Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2017-18379

Publication date:
27/07/2019
In the Linux kernel before 4.14, an out of boundary access happened in drivers/nvme/target/fc.c.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2010-5331

Publication date:
27/07/2019
In the Linux kernel before 2.6.34, a range check issue in drivers/gpu/drm/radeon/atombios.c could cause an off by one (buffer overflow) problem. NOTE: At least one Linux maintainer believes that this CVE is incorrectly assigned and should be rejected because the value is hard coded and are not user-controllable where it is used
Severity CVSS v4.0: Pending analysis
Last modification:
21/11/2024

CVE-2011-5327

Publication date:
27/07/2019
In the Linux kernel before 3.1, an off by one in the drivers/target/loopback/tcm_loop.c tcm_loop_make_naa_tpg() function could result in at least memory corruption.
Severity CVSS v4.0: Pending analysis
Last modification:
21/11/2024

CVE-2012-6712

Publication date:
27/07/2019
In the Linux kernel before 3.4, a buffer overflow occurs in drivers/net/wireless/iwlwifi/iwl-agn-sta.c, which will cause at least memory corruption.
Severity CVSS v4.0: Pending analysis
Last modification:
03/11/2022

CVE-2016-10764

Publication date:
27/07/2019
In the Linux kernel before 4.9.6, there is an off by one in the drivers/mtd/spi-nor/cadence-quadspi.c cqspi_setup_flash() function. There are CQSPI_MAX_CHIPSELECT elements in the ->f_pdata array so the ">" should be ">=" instead.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2015-9289

Publication date:
27/07/2019
In the Linux kernel before 4.1.4, a buffer overflow occurs when checking userspace params in drivers/media/dvb-frontends/cx24116.c. The maximum size for a DiSEqC command is 6, according to the userspace API. However, the code allows larger values such as 23.
Severity CVSS v4.0: Pending analysis
Last modification:
11/12/2019

CVE-2007-6762

Publication date:
27/07/2019
In the Linux kernel before 2.6.20, there is an off-by-one bug in net/netlabel/netlabel_cipso_v4.c where it is possible to overflow the doi_def->tags[] array.
Severity CVSS v4.0: Pending analysis
Last modification:
21/11/2024

CVE-2019-14295

Publication date:
27/07/2019
An Integer overflow in the getElfSections function in p_vmlinx.cpp in UPX 3.95 allows remote attackers to cause a denial of service (crash) via a skewed offset larger than the size of the PE section in a UPX packed executable, which triggers an allocation of excessive memory.
Severity CVSS v4.0: Pending analysis
Last modification:
11/04/2025

CVE-2019-14296

Publication date:
27/07/2019
canUnpack in p_vmlinx.cpp in UPX 3.95 allows remote attackers to cause a denial of service (SEGV or buffer overflow, and application crash) or possibly have unspecified other impact via a crafted UPX packed file.
Severity CVSS v4.0: Pending analysis
Last modification:
11/04/2025

CVE-2019-14288

Publication date:
27/07/2019
An issue was discovered in Xpdf 4.01.01. There is an Integer overflow in the function JBIG2Bitmap::combine at JBIG2Stream.cc for the "one byte per line" case.
Severity CVSS v4.0: Pending analysis
Last modification:
29/07/2019

CVE-2019-14289

Publication date:
27/07/2019
An issue was discovered in Xpdf 4.01.01. There is an integer overflow in the function JBIG2Bitmap::combine at JBIG2Stream.cc for the "multiple bytes per line" case.
Severity CVSS v4.0: Pending analysis
Last modification:
29/07/2019

CVE-2019-14290

Publication date:
27/07/2019
An issue was discovered in Xpdf 4.01.01. There is an out of bounds read in the function GfxPatchMeshShading::parse at GfxState.cc for typeA==6 case 2.
Severity CVSS v4.0: Pending analysis
Last modification:
29/07/2019