json bin field would allow a package publisher to modify and/or gain access to arbitrary files on a user's system when the package is installed. This behavior is still possible through install scripts. This vulnerability bypasses a user using the --ignore-scripts install option.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2019-16774

Publication date:
12/12/2019
In phpfastcache before 5.1.3, there is a possible object injection vulnerability in cookie driver.
Severity CVSS v4.0: Pending analysis
Last modification:
07/10/2020